At TNG Digital, part of TNG Digital Group, we build the tech behind TNG eWallet, one of Malaysia's most used apps for payments and everyday life.
Millions of people rely on us daily, not just to pay, but to manage money, access financial services, and get things done faster and simpler.
Behind it all is a team that likes to question how things are done, move quickly, and try new ideas. If you enjoy solving real problems and seeing your work used at scale, you will feel right at home here.
What You'll Do:
- Responsible in reviewing access control for all existing system, application across enterprise and to propose improvement/enhancement.
- Manage privileged and non-human identities, including service accounts, application identities, RAM Roles, Service Principals, AK/SK, API tokens, certificates, and secrets.
- To consolidate and streamline existing access control (SSO etc), including staff onboarding and offboarding process.
- Overseeing the provisioning and deprovisioning of user accounts, managing access rights, and monitoring user activity to ensure compliance with security policies.
- Design and implement Alibaba Cloud RAM Roles, RAM Policies, STS AssumeRole, RRSA and OIDC federation.
- Manage Alibaba Cloud KMS and Secrets Manager, including KMS instances, keys, secrets, permissions, access policies, rotation, expiration, and lifecycle management.
- Define strict separation between KMS administration, key usage, secret management, and secret-value retrieval.
- Control and review permissions such as Encrypt, Decrypt, GetSecretValue, key management, and secret management based on least privilege.
- Implement secure storage and rotation of AK/SK, API tokens, application secrets, database credentials, certificates, and other sensitive credentials using approved secrets-management solutions.
- Assess requests for long-lived AK/SK and recommend RAM Roles, STS, OIDC, workload identity, or KMS Secrets Manager where technically feasible.
- Manage Microsoft Entra ID App Registrations, Enterprise Applications, Service Principals, Managed Identities, client secrets, certificates, API permissions, and workload identity federation.
- Support secure authentication for applications, scripts, CI/CD pipelines, Kubernetes/ACK workloads, automation, and cloud services.
- Identify and remediate unused, excessive, expired, orphaned, shared, or improperly stored credentials and secrets.
- Establish and enforce credential and cryptographic key rotation standards.
- Monitor privileged identities, KMS activities, secret retrieval, and credential usage for suspicious or unauthorized activities.
- Support periodic User Access Reviews (UAR), privileged-access reviews, service-account reviews, and KMS access reviews.
- Develop automation for identity provisioning, credential rotation, secret lifecycle management, access reviews, and revocation.
- Support audit and regulatory requirements relating to identity, privileged access, cryptographic keys, secrets, and authentication credentials.
- To manage user access to systems, applications, and data with development of proper user matrices
- To monitor compliance with policies, regulations, and customer requirements.
- To assist in all risk assessments and audits related assignments.
- Investigate incidents and recommend corrective actions.
- To instill users awareness on policies and procedures related to IAM via training, email etc
- Stay up to date on evolving threats, technologies, and solutions.
- Collaborate with other departments to ensure secure access to systems and data.
- Maintaining up-to-date knowledge of emerging IAM technologies, trends, and threats, and making recommendations to improve the organization's security posture.
Role Requirements:
- Bachelor's degree in computer science, information technology, or a related field.
- Prior experience in managing cloud security on CSP such as Alicloud, Azure and AWS.
- Minimum of 3 - 5 years of experience in IAM or related fields, such as cybersecurity or information security.
- Experience with IAM technologies, such as identity and access governance, access control systems, and identity federation.
- Experience in IAM solution implementation (project management, working level, hands-on implementation)
- Strong experience designing and governing access controls, SSO, user provisioning/deprovisioning, role-based access, user access matrices and periodic access reviews across enterprise systems.
- Proven ability to manage privileged accounts, service accounts, application identities, API tokens, certificates and other non-human identities throughout their lifecycle.
- Hands-on expertise in Alibaba Cloud RAM, STS, RRSA and OIDC federation, as well as Microsoft Entra ID App Registrations, Service Principals, Managed Identities and workload identity federation.
- Experience managing cryptographic keys and secrets using KMS and Secrets Manager, including least-privilege access, separation of duties, secure storage, rotation, expiration, monitoring and revocation.
- Ability to automate identity and credential processes, monitor suspicious access activities, support incident investigations, and demonstrate compliance with security policies, audits and regulatory requirements.
- Strong knowledge of security frameworks and regulations, such as BNM RMiT, PCI DSS etc.
- Excellent communication and interpersonal skills, with the ability to interact with stakeholders at all levels of the organization.
- Relevant industry certifications, such as Certified Information Systems Security Professional (CISSP) or Certified Information Security Manager (CISM), are preferred.
What You Get
Work your way
Your wellbeing matters
- Medical coverage, with option to include dependants
- Extra leave for family and caregiving needs
Rewards that grow with you
- Monthly lifestyle allowance via TNG eWallet
- Long-term rewards for your contributions
Everyday support
- Mobile and broadband reimbursement
- Discounts and wellness perks
What it's like to work here
We care about people who take ownership, speak up, and want to make things better. Titles matter less than impact. Good ideas can come from anyone.
You will be working with people who are curious, practical, and not afraid to challenge each other in a good way.
Note: Only shortlisted candidates will be contacted.