Apply now
Apply for Job
AVP, Corporate Enterprise Identity Systems
Date:
6 Oct 2026
Location:
SG
Company:
StarHub Ltd
Job Description
Role Mission
Make identity StarHub’s enterprise control plane: one canonical identity, Google Workspace / Cloud Identity as the workforce front door, planned AD retirement, and accountable governance of all identities.
Own the end-to-end identity roadmap across architecture, authoritative sources, migration, lifecycle and operations, enabling Zero Trust, AWS, M&A and safe AI adoption.
Accountabilities
- Own the Identity-Led Enterprise strategy and 18-month roadmap, delivering approved scope, budget and milestones.
- Own the canonical identity model (Global Person ID), authoritative sources and attribute precedence across SuccessFactors and legacy M&A sources.
- Establish Google Workspace / Cloud Identity as the sole workforce authentication and SSO front door.
- Retire AD as a workforce authority: inventory dependencies, then migrate, federate, retire or time-bound exceptions.
- Govern privileged, non-human and AI-agent identities so privileged/autonomous actions remain attributable to an accountable human.
- Implement CISO-set identity policy; BTS operates it, while the CISO owns policy, risk acceptance and exceptions.
- Report status, risks and decisions to the CIO, ISLT and ICC, and own the Identity OKR.
Strategy & Architecture
- Translate the Identity-Led Enterprise position paper into a phased architecture covering authoritative sources, canonical identity, Google front door, access enforcement, workload access and telemetry.
- Define AD-to-Google coexistence, including event authority, JML and exit criteria for every AD dependency.
- Select IGA/PAM tooling that supports the Google-first model without creating a second identity authority.
- Set integration and onboarding standards for applications, AWS, endpoints, integration and AI platforms.
Delivery & Migration
- Lead matrixed architecture, security, engineering, project resources and partners; control scope, sequencing, RAID and budget.
- Deliver migration waves with identity clean-up, role/group rationalisation, orphan-account testing and validated deprovisioning.
- Automate JML from SuccessFactors and approved contractor/guest workflows, including sponsors, end dates and revalidation.
- Reconcile MyRepublic, JOS and Strateq under the canonical model using match logic, confidence thresholds, adjudication and merge/unmerge controls.
Governance & Controls
- Separate standard and privileged personas; enforce named approvals, break-glass controls and quarterly access certification.
- Maintain a non-human identity registry covering owner, purpose, environment, credentials, review and decommission trigger.
- Enforce zero net-new unmanaged shared/generic accounts and reduce existing account debt to a published schedule.
- Govern AI agents as non-human identities with approved purpose, data domains, actions and act-as/on-behalf-of modes, aligned to the IMDA Model AI Governance Framework for Agentic AI.
- Feed GWS, AWS, endpoints and critical applications into the SIEM using common identity identifiers.
- Provide audit evidence for identity controls, including CCoP and internal audit.
Qualifications
Team, Vendors & Stakeholders
- Lead and develop the IAM Specialist across identity engineering, governance and controls.
- Own the IAM managed-service vendor, including scope, SLAs/KPIs, reviews, change and commercial performance.
- Retain StarHub design authority and control ownership; build internal capability and reduce vendor dependency under the IS Best Team insourcing strategy.
- Partner with HR and application/platform owners on data quality, lifecycle, roles, approvals and provisioning.
- Optimise Google/Microsoft licensing as AD retires; track business-case benefits and report realisation to Finance.
Areas of Impact
- Zero Trust enforcement across the corporate estate.
- Single-provider SSO and improved employee/partner sign-in.
- AD retirement and associated Microsoft licence savings.
- Fewer orphaned, shared and ownerless accounts and cleaner audits.
- Safe, attributable AI-agent adoption.
- Faster, lower-cost future M&A integration.
- Move Identity from Legacy to Intelligent on the IS estate map by FY30, and Identity & Access from L2 to L4.
Ideal Track Record
- 12+ years in identity and access management, security architecture or enterprise platforms, including leading at least one enterprise IAM programme end to end.
- Has led at least one large directory migration or consolidation (for example on-premises AD to a cloud IdP such as Google Cloud Identity, Entra ID or Okta) in an organisation of several thousand identities.
- Hands-on depth in identity lifecycle and JML automation, IGA, PAM, SSO / federation (SAML, OIDC, SCIM) and access certification.
- Experience governing non-human identities: service accounts, workload identity, secrets and certificate-based patterns, ideally including AWS IAM.
- Working knowledge of Zero Trust architecture and emerging identity controls for AI agents.
- Experience reconciling identities across multiple HR systems or after mergers and acquisitions.
- Has presented to C-level or board committees and won funding and decisions with clear business cases.
- Delivers through a lean team and influence: managed-service vendors, system integrators and matrixed teams, with a track record of holding vendors to SLAs and outcomes.
- Has coached and developed junior engineers or specialists.
- Familiarity with Singapore requirements (CSA Cybersecurity Code of Practice, PDPA, IMDA AI governance) preferred.
- Relevant certifications (e.g. CISSP, CISM, CCSP, IDPro CIDPro, Google Cloud or AWS security) are an advantage.
Apply now