SVP, Identity Security Management & Governance Singapore, Singapore, Singapore 8 - 10 Years Permanent - Full Time
Job Description
Singlifeis a leading homegrown financial services company, offering consumers a betterway to financial freedom. Through innovative, technology-enabled solutions anda wide range of products and services, Singlife provides consumers coantrolover their financial wellbeing at every stage of their lives.
Inaddition to a comprehensive suite of insurance plans, employee benefits,partnerships with financial adviser channels and bancassurance, Singlife offersinvestment and advisory solutions through its GROW with Singlife platform. Italso offers the Singlife Account, a mobile-first insurance savingsplan.
Singlifeis the exclusive insurance provider for the Ministry of Defence, Ministry ofHome Affairs and Public Officers Group Insurance Scheme. Singlife is also anofficial signatory of the United Nations Principles for Sustainable Insuranceand the United Nations-supported Principles for Responsible Investment,affirming its commitment to finding a better way to sustainability.
Themerger of Aviva Singapore and Singlife was announced in September 2020 andcreated one of the largest homegrown financial services companies in Singaporein a deal valued at S$3.2 billion. It was the largest insurance deal inSingapore at the time. Singlife was subsequently acquired by Sumitomo Life inMarch 2024, one of Japan’s leading life insurers, which valued Singlife atS$4.6 billion, making the transaction one of the largest insurance deals inSoutheast Asia.
Purpose:
Providesenior strategic leadership and executive ownership of the enterprise Identity& Access Management (IAM) and Privileged Access Management (PAM) function, spanningSystem Access Management, Identity Governance & Administration (IGA), IAMplatform operations and identity lifecycle management.
As a Senior Vice President, the role leads and develops the IAM/PAM leadershipand delivery teams, and is accountable for defining and executing theenterprise IAM/PAM strategy, operating model and multi-year transformationroadmap in alignment with business, technology and regulatory objectives.
The role provides executive oversight of audit and regulatory engagementsrelating to identity controls, ensures secure, compliant and resilient identityservices, drives automation and continuous improvement across the IAMecosystem, and represents the function to executive management, regulators,auditors and governance committees.
Responsibilities:
TeamLeadership & People Management
- Lead,mentor and develop the IAM/PAM leadership team and delivery functions,including System Access Operations, PAM Operations, IGA Engineering &Operations and 24x7 IAM/PAM support.
- Setdirection, performance objectives and delivery standards across all IAM/PAMteams, fostering a culture of accountability, collaboration and continuousimprovement.
- Buildlong-term organisational capability through succession planning, talentdevelopment, leadership coaching and workforce planning.
- Managevendors and managed service providers, ensuring performance, value and servicequality across a 24x7 operating model.
- Defineand own the enterprise IAM/PAM strategy, operating model and multi-yeartransformation roadmap across System Access Management, PAM and IGAcapabilities.
- Setthe strategic direction for identity modernisation, automation and Zero Trustadoption across on-premise, cloud and SaaS environments.
- Extendidentity governance to machine and non-human identities (service accounts,workloads, API and AI/agentic identities), and drive cryptographic-agility andpost-quantum readiness across IAM/PAM secrets and credentials.
- OwnIAM/PAM financial planning, including budget management, vendor contracts,licence optimisation and investment prioritisation.
- Driveenterprise onboarding, entitlement modelling, role engineering and accessgovernance design to support digital transformation initiatives.
Audit& Regulatory Oversight
- Provideexecutive oversight of, and act as senior point of contact for, internal andexternal audit engagements
- relatingto IAM/PAM controls, including evidence provision and remediation management.
- Actas the technology risk owner for IAM/PAM platforms and services, ensuring risksare identified, assessed, mitigated and reported appropriately.
- Ensurecompliance with MAS TRM guidelines, FSM-N04 Cyber Hygiene requirements,internal policies and industry best practices.
- EstablishIAM/PAM standards, policies and governance frameworks, and advocate identityhygiene and compliance with Singlife security policies and standards.
IAM/PAMOperations & Governance
- Providestrategic oversight of System Access operations (Joiner, Mover, Leaver), PAMoperations (CyberArk onboarding, privileged credential and session management,breakglass) and IGA operations (HR-to-AD integration, birthright provisioning).
- Ensurecontinuity, effectiveness and resilience of IGA and PAM solutions, includingdisaster recovery, business continuity and cyber recovery capabilities.
- Provideregular executive reporting on IAM/PAM operational health, risk posture, auditstatus and strategic initiatives to the CISO, CIO and relevant governancecommittees.
Requirements:
- Bachelor'sdegree in Computer Science, Information Security, Information Systems,Engineering or a related discipline.
- Minimum10 years of experience in Information Technology, Cyber Security or Identity& Access Management disciplines.
- Minimum8 years of direct experience across IAM domains including System AccessManagement, Privileged Access Management (PAM), Identity Governance &Administration (IGA) and Identity Lifecycle Management.
- Minimum5 years of senior leadership experience managing IAM/PAM teams, leaders,vendors or managed service providers.
- Proventrack record defining and executing enterprise IAM/PAM strategy and multi-yeartransformation roadmaps in highly regulated environments such as financialservices, insurance or banking.
- Demonstratedexperience providing executive oversight of audit and regulatory engagementsrelating to identity controls.
- Strongunderstanding of identity concepts, including:
- Joiner, Mover andLeaver (JML)
- Enterprise roles androle hierarchy
- Entitlements andfine-grained permissions
- Role Based AccessControl (RBAC)
- Attribute BasedAccess Control (ABAC)
- Segregation of Duties(SoD)
- Access certificationand recertification
- Machine and Humanidentities
- Privileged AccessManagement
- Goodunderstanding of SAML, OAuth2, OpenID Connect (OIDC), LDAP and SCIM.
- Ableto contribute to IAM solutioning, role engineering, entitlement modelling andaccess governance design.
- Experiencesupporting audit and regulatory requirements including MAS TRM, FSM-N04,Internal Audit and External Audit activities.
- Professionalcertifications such as CISSP, CISM, CyberArk or Saviynt certifications arehighly desirable.