[What the role is]
As an Identity & AI Security Specialist, you will strengthen HDB’s identity security capabilities and enable the secure adoption of Generative AI and agentic AI. Working with system owners, architects, operations teams, governance functions and partners, you will design, implement, administer and operate security controls and the supporting infrastructure for human identities, privileged accounts, service and workload identities, application credentials and AI agents across on-premises, cloud and AI-enabled environments. You will also help maintain the security, availability, performance and resilience of enterprise identity and AI security platforms and their underlying infrastructure.
[What you will be working on]
- Shape identity and AI security: Review and improve policies, standards, referencearchitecturesand control requirements in line with the threat landscape, regulatoryobligationsand industry practices.
- Assess and reduce risk: Identifygaps affecting human, privileged, machine and AI identities; conduct securityriskassessments; and recommend practical remediation measures and security solutions.
- Engineer identity controls: Design, implement and enhance IAM, IGA, PAM, PIM, MFA, SSO, Conditional Access, RBAC, just-in-time access and access-governance capabilities across hybrid environments.
- Govern the identity lifecycle: Establishcontrols for privileged accounts, service accounts, application identities, API credentials, workloadidentitiesand AI agents, including discovery, onboarding, recertification, credentialrotationand decommissioning.
- Secure AI use cases: Review Generative AI and agentic AI solutions and define controls for agent authentication and authorisation, tool and data access, secrets, prompt injection, excessive agency, data leakage, human approval,loggingand auditability.
- Maintain identity and AI security infrastructure: Administer,operateand maintain enterprise identity and AI security platforms and their underlying infrastructure. Monitor system health, capacity, availability, performance,securityand integration dependencies; perform patching, upgrades, hardening,backupand recovery activities; troubleshoot technical issues; and coordinate maintenance and technology refreshes with internal teams and vendors.
- Deliver secureand resilientsolutions: Translate business, infrastructureand security requirements into solution designs and implementation plans; coordinate configuration, integration, testing,deploymentandoperational handover;andmanagelifecycle upgrades, capacity needs,resilienceand technology refresh activities.
- Automate and integrate: Develop scripts, APIintegrationsand workflows to improve identity discovery, provisioning, access reviews, credential management,monitoringand remediation.
- Operate and respond: Monitorthe health, availability, performance and security posture ofidentity and AI securityplatforms and their supporting infrastructure. Investigatealerts, servicedisruptionsand securityincidents; performroot-cause analysis;and implementtimelyrecovery,containment,remediationand preventivemeasures.
- Support assurance: Maintaintechnical documentation, operatingproceduresand control evidence; support audits and assessments; and ensure excessive,dormantor unauthorised access is remediated promptly.
- Communicate outcomes: Analyse risks, trends and control effectiveness, and present clear recommendations and management reports to technical and non-technical stakeholders.
[What we are looking for]
- Have a degree in cybersecurity, computer science, information systems, engineering or a related discipline, or equivalent relevant professional experience.
- Have at least 3 years of relevant experience in identity security, cybersecurity engineering, infrastructureoperationsor security architecture, including hands-on experience implementing,administeringorsupporting enterprise identity and AI security platforms and their underlying infrastructure.
- Have practical knowledge of enterprise infrastructure operations, including Windows Server or Linux administration, platform monitoring, system hardening, patching, backup and recovery, high availability, capacity management, changemanagementand technical troubleshooting.
- Understand identity lifecycle management, authentication, authorisation, Zero Trust, least privilege, segregation of duties, privileged access, accessreviewsand identity-related threat scenarios.
- Have working knowledge of enterprise identity technologies and integration patterns, including Active Directory or Microsoft Entra ID, SAML 2.0, OAuth 2.0, OpenID Connect, SCIM, LDAP, Kerberos,federationand REST APIs.
- Can analyse complex security and operational issues, translate requirements into practical controls, and troubleshoot identity integrations and access-related incidents.
- Can work effectively with system owners, architects, operations teams,auditorsand vendors, and communicate technical risks and recommendations clearly to different audiences.
- Are organised, outcome-focused and able tomaintainclear technical documentation, operatingproceduresand implementation records.
Good tohave
- Experience with identity governance, privilegedaccessand secrets-management platforms.
- Experience with cloud IAM, CIEM, identity threat detection and response, non-human identity governance, workloadidentitiesor hybrid identity environments.
- Experience conducting security architecture reviews, threat modelling or risk assessments for Generative AI, agenticAIor other emerging technologies.
- Proficiencyin PowerShell, Python or similar languages for security automation, APIintegrationand orchestration; exposure to infrastructure as code orDevSecOpspractices is an advantage.
- Relevant certifications such as CISSP, CISM, CCSP or equivalent.