AVP, Corporate Enterprise Identity Systems

StarHub LtdSingaporeOn-siteFull-timeListed 2 days ago

Apply now

About this role

Job Description

Role Mission

Make identity StarHub’s enterprise control plane: one canonical identity, Google Workspace / Cloud Identity as the workforce front door, planned AD retirement, and accountable governance of all identities.

Own the end-to-end identity roadmap across architecture, authoritative sources, migration, lifecycle and operations, enabling Zero Trust, AWS, M&A and safe AI adoption.

Accountabilities

- Own the Identity-Led Enterprise strategy and 18-month roadmap, delivering approved scope, budget and milestones.

- Own the canonical identity model (Global Person ID), authoritative sources and attribute precedence across SuccessFactors and legacy M&A sources.

- Establish Google Workspace / Cloud Identity as the sole workforce authentication and SSO front door.

- Retire AD as a workforce authority: inventory dependencies, then migrate, federate, retire or time-bound exceptions.

- Govern privileged, non-human and AI-agent identities so privileged/autonomous actions remain attributable to an accountable human.

- Implement CISO-set identity policy; BTS operates it, while the CISO owns policy, risk acceptance and exceptions.

- Report status, risks and decisions to the CIO, ISLT and ICC, and own the Identity OKR.

Strategy & Architecture

- Translate the Identity-Led Enterprise position paper into a phased architecture covering authoritative sources, canonical identity, Google front door, access enforcement, workload access and telemetry.

- Define AD-to-Google coexistence, including event authority, JML and exit criteria for every AD dependency.

- Select IGA/PAM tooling that supports the Google-first model without creating a second identity authority.

- Set integration and onboarding standards for applications, AWS, endpoints, integration and AI platforms.

Delivery & Migration

- Lead matrixed architecture, security, engineering, project resources and partners; control scope, sequencing, RAID and budget.

- Deliver migration waves with identity clean-up, role/group rationalisation, orphan-account testing and validated deprovisioning.

- Automate JML from SuccessFactors and approved contractor/guest workflows, including sponsors, end dates and revalidation.

- Reconcile MyRepublic, JOS and Strateq under the canonical model using match logic, confidence thresholds, adjudication and merge/unmerge controls.

Governance & Controls

- Separate standard and privileged personas; enforce named approvals, break-glass controls and quarterly access certification.

- Maintain a non-human identity registry covering owner, purpose, environment, credentials, review and decommission trigger.

- Enforce zero net-new unmanaged shared/generic accounts and reduce existing account debt to a published schedule.

- Govern AI agents as non-human identities with approved purpose, data domains, actions and act-as/on-behalf-of modes, aligned to the IMDA Model AI Governance Framework for Agentic AI.

- Feed GWS, AWS, endpoints and critical applications into the SIEM using common identity identifiers.

- Provide audit evidence for identity controls, including CCoP and internal audit.

Qualifications

Team, Vendors & Stakeholders

- Lead and develop the IAM Specialist across identity engineering, governance and controls.

- Own the IAM managed-service vendor, including scope, SLAs/KPIs, reviews, change and commercial performance.

- Retain StarHub design authority and control ownership; build internal capability and reduce vendor dependency under the IS Best Team insourcing strategy.

- Partner with HR and application/platform owners on data quality, lifecycle, roles, approvals and provisioning.

- Optimise Google/Microsoft licensing as AD retires; track business-case benefits and report realisation to Finance.

Areas of Impact

- Zero Trust enforcement across the corporate estate.

- Single-provider SSO and improved employee/partner sign-in.

- AD retirement and associated Microsoft licence savings.

- Fewer orphaned, shared and ownerless accounts and cleaner audits.

- Safe, attributable AI-agent adoption.

- Faster, lower-cost future M&A integration.

- Move Identity from Legacy to Intelligent on the IS estate map by FY30, and Identity & Access from L2 to L4.

Ideal Track Record

- 12+ years in identity and access management, security architecture or enterprise platforms, including leading at least one enterprise IAM programme end to end.

- Has led at least one large directory migration or consolidation (for example on-premises AD to a cloud IdP such as Google Cloud Identity, Entra ID or Okta) in an organisation of several thousand identities.

- Hands-on depth in identity lifecycle and JML automation, IGA, PAM, SSO / federation (SAML, OIDC, SCIM) and access certification.

- Experience governing non-human identities: service accounts, workload identity, secrets and certificate-based patterns, ideally including AWS IAM.

- Working knowledge of Zero Trust architecture and emerging identity controls for AI agents.

- Experience reconciling identities across multiple HR systems or after mergers and acquisitions.

- Has presented to C-level or board committees and won funding and decisions with clear business cases.

- Delivers through a lean team and influence: managed-service vendors, system integrators and matrixed teams, with a track record of holding vendors to SLAs and outcomes.

- Has coached and developed junior engineers or specialists.

- Familiarity with Singapore requirements (CSA Cybersecurity Code of Practice, PDPA, IMDA AI governance) preferred.

- Relevant certifications (e.g. CISSP, CISM, CCSP, IDPro CIDPro, Google Cloud or AWS security) are an advantage.