Senior Security Analyst I, Identity & Access Management
__jobinformationwidget.freetext.LocationText__
Singapore, sg
- Corporate
- Hybrid
- Full-time
About AbbVie
AbbVie's mission is to discover and deliver innovative medicines and solutions that solve serious health issues today and address the medical challenges of tomorrow. We strive to have a remarkable impact on people's lives across several key therapeutic areas including immunology, oncology and neuroscience - and products and services in our Allergan Aesthetics portfolio. For more information about AbbVie, please visit us at www.abbvie.com. Follow @abbvie on LinkedIn, Facebook, Instagram, X and YouTube.
This position is part of the Information Security & Risk Management (ISRM) team. We are here to put our partners in a position to succeed — providing the knowledge, tools, and governance frameworks they need to use data and technology securely while managing risk at enterprise scale.
We are looking for a highly motivated, technically skilled identity professional to join our Identity and Access Management (IAM) team. This role is critical in safeguarding the enterprise by ensuring that user access is accurate, compliant, and aligned with global security standards. The IAM Senior Security Analyst I will drive the full lifecycle of identity governance across OIM, Saviynt, Active Directory, and other enterprise identity systems — enabling secure, seamless access for employees, contractors, and partners worldwide.
The ideal candidate brings deep hands-on expertise in identity administration and governance, a strong understanding of compliance frameworks, and the ability to work independently to drive improvements across people, processes, and technology.
Key Responsibilities
- Act as a subject matter expert for identity lifecycle events — joiner, mover, and leaver — across global user populations, ensuring timely and accurate execution within established SLAs
- Drive access provisioning and governance activities in accordance with least-privilege and Segregation of Duties (SoD) principles, validating approvals against business rules and compliance requirements
- Lead and support periodic access certification and recertification campaigns within Saviynt, identifying anomalies and driving remediation
- Create, modify, and maintain federation and SSO application integrations, resolving identity-related incidents including login failures, MFA issues, and provisioning errors
- Identify process improvement opportunities and develop plans of action with minimal management intervention or direction
- Collaborate cross-functionally with IT support teams, application owners, and security engineers to remediate access issues and reduce manual workload through automation
- Maintain documentation and audit evidence to support internal and external audits, ensuring adherence to SOX, GDPR, and ISO 27001 requirements
- Contribute to enhancements in Saviynt workflows, access request forms, and role models; support rollout of new IAM capabilities and governance policies
- Monitor automated provisioning workflows, escalate failures, and drive continuous improvement in IAM operational reliability
Basic Qualifications
- Demonstrated expertise in identity administration, including SSO, MFA, automated lifecycle workflows, and API integrations
- Strong hands-on experience with Oracle Identity Manager (OIM), Saviynt, Ping, and Active Directory
- Expert-level understanding of IAM terminology, governance frameworks, and access certification methodologies
- Familiarity with regulatory and compliance frameworks as they apply to identity and access (SOX, GDPR, ISO 27001)
- Experience with ServiceNow for ITSM and access request workflows
- Ability to author clear and concise incident and audit reports
- Ability to work independently without direction for day-to-day activities, while proactively identifying and closing gaps
- Strong communication and cross-functional collaboration skills, including the ability to translate technical concepts for non-technical stakeholders
- Education & Experience — Minimum of one of the following:
- Minimum of 8 years of IT experience with 6 years in a specialized information security role
- Bachelor's Degree in Computer Science or related technical field and 5+ years of specialized IAM or information security experience
- Master's Degree in Computer Science or related technical field and 4 years of specialized experience
Desired Qualifications
- Experience administering identity governance in enterprise cloud environments (Azure AD, AWS IAM, or similar)
- Familiarity with scripting or automation (e.g., PowerShell, Python) to support IAM workflow improvements
- Experience with Privileged Access Management (PAM) platforms such as BeyondTrust or CyberArk
- Relevant certifications such as Saviynt, CISSP, or CISM
AbbVie is an equal opportunity employer and is committed to operating with integrity, driving innovation, transforming lives and serving our community. Equal Opportunity Employer/Veterans/Disabled.
US & Puerto Rico only - to learn more, visit https://www.abbvie.com/join-us/equal-employment-opportunity-employer.html
US & Puerto Rico applicants seeking a reasonable accommodation, click here to learn more:
https://www.abbvie.com/join-us/reasonable-accommodations.html
We have recently become aware of various recruitment phishing scams targeting job seekers. Please be advised:
- AbbVie will never request sensitive personal information (such as bank account details, social security numbers, or payment of any kind) during the recruitment process.
- If you suspect you have received a fraudulent offer or communication claiming to be from AbbVie, please do not respond, open any attachments, or click on any hyperlinks.
If you have any questions or concerns regarding the authenticity of a communication alleged to have been made by or on behalf of AbbVie, please contact us immediately.
Protect yourself by verifying job offers and communications. Your safety is important to us.
Pay Range: $
-
Where We Work
Role is primarily site- or office-based but can occasionally be performed remotely. Employees who are site/office-based and can occasionally perform their role virtually work both in the office and remotely*, following the policies and regulations in place at their location. US Employees must be in the office on Tuesday, Wednesday, and Thursday with flexibility to work remotely on Mondays and Fridays. Three days in the office is the minimum; some individuals or teams may require more in-office days due to meetings, business/project needs or their role.