Role Purpose
The Senior IAM Lead is accountable for the day-to-day delivery, control and continuous improvement of identity and access management services within a large Singapore public healthcare environment. The role leads a sizeable operational team, protects service levels, strengthens access governance and serves as a trusted link between the client, clinical and corporate users, application owners, audit stakeholders and delivery teams.
Key Responsibilities
1. IAM Operations and Service Delivery
- Lead daily IAM operations across at least 50 enterprise or healthcare applications, covering user provisioning, access modification, de-provisioning, revalidation and authentication or authorisation support.
- Direct ticket assignment, request prioritisation, queue management, backlog reduction and escalation handling to achieve contractual service levels and operational targets.
- Coordinate access readiness for employee onboarding, transfers, postings, rotations, project mobilisation and separation activities.
- Maintain disciplined operating procedures, knowledge records and handover controls to support consistent and reliable service delivery.
2. Team Leadership and Performance
- Lead, coach and develop a sizeable team of ID Administrators, setting clear ownership, quality expectations and performance standards.
- Allocate resources dynamically based on demand, capacity, ageing requests, priority cases, planned activities and client escalations.
- Conduct regular operational reviews, address capability or conduct gaps and build a culture of accountability, collaboration and continuous improvement.
3. Client and Stakeholder Management
- Act as the primary operational point of contact for IAM service matters and provide clear, timely updates on performance, risks, escalations and recovery actions.
- Lead client service reviews and coordinate resolution across ID Administration, application, infrastructure, security and support teams.
- Translate technical and operational issues into practical recommendations for business and management stakeholders.
4. Access Governance, Risk and Audit
- Ensure access is provisioned in line with approved roles, least-privilege principles, segregation requirements and applicable policies.
- Oversee role-based access control checks, privileged access governance, periodic access reviews, exception investigation and remediation tracking.
- Support internal and external audits by coordinating evidence, explaining operational controls, responding to queries and closing findings within agreed timelines.
- Maintain compliance with applicable privacy, security and client requirements, including PDPA and controls relevant to regulated environments.
5. Reporting, Controls and Continuous Improvement
- Monitor SLA performance, service quality, recurring incidents, control exceptions and operational risk initiate corrective and preventive action where required.
- Produce accurate management and client reporting covering volumes, backlog, ageing, productivity, quality, escalations, audit matters and improvement actions.
- Use PowerShell, Excel Power Query, Office Scripts, Power BI or similar tools to streamline evidence preparation, reporting and repetitive workflows.
- Contribute to root-cause analysis and service-improvement initiatives that strengthen security, efficiency and end-user experience.
Requirements
- At least 4 years of relevant experience spanning IAM or ID administration, access governance, IT security operations and SLA-based technology service delivery.
- Current or recent experience leading an IAM or ID Administration operation of at least 20 team members, including work allocation, queue control, coaching, escalations and performance oversight.
- Demonstrated responsibility for IAM delivery across at least 50 enterprise applications in a large, complex user environment.
- Direct experience supporting Singapore public healthcare or an equivalent highly regulated, privacy-sensitive critical-services environment public healthcare experience will be strongly prioritised.
- Strong working knowledge of the Joiner-Mover-Leaver lifecycle, RBAC, least privilege, access reviews, privileged access governance and audit evidence management.
- Hands-on experience with Microsoft Active Directory and PAM technology, together with ServiceNow, IBM Control Desk or a comparable enterprise ITSM platform.
- Proven ownership of client-facing SLA reviews, operational escalations, internal or external audit meetings, evidence requests and remediation follow-up.
- Practical reporting or workflow-automation capability using PowerShell and advanced Excel tools such as Power Query or Office Scripts.
- ITIL 4 Foundation and a recognised entry-level or higher cybersecurity certification, such as ISC2 Certified in Cybersecurity (CC), Security+ or equivalent.
- Clear written and verbal communication, sound judgement, structured problem-solving and the confidence to lead under operational pressure.
Additional Advantages
- Diploma or degree in information technology, cybersecurity, business, accounting or a related discipline.
- Hands-on exposure to endpoint-security operations, security incident triage, endpoint firewall controls and NIST-aligned controls.
- Experience producing client-ready dashboards or management reporting using Power BI or Microsoft 365 tools.