Apply now

Apply for Job

AVP, Corporate Enterprise Identity Systems

Date:  6 Oct 2026
Location: 

SG

Company:  StarHub Ltd

Job Description

Role Mission

Make identity StarHub’s enterprise control plane: one canonical identity, Google Workspace / Cloud Identity as the workforce front door, planned AD retirement, and accountable governance of all identities.

Own the end-to-end identity roadmap across architecture, authoritative sources, migration, lifecycle and operations, enabling Zero Trust, AWS, M&A and safe AI adoption.

Accountabilities

  • Own the Identity-Led Enterprise strategy and 18-month roadmap, delivering approved scope, budget and milestones.
  • Own the canonical identity model (Global Person ID), authoritative sources and attribute precedence across SuccessFactors and legacy M&A sources.
  • Establish Google Workspace / Cloud Identity as the sole workforce authentication and SSO front door.
  • Retire AD as a workforce authority: inventory dependencies, then migrate, federate, retire or time-bound exceptions.
  • Govern privileged, non-human and AI-agent identities so privileged/autonomous actions remain attributable to an accountable human.
  • Implement CISO-set identity policy; BTS operates it, while the CISO owns policy, risk acceptance and exceptions.
  • Report status, risks and decisions to the CIO, ISLT and ICC, and own the Identity OKR.

Strategy & Architecture

  • Translate the Identity-Led Enterprise position paper into a phased architecture covering authoritative sources, canonical identity, Google front door, access enforcement, workload access and telemetry.
  • Define AD-to-Google coexistence, including event authority, JML and exit criteria for every AD dependency.
  • Select IGA/PAM tooling that supports the Google-first model without creating a second identity authority.
  • Set integration and onboarding standards for applications, AWS, endpoints, integration and AI platforms.

Delivery & Migration

  • Lead matrixed architecture, security, engineering, project resources and partners; control scope, sequencing, RAID and budget.
  • Deliver migration waves with identity clean-up, role/group rationalisation, orphan-account testing and validated deprovisioning.
  • Automate JML from SuccessFactors and approved contractor/guest workflows, including sponsors, end dates and revalidation.
  • Reconcile MyRepublic, JOS and Strateq under the canonical model using match logic, confidence thresholds, adjudication and merge/unmerge controls.

Governance & Controls

  • Separate standard and privileged personas; enforce named approvals, break-glass controls and quarterly access certification.
  • Maintain a non-human identity registry covering owner, purpose, environment, credentials, review and decommission trigger.
  • Enforce zero net-new unmanaged shared/generic accounts and reduce existing account debt to a published schedule.
  • Govern AI agents as non-human identities with approved purpose, data domains, actions and act-as/on-behalf-of modes, aligned to the IMDA Model AI Governance Framework for Agentic AI.
  • Feed GWS, AWS, endpoints and critical applications into the SIEM using common identity identifiers.
  • Provide audit evidence for identity controls, including CCoP and internal audit.

Qualifications

Team, Vendors & Stakeholders

  • Lead and develop the IAM Specialist across identity engineering, governance and controls.
  • Own the IAM managed-service vendor, including scope, SLAs/KPIs, reviews, change and commercial performance.
  • Retain StarHub design authority and control ownership; build internal capability and reduce vendor dependency under the IS Best Team insourcing strategy.
  • Partner with HR and application/platform owners on data quality, lifecycle, roles, approvals and provisioning.
  • Optimise Google/Microsoft licensing as AD retires; track business-case benefits and report realisation to Finance.

Areas of Impact

  • Zero Trust enforcement across the corporate estate.
  • Single-provider SSO and improved employee/partner sign-in.
  • AD retirement and associated Microsoft licence savings.
  • Fewer orphaned, shared and ownerless accounts and cleaner audits.
  • Safe, attributable AI-agent adoption.
  • Faster, lower-cost future M&A integration.
  • Move Identity from Legacy to Intelligent on the IS estate map by FY30, and Identity & Access from L2 to L4.

Ideal Track Record

  • 12+ years in identity and access management, security architecture or enterprise platforms, including leading at least one enterprise IAM programme end to end.
  • Has led at least one large directory migration or consolidation (for example on-premises AD to a cloud IdP such as Google Cloud Identity, Entra ID or Okta) in an organisation of several thousand identities.
  • Hands-on depth in identity lifecycle and JML automation, IGA, PAM, SSO / federation (SAML, OIDC, SCIM) and access certification.
  • Experience governing non-human identities: service accounts, workload identity, secrets and certificate-based patterns, ideally including AWS IAM.
  • Working knowledge of Zero Trust architecture and emerging identity controls for AI agents.
  • Experience reconciling identities across multiple HR systems or after mergers and acquisitions.
  • Has presented to C-level or board committees and won funding and decisions with clear business cases.
  • Delivers through a lean team and influence: managed-service vendors, system integrators and matrixed teams, with a track record of holding vendors to SLAs and outcomes.
  • Has coached and developed junior engineers or specialists.
  • Familiarity with Singapore requirements (CSA Cybersecurity Code of Practice, PDPA, IMDA AI governance) preferred.
  • Relevant certifications (e.g. CISSP, CISM, CCSP, IDPro CIDPro, Google Cloud or AWS security) are an advantage.

To APPLY NOW, click on Skye!

Apply now

Apply for Job