IAM & DLP Lead, APAC

Liberty in Asia Pacific

Mumbai

On-site

INR 4,000,000 - 6,000,000

Full time

3 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Liberty in Asia Pacific is hiring an IAM (Identity & Access Management) & DLP Lead to establish unified access governance and data loss prevention frameworks across APAC markets. You will translate global standards into locally compliant guidelines, SOPs, access certification processes, and DLP controls, collaborating with market CISOs.

You will shape IAM and DLP roadmaps, drive user access reviews, tune DLP policies, ensure audit readiness, and balance global consistency with local regulatory

Qualifications

  • 10+ years in IAM, DLP, IT governance or security.
  • Hands-on experience with access certification and user access reviews.
  • Experience implementing DLP solutions (policy creation, tuning, incident triage).
  • Proven skills with Purview and Proofpoint.
  • Understanding IAM concepts (RBAC/ABAC, SSO, MFA, SailPoint, Entra ID) and PAM tools.
  • Insurance or financial services domain familiarity.

Responsibilities

  • Define and operationalize APAC IAM and DLP frameworks.
  • Lead governance, policy management, and controls across markets.
  • Drive user access reviews and certification across all account types.
  • Tune DLP policies and monitor incidents for risk reduction.
  • Coordinate with CISOs, HR, legal, and risk to maintain audit readiness.
  • Produce periodic DLP and IAM reporting to stakeholders.
  • Ensure local regulatory alignment with global standards.

Skills

IAM Leadership
DLP Leadership
Access governance
Policy development
Regulatory compliance
Stakeholder management
Documentation
Audits & reporting

Education

CISA certification
CRISC certification
CISM certification
SailPoint certification
Microsoft Security certification

Tools

Microsoft Purview
Proofpoint
SailPoint
Microsoft Entra ID
CyberArk
Delinea

Job description

We're hiring an IAM (Identity & Access Management) & DLP (Data Loss Prevention) Lead to establish and operationalize unified access governance and data loss prevention frameworks across our APAC insurance markets. Working from the global IAM and Data Security teams' policy references, you'll translate enterprise standards into practical, locally compliant frameworks – setting up local guidelines, SOPs, access certification processes, and DLP controls for each market. You'll partner closely with market CISOs to shape and execute the IAM and DLP roadmap, drive user access reviews across all account types, implement and tune DLP policies to protect sensitive data, and ensure the entire program is audit-ready against local regulatory expectations. This role is ideal for someone who can balance global consistency with local regulatory reality across both access governance and data protection, and who takes pride in building durable, well-documented governance.

Access Governance Framework
  • Establish an access governance framework for APAC, using the global IAM team's policies and standards as the authoritative reference point
  • Adapt and operationalize global IAM principles to fit the APAC market context, leveraging the global team's capabilities, tooling, and patterns wherever possible
  • Design a unified, consistent IAM framework that works across all in-scope APAC markets while accommodating local regulatory and operational differences
  • Where global standards cannot be implemented as-is in a given market, raise, document, and manage formal security exceptions through the appropriate risk acceptance process
  • Establish a DLP governance framework for APAC, aligned to the global Data Security team's policies and data classification standards
  • Define and operationalize DLP policies across endpoint, email, cloud, and web channels to prevent unauthorized disclosure of sensitive and regulated data (PII, policyholder data, financial records, intellectual property)
  • Adapt global DLP rules and detection logic to accommodate local data types, languages, and regulatory requirements specific to each APAC market
  • Design and maintain data classification schemas and sensitive information types relevant to APAC insurance operations
  • Where global DLP standards cannot be applied as-is, raise, document, and manage formal security exceptions through the appropriate risk acceptance process
DLP Policy Management & Tuning
  • Develop, test, and deploy DLP policies using Microsoft Purview and Proofpoint across email, endpoints, cloud applications, and collaboration platforms
  • Continuously monitor and tune DLP rules to reduce false positives while maintaining detection efficacy for true data exposure risks
  • Define and manage DLP response actions (block, quarantine, notify, encrypt) appropriate to the sensitivity of the data and the regulatory context of each market
  • Establish incident triage workflows for DLP alerts — including escalation paths, investigation procedures, and evidence preservation
  • Conduct periodic reviews of DLP policy effectiveness and produce metrics on policy hits, incidents, trends, and remediation outcomes
Local Guidelines, SOPs & Procedures
  • Develop and maintain local IAM and DLP guidelines, SOPs, and work instructions for each APAC market
  • Ensure procedures clearly define roles, responsibilities, approval workflows, and escalation paths for both access governance and data protection
  • Keep documentation current as global policy, local regulation, and tooling evolve
Access Certification & User Access Reviews
  • Set up and run access certification and periodic user access review (UAR) processes covering all account types — standard user, privileged, service, shared, and third-party/vendor accounts
  • Define review cadence, scope, ownership, and evidence requirements per market
  • Track review completion, remediate identified access gaps and toxic combinations, and confirm closure
  • Drive continuous improvement in certification quality, automation, and reviewer accountability
  • Monitor DLP dashboards and alert queues, triaging and investigating potential data leakage incidents across all channels
  • Coordinate with market CISOs, legal, compliance, and HR on confirmed DLP incidents, ensuring appropriate containment and remediation
  • Maintain DLP incident records with full traceability — detection, investigation, response, root cause, and closure
  • Produce periodic DLP reporting for market CISOs covering incident volumes, trends, top triggered policies, high-risk users/departments, and remediation status
  • Drive user awareness and behaviour change through targeted engagement informed by DLP findings
Regulatory Compliance & Audit Readiness
  • Identify and interpret IAM- and DLP-relevant regulatory requirements across MAS, HKIA, APRA, BNM, NFRA, and IRDAI (e.g., access control, segregation of duties, privileged access, periodic recertification, logging, data protection, cross-border data transfer, breach notification)
  • Map local requirements into the access governance and DLP frameworks and ensure procedures demonstrably comply
  • Maintain the IAM and DLP programs in a continuously audit-ready state — complete, current evidence; clear traceability from control to procedure to execution
  • Support internal audits, external audits, and regulatory inspections, and drive closure of any IAM- or DLP-related findings
Stakeholder Engagement & Reporting
  • Partner with market CISOs to define, prioritize, and execute the IAM and DLP roadmap for each market
  • Provide periodic reporting to market CISOs on progress, key risks, challenges, exceptions, and remediation status across both IAM and DLP
  • Coordinate with the global IAM team, Data Security team, local IT, application owners, HR, and risk/compliance functions to keep the frameworks aligned and effective
  • Escalate blockers and emerging risks promptly with clear, decision-ready context
Requirements:
  • 10+ years of experience in identity and access management, data loss prevention, IT governance, security, or a closely related field
  • Hands-on experience with access governance processes — access certification, user access reviews, joiner/mover/leaver, privileged access management, and segregation of duties
  • Hands-on experience implementing and managing DLP solutions, including policy creation, tuning, incident triage, and reporting
  • Demonstrated experience with DLP tooling, specifically Microsoft Purview (Information Protection, DLP, Insider Risk Management) and Proofpoint (Email DLP, Content Compliance)
  • Demonstrated experience developing IAM and/or DLP policies, guidelines, SOPs, or control documentation in a regulated environment
  • Understanding of IAM concepts and tooling (RBAC/ABAC, SSO, MFA, SailPoint, Microsoft Entra ID, and PAM tools such as CyberArk or Delinea)
  • Understanding of data classification frameworks, sensitive information types, and data handling requirements in financial services
  • Familiarity with IAM- and DLP-relevant regulatory and control expectations across one or more APAC markets (MAS, HKIA, APRA, BNM, NFRA, IRDAI)
  • Familiarity with control frameworks such as ISO 27001, NIST CSF, or SOC 2
  • Experience supporting audits and regulatory inspections, and managing findings to closure
  • Strong documentation and stakeholder management skills, including the ability to report clearly to senior stakeholders such as CISOs
  • Highly organized, with the ability to manage multiple market workstreams in parallel
  • Prior experience in insurance or broader financial services
  • Relevant certifications (CISA, CRISC, CISM, SailPoint certifications, Microsoft Security certifications, or equivalent)
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

IAM & DLP Lead, APAC
IAM & DLP Lead, APAC

Liberty Specialty Markets • India

On-site
INR 1,800,000 - 3,000,000
Architect - Identity & Access Management
Architect - Identity & Access Management

PepsiCo • Hyderabad

On-site
INR 1,800,000 - 2,400,000
Architect - Identity & Access Management
Architect - Identity & Access Management

PepsiCo Inc. • Hyderabad

On-site
INR 1,400,000 - 2,200,000
IN_Senior Associate_IAM Engineer_Strategy, Governance, Risk & Compliance_Advisory_Bangalore
IN_Senior Associate_IAM Engineer_Strategy, Governance, Risk & Compliance_Advisory_Bangalore

Price Waterhouse Cooper LLP • Bengaluru

On-site
INR 4,000,000 - 7,000,000
IN_Senior Associate_IAM Engineer_FS - Cyber Risk and Regulations_Advisory_Pune
IN_Senior Associate_IAM Engineer_FS - Cyber Risk and Regulations_Advisory_Pune

Price Waterhouse Cooper LLP • Maharashtra

On-site
INR 4,000,000 - 7,000,000
Mentorship
Flexible benefits
Inclusive benefits
IAM Architect
IAM Architect

Gas Strategies • Bengaluru

On-site
INR 3,500,000 - 5,500,000
Data Platform and Governance Director
Data Platform and Governance Director

Deutsche Post DHL Group • Maharashtra

On-site
INR 3,500,000 - 5,500,000
Job Role – IAM and PAM Security Lead
Job Role – IAM and PAM Security Lead

Teciem • India

On-site
INR 2,400,000 - 4,200,000
Identity Access Management Operations And Engineering Manager
Identity Access Management Operations And Engineering Manager

StoneX Group Inc. • Bengaluru

On-site
INR 2,500,000 - 5,200,000
Information Security Manager
Information Security Manager

Mondee • Hyderabad

On-site
INR 3,500,000 - 7,000,000