Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.
PwC Acceleration Center Manila is seeking an IAM Engineer to lead end-to-end IAM delivery, governance, and automation across enterprise environments. You will focus on IGA, PAM, and AM, driving secure identity lifecycles, while ensuring audit readiness and regulatory compliance.
The role requires 5–10 years of IAM experience, strong English communication, and knowledge of SailPoint, CyberArk, Okta, Ping, and Microsoft Entra ID. Collaboration with clients and cross-functional teams is essential.
A career at PwC Cyber Data & Tech Risk Managed Services offers you the opportunity to deliver strategic cybersecurity solutions that safeguard our clients’ critical business and data assets. As an engineer, the IAM Engineer is responsible for the end-to-end delivery, engineering, and operational support of Identity and Access Management (IAM) capabilities across enterprise client environments. This role focuses on Identity Governance & Administration (IGA), Privileged Access Management (PAM), and Access Management (AM), driving secure identity lifecycle processes, automation, and continuous improvement while ensuring governance, compliance, and audit readiness.
You will collaborate closely with clients, internal stakeholders, and global experts to drive cyber resilience, regulatory compliance, and innovation. You will provide hands-on technical delivery, operational excellence, and continuous improvement across cyber managed services programs.
Bachelor’s Degree
5-10 years of relevant experience preferred
Oral and written proficiency in English required
Relevant experience in end-to-end support of IAM services and certifications like CISSP, CISM, CISA, GIAC (GCIH, GSEC, GCIA), CCSP, or equivalent is desirable.
Certifications specific to IAM (e.g., SailPoint Certified Engineer, CyberArk Trustee, Okta Certified Administrator or Microsoft SC-300) are an advantage.
Relevant experience in end-to-end support for IGA tools like SailPoint IDN/ IIQ, Saviynt, PAM tools like CyberArk and Delinea & Access Management Tools like Okta, Ping and Microsoft Entra AM.
Demonstrates knowledge and/or a proven record of success in one or more of the following areas:
Identity Governance and Administration:
Configuring, administering, and supporting Identity Governance and Administration (IGA) tools such as SailPoint ISC/IIQ, Saviynt, or equivalent platforms.
Implementing and optimizing access request management, approval workflows, and automated provisioning/de-provisioning processes to enhance efficiency and governance adherence.
Applying user lifecycle management best practices including role-based access control (RBAC), segregation of duties (SoD), and least privilege principles aligned to client policy and regulatory requirements.
Configuring identity workflows, role and entitlement models, and access approval processes tailored to client-specific business needs and compliance requirements.
Performing periodic access reviews/certifications, support remediation activities, and maintain audit-ready evidence for IAM controls and processes.
Privileged Access Management (PAM)
Administering Privileged Access Management (PAM) solutions including CyberArk, Delinea, BeyondTrust, or similar technologies, ensuring secure privileged account onboarding, credential rotation, session management, and policy enforcement.
Access Management (AM)
Supporting Access Management (AM) capabilities including Single Sign-On (SSO), Multi-Factor Authentication (MFA), and federation protocols (SAML, OAuth, OpenID Connect) using platforms such as Ping, Okta, Microsoft Entra ID, ForgeRock, or equivalent.
Demonstrates knowledge and/or a proven record of success in the following areas:
Owning incident, problem, and change management activities related to IAM/PAM services, following ITIL practices and using service management platforms such as ServiceNow and Jira.
Developing and maintaining operational documentation, runbooks, knowledge articles, and standard operating procedures (SOPs) to enable consistent delivery and audit readiness.
Driving automation and integration using scripting (PowerShell, Python, Ruby), REST APIs, and tooling (e.g., Postman) to reduce manual effort and improve service reliability.
Collaborating cross-functionally with IT security, risk, compliance, and application owners to onboard systems and validate secure integrations into the IAM architecture.
Monitoring service health, support SLA adherence, perform root cause analysis (RCA) for recurring issues, and recommend continuous improvements.
Identity & Access Management: Active Directory, SailPoint Identity Now IIQ/ISC, CyberArk, Saviynt, Ping Access/Federate, Microsoft Entra ID, Okta, ForgeRock
Scripting & Automation: PowerShell, Python, Ruby, REST APIs
Support & Management Platforms: ServiceNow, Jira, Git
Databases & Protocols: SQL (MSSQL/Oracle), Java fundamentals, SAML, OAuth, OpenID Connect
Utilities: Postman, Putty, WinSCP