Identity And Access Management Systems Operations Engineer
Do you want your voice heard and your actions to count? Discover your opportunity with Mitsubishi UFJ Financial Group (MUFG), one of the world's leading financial groups. Across the globe, we're 150,000 colleagues, striving to make a difference for every client, organization, and community we serve. We stand for our values, building long-term relationships, serving society, and fostering shared and sustainable growth for a better world.
With a vision to be the world’s most trusted financial group, it's part of our culture to put people first, listen to new and diverse ideas and collaborate toward greater innovation, speed and agility. This means investing in talent, technologies, and tools that empower you to own your career.
Join MUFG, where being inspired is expected and making a meaningful impact is rewarded.
The Identity And Access Management Systems Operations Engineer oversees and manages the IAM solutions operations to mitigate IT risk to MUFG Bank across Asia Pacific region. This position is accountable for the overall development of strategic roadmap in the access control domain and ensures alignment with the overall global access management strategy.
IAM Functions
- Ensure identity access management systems does the identity management in accordance with global IAM policy, regulatory guidelines, established standards and procedures.
- Support to define the regional identity access management strategy and roadmap to provide end-to-end user life cycle management capabilities and enhance detective control to prevent any unauthorized access.
- Continuously review, perform gap analysis and identify opportunities to streamline and automate user access control for the region to ensure that the design controls are effective and efficient.
- Support to manage and perform risk assessment for new system on-boarding and system enhancement to ensure relevant security controls (preventive, detective, mitigation) in user access control, audit trail and security log monitoring requirements are incorporated into new/enhance systems prior to system rollout.
- Support to manage regional Identity access management project and initiatives to ensure the objectives and capability are delivered within scope, on time and on budget.
- Collaborate with Asia Pacific branches to define a regional user access control standards and established roles and responsibilities for administration of user access system/ applications.
- Establish and promote adoption of regional toolset, standards, and processes for user access management in APAC region as part of a team.
- Provides support for both internal and external audit inspection activities, draft responses as required from the local authorities, second or third line of defences.
- Lead as subject matter expert in the technologies for identity and access management and implement enterprise-wide identity services to support regional users.
Job Requirements
- Perform day-to-day IAM operations, including user provisioning, de-provisioning, access reviews, role assignments, and entitlement management.
- Support Oracle Identity Governance (OIG) operations such as certification campaigns, workflow monitoring, and policy enforcement.
- Manage CyberArk operational tasks including account onboarding, credential rotation, session monitoring, and vault administration.
- Develop and maintain automation scripts (PowerShell, Python, APIs) to automate repetitive IAM tasks.
- Assist with risk and compliance activities, including evidence collection, audit responses, and access certification support.
- Monitor and report on IAMS system health, performance, and security controls.
- Work with IT and security teams to ensure IAM operations align with organizational policies and compliance requirements.
- Document operational processes, standard procedures, and access workflows for audit and knowledge management.
- Support incident management by troubleshooting IAM-related issues and escalating where necessary.
- Understanding of different SSO protocols e.g SAML 2.0, OAuth/OIDC and Multi-Factor authentication
Job Requirements
- Min 6 years of professional experience in IAM operations or related security domains.
- Experience of Oracle Identity Governance (OIG) concepts including provisioning, workflows, policies, and certification campaigns.
- Experience with CyberArk Privileged Access Management for account management, password rotation, and monitoring.
- Hands-on skills in automation and scripting (PowerShell, Python, REST APIs, or similar).
- Experience in IAM fundamentals: authentication, authorization, RBAC, least privilege, and SoD.
- Familiarity with risk and compliance frameworks (SOX, GDPR, MAS TRM, NIST).
- Good troubleshooting, problem-solving, and communication skills to support cross-functional teams.
- Exposure and hands on experience to IAM platforms (Oracle, CyberArk, Entra).
- Experience working with ticketing/ITSM tools (ServiceNow, Jira, etc.) for IAM request fulfillment.
- Certifications such as CyberArk Defender, Oracle IGA Specialist, or IT security certifications (CISSP, CISM)
Mitsubishi UFJ Financial Group (MUFG) is an equal opportunity employer. We view our employees as our key assets as they are fundamental to our long-term growth and success. MUFG is committed to hiring based on merit and organizational fit, regardless of race, religion or gender.