NG
Hiring from
Malaysia
Work type
Remote
Posted
Sep 25, 2026
Is this job info correct?

IAM Security Architect At Provido , we’re more than a technology company. We are a global hub of innovation, creativity, and engineering excellence. Our teams design and deliver intelligent, secure, and high-performance digital solutions that help organizations modernize operations, scale their platforms, and succeed in an increasingly digital world. As part of a dynamic international ecosystem, we bring together forward-thinking engineers, technology specialists, designers, and delivery professionals who transform ideas into scalable, real-world solutions with measurable business impact. If you are motivated by challenge, inspired by technology, and ready to grow with a company that truly invests in its people, your journey starts here. 👉 Why We Need You The IAM Security Architect is responsible for designing, governing, and continuously improving the organization’s identity and access management security architecture, with a primary focus on Microsoft Azure and Microsoft Entra ID. This role defines secure, scalable, and auditable identity patterns for workforce, privileged, application, and external access across cloud, hybrid, and enterprise environments. The architect will lead the design of Microsoft Entra ID capabilities including Conditional Access, Privileged Identity Management, Identity Governance, Identity Protection, access reviews, entitlement management, single sign-on, application registration governance, and hybrid identity integration. While awareness of other cloud platforms is expected, the role is primarily centered on Azure and Entra as the strategic identity control plane for Zero Trust, least privilege, compliance, and operational resilience. 👉 What You’ll Be Doing Design and maintain enterprise IAM security architecture with a primary focus on Microsoft Azure, Microsoft Entra ID, Microsoft 365 identity integrations, and hybrid identity environments. Architect and govern Microsoft Entra ID capabilities including Conditional Access, Multi-Factor Authentication, Identity Protection, Privileged Identity Management, Access Reviews, Entitlement Management, and lifecycle workflows. Define and enforce Zero Trust and least-privilege access models across users, administrators, service principals, managed identities, applications, groups, and Azure resources. Lead secure design for authentication and authorization flows, including SAML, OAuth 2.0, OpenID Connect, SCIM provisioning, federation, single sign-on, and application access integration patterns. Govern Azure application registrations, enterprise applications, API permissions, consent settings, secrets, certificates, service principals, and workload identities to reduce privilege escalation and OAuth abuse risks. Design privileged access controls using Entra Privileged Identity Management, just-in-time elevation, approval workflows, break-glass account controls, privileged access reviews, and administrative role hardening. Develop identity security standards, reference architectures, design patterns, roadmaps, and control requirements aligned with security policy, regulatory expectations, and audit readiness. Partner with security engineering, cloud platform, infrastructure, application, GRC, SOC, and business teams to embed identity controls into projects, migrations, and operational processes. Support identity risk assessment, control validation, incident response, and remediation activities involving compromised accounts, excessive privileges, risky sign-ins, misconfigured applications, or identity governance gaps. 👉 What You Bring to the Team Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, Engineering, or a related discipline; equivalent professional experience may be considered. 5+ years of experience in cybersecurity, identity and access management, cloud security, security architecture, or infrastructure security, with significant hands-on experience in Microsoft identity platforms. Deep knowledge of Microsoft Entra ID, Azure RBAC, Conditional Access, MFA, Identity Protection, Privileged Identity Management, Access Reviews, Entitlement Management, and identity lifecycle governance. Strong understanding of Active Directory, hybrid identity, Entra Connect or Cloud Sync, federation, directory synchronization, Microsoft 365 identity dependencies, and enterprise authentication patterns. Experience designing SSO and application integration patterns using SAML, OAuth 2.0, OpenID Connect, SCIM, APIs, service principals, managed identities, and application registration governance. Ability to translate business, regulatory, and security requirements into practical identity architecture, control standards, implementation roadmaps, and operational guardrails. Strong written and verbal communication skills, including the ability to influence technical teams, present architecture decisions, document standards, and engage senior stakeholders. Experience supporting audit, compliance, control testing, access certification, identity risk remediation, and evidence generation for regulated or compliance-focused environments. 👉 Preferred Skills Microsoft certifications such as Microsoft Certified: Cybersecurity Architect Expert, Azure Solutions Architect Expert, Azure Security Engineer Associate, Identity and Access Administrator Associate, or Microsoft 365 Enterprise Administrator Expert. Security certifications such as CISSP, CISM, CCSP, or equivalent architecture, governance, or cloud security credentials. Experience with Microsoft Sentinel, Microsoft Defender for Cloud, Defender for Identity, Defender for Cloud Apps, Azure Key Vault, and identity-related detection or monitoring use cases. Experience automating IAM and Azure security controls using PowerShell, Microsoft Graph API, Azure CLI, Terraform, Bicep, ARM templates, or CI/CD pipelines. Knowledge of Zero Trust architecture, NIST Cybersecurity Framework, ISO 27001, CIS benchmarks, least privilege, separation of duties, and privileged access governance. Exposure to non-Microsoft cloud IAM capabilities such as AWS IAM or Google Cloud IAM is beneficial, but the role remains primarily focused on Azure and Microsoft Entra. 👉 Why You’ll Love Working with Us ☐ Employee Benefits & Advantages At Provido, we value our employees and nurture a culture of progress and creativity. Our team members enjoy a supportive, inclusive, and growth-focused environment. ☐ Competitive Compensation & Performance Incentives Provido offers an attractive salary package and performance-based bonuses to recognize and reward your contribution. ☐ Flexible Working Options We support remote and hybrid working models to help you maintain a healthy work-life balance. ☐ Health & Well-being Support We provide comprehensive health insurance, wellness initiatives, and resources to support both physical and mental well-being. ☐ Career Advancement & Development Programs We invest in continuous learning through training programs, mentorship, and clearly defined career development paths. ☐ Team-Oriented & Inclusive Workplace Our culture is built on diversity, inclusion, and collaboration. Every voice matters and innovation is encouraged. ☐ Team Events & Social Activities We organize regular team-building activities and social events to strengthen relationships and create a positive, connected workplace. Division Provido Location Malaysia Remote status Fully Remote Employment type Contract Job Category Tech Job About Provido Provido provides wholesale IT, network, data storage and processing infrastructure services: the layer applications stand on. Every service level is defined up front, then measured and reported, month after month. Applicant tracking system by Teamtailor

Similar jobs

Apply for this job