Lead Engineer – Identity & Access Security

Dyson GmbH

Kuala Lumpur

On-site

MYR 180,000 - 260,000

Full time

38 hours ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Dyson GmbH in Malaysia (Kuala Lumpur) seeks a Lead Engineer for Identity & Access Security to design, engineer, and run identity controls protecting workforce identities and access pathways. You will drive MFA, passwordless, and zero-trust, while governing joins, moves, and leavers across the enterprise.

You’ll implement governance for lifecycle workflows, monitor identity threats, and push modernization of federation and SSO strategies, partnering with IT, HR, and business apps teams.

Qualifications

  • Bachelor’s degree in computer science, cybersecurity, information technology, or related field.
  • 5–7 years of hands-on cybersecurity experience in IAM within enterprise environments.
  • Experience designing and operating enterprise identity controls, federation protocols, and directory services.
  • Certs such as MS SC-300, CISSP, or CISM are desirable.

Responsibilities

  • Design and operate robust identity security controls across enterprise.
  • Enforce strong authentication, zero-trust access, and identity governance.
  • Manage Joiner, Mover, Leaver processes and lifecycle frameworks.
  • Lead identity threat monitoring, remediation, and risk-based policy enforcement.

Skills

IAM expertise
Identity protocols
MFA and zero-trust
Automation (PowerShell/SCIM)

Education

Bachelor’s degree in CS/IT/Cybersecurity

Tools

Entra ID (Azure AD)
PIM
Conditional Access
SSO and Federation
MFA controls

Job description

Lead Engineer – Identity & Access Security
Summary

Salary : Competitive Job Family : Cyber Security Location : Malaysia - Kuala Lumpur Office

Role Purpose

As the Identity and Access Security Engineer, you are accountable for designing, engineering, and operating robust identity security controls that protect workforce identities, endpoint devices, and corporate access pathways across the enterprise.

Operating as a technical specialist, you will enforce strong authentication, zero-trust access, and identity governance controls. By engineering seamless protection mechanisms, managing privileged accounts, and securing Joiner, Mover, and Leaver processes, you will mitigate identity threats and continuously harden authentication pathways against compromise.

In this role, you will lead and manage the following domains:

Conditional Access and Authentication: Designing and managing Conditional Access policies, MFA, and passwordless capabilities.

Privileged Identity Management (PIM): Engineering and governing high-privilege access workflows and just-in-time access controls.

Identity Lifecycle and Governance: Implementing secure Joiner, Mover, and Leaver processes and identity lifecycle frameworks.

Identity Threat Monitoring and Remediation: Monitoring identity-centric attack vectors and rapidly remediating active authentication weaknesses.

Identity Improvement Initiatives: Leading technical projects aimed at modernizing and securing federation and single sign-on (SSO) pathways.

Key Skills and Qualifications
  • Bachelor's degree in computer science, Cybersecurity, Information Technology, or a related field (or equivalent practical experience).
  • A minimum of 5 to 7 years of hands-on cybersecurity experience specializing in Identity and Access Management (IAM) within enterprise environments.
  • Deep hands-on experience designing and operating enterprise identity controls, federation protocols, and directory services.
  • Industry certifications such as Microsoft Certified: Identity and Access Administrator Associate (SC-300), CISSP, or CISM are highly desirable.
Security Expertise and Architecture

In-depth technical knowledge of modern identity protocols (SAML 2.0, OAuth 2.0, OIDC, FIDO2) and threat vectors targeting identities (password spraying, token theft, phishing-resistant MFA bypass).

Tooling and Technical Proficiency

Hands-on engineering expertise in Entra ID (Azure AD), Privileged Identity Management (PIM), Conditional Access, Entra ID Governance, SSO, Federation, and MFA controls.

Risk Management and Prioritisation

Ability to identify identity exposure risks, prioritize identity security controls based on privilege and threat context, and minimize identity attack surfaces.

Governance, Process and Control Design

Experience designing automated lifecycle management workflows (Joiner, Mover, Leaver) and establishing granular access control governance frameworks.

Service Delivery and Operational Management

Proven track record of managing identity control platforms, meeting operational SLAs, and executing seamless tenant-wide identity migrations.

Data Analysis, Reporting and Insight

Ability to extract insights from authentication logs and identity risk scores to visualize identity posture, sign-in risks, and policy enforcement effectiveness.

Stakeholder Management and Influence

Strong communication skills to collaborate with infrastructure, HR, and business applications teams to embed secure identity practices without hindering productivity.

Threat Intelligence Integration

Ability to incorporate real-time identity risk signals and CTI feeds into dynamic, risk-based authentication and access policies.

Leadership and Influence

Capability to drive identity security outcomes across technical groups through influence, clear technical guidance, and collaborative problem-solving.

Continuous Improvement and Automation

A strong focus on automation using PowerShell, Graph API, or SCIM provisioning to eliminate manual access assignments and reduce operational drift.

Key Accountabilities and Success Measures
Conditional Access and Policy Engineering

Accountability: Engineer, maintain, and continuously tune adaptive Conditional Access policies to enforce risk-based, zero-trust controls.

Success Measures: 100 percent of workforce sign-ins protected by modern MFA or passwordless authentication standards; zero unauthorized access breaches resulting from misconfigured access policies.

Privileged Identity and Lifecycle Governance

Accountability: Implement PIM and engineer lifecycle processes to govern privileged access and automate Joiner, Mover, and Leaver security controls.

Success Measures: 100 percent of administrative roles subject to Just-In-Time (JIT) access and approval workflows via PIM; 0 percent residual active accounts remaining for departed personnel beyond defined SLA windows.

Threat Remediation and Weakness Mitigation

Accountability: Continuously monitor identity telemetry, identify vulnerabilities in authentication, and execute swift remediation workflows.

Success Measures: Substantial reduction in MTTR for risky user alerts and identity threat detections; active reduction of legacy authentication protocols across the organization to less than 1 percent.

Dyson is an equal opportunity employer. We know that great minds don’t think alike, and it takes all kinds of minds to make our technology so unique. We welcome applications from all backgrounds and employment decisions are made without regard to race, colour, religion, national or ethnic origin, sex, sexual orientation, gender identity or expression, age, disability, protected veteran status or other any other dimension of diversity.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Principal – Workspace Security Architecture and Engineering
Principal – Workspace Security Architecture and Engineering

Dyson GmbH • Kuala Lumpur

On-site
MYR 360,000 - 520,000
Identity & Access Security Lead — Zero-Trust & IAM
Identity & Access Security Lead — Zero-Trust & IAM

Dyson GmbH • Kuala Lumpur

On-site
MYR 180,000 - 260,000
Information Security Specialist
Information Security Specialist

Zurich Insurance • Kuala Lumpur

On-site
MYR 90,000 - 120,000
Senior IAM / Microsoft Entra ID Architect / Engineer
Senior IAM / Microsoft Entra ID Architect / Engineer

OPTIMUM INFOSOLUTIONS (M) SDN BHD • Kuala Lumpur

On-site
MYR 180,000 - 240,000
Regional Assistant Manager, Security Engineering
Regional Assistant Manager, Security Engineering

ZUS COFFEE • Selangor

On-site
MYR 180,000 - 300,000
Lead Engineer – Identity & Access Security
Lead Engineer – Identity & Access Security

Dyson Institute • Kuala Lumpur

On-site
MYR 120,000 - 180,000
IAM Application Migration & Test Engineer
IAM Application Migration & Test Engineer

Hexamatics Servvcom Sdn Bhd • Kuala Lumpur

On-site
MYR 90,000 - 180,000
Identity & Security Operations Manager
Identity & Security Operations Manager

Abbott • Petaling Jaya

On-site
MYR 180,000 - 260,000
Career development
Great place to work worldwide
Diversity & inclusion
IAM Lead – IT Application & Database Security
IAM Lead – IT Application & Database Security

Hong Leong Bank • Petaling Jaya

On-site
MYR 180,000 - 320,000
APAC IT Manager (Cybersecurity)
APAC IT Manager (Cybersecurity)

hoffmanagency • Kuala Lumpur

On-site
MYR 120,000 - 180,000
Competitive salary
Four‑week sabbatical after four years
Career advancement opportunities