Technology IAM Security Engineer

Posted 28 May 2026
Salary HKD700000 - HKD950000 per annum
LocationHong Kong
Job type Permanent
Discipline TechnologyLegal
Referenceb19f137e-5e18-4d55-8ca4-2cb86ee26d3f

Job description

About the Role
A leading global professional services firm is seeking an Identity and Access Management (IAM) Security Engineer to join its Technology team. This position plays a critical role in designing, implementing, and operating secure, compliant, and scalable identity services that protect enterprise data and enable business operations.
Key Responsibilities
  • Deliver and manage IAM capabilities across provisioning, authentication, authorization, and identity lifecycle processes.
  • Administer and enhance Microsoft Entra ID (Azure AD) and on‑prem Active Directory, including account lifecycle management, group/role administration, and directory hygiene.
  • Implement and support Single Sign‑On (SSO), Multi‑Factor Authentication (MFA), and Conditional Access controls, ensuring consistent application of authentication standards.
  • Engineer and maintain identity integrations for SaaS and on‑prem applications, including federation and enterprise application configurations.
  • Support Privileged Access Management (PAM) by onboarding privileged identities, implementing credential protection and rotation workflows, and managing access approvals.
  • Execute identity governance workflows such as joiner/mover/leaver processes, access requests, reviews, and remediation activities in coordination with HR and Technology stakeholders.
  • Implement secure cloud identity solutions for human and workload identities, aligned to organizational standards and least‑privilege principles.
  • Contribute to certificate lifecycle management, including inventory, issuance/renewal processes, automation, and platform maintenance.
  • Automate IAM operations through scripting and workflows to improve efficiency, consistency, and reliability.
  • Monitor IAM systems and partner with Cybersecurity teams to resolve issues or anomalies.
  • Develop and maintain documentation, procedures, and runbooks for IAM systems and integrations.
  • Participate in on‑call rotation and provide after‑hours support as required.
Qualifications
  • Solid experience in IAM engineering, with expertise in Entra ID (Azure AD), Active Directory, SSO/MFA/Conditional Access, PAM, and identity governance.
  • Familiarity with cloud identity solutions (AWS) and certificate lifecycle management.
  • Proficiency in automation and scripting to streamline IAM operations.
  • Strong collaboration skills with cross‑functional teams including Cybersecurity, HR, and business stakeholders.
  • Excellent communication skills and commitment to service excellence.
If you believe you have the right skills, attitude and experience please click 'apply now' below and upload your resume. Alternatively, for a confidential chat, please contact Kevin Ng by applying directly to email kng@captarpartners.com or reach out at +852 3901 8736.

We apologies that only shortlisted candidates will be contacted.