Lead Engineer – Identity & Access Security
Dyson is hiring a Lead Engineer – Identity & Access Security in Kuala Lumpur, Malaysia. Level rates it ; you can apply on Level.
AI in this role
Lead Identity and Access Security Engineer designing and operating identity protection controls, zero-trust access, and IAM frameworks.
Role Purpose
As the Identity and Access Security Engineer, you are accountable for designing, engineering, and operating robust identity security controls that protect workforce identities, endpoint devices, and corporate access pathways across the enterprise.
Operating as a technical specialist, you will enforce strong authentication, zero-trust access, and identity governance controls. By engineering seamless protection mechanisms, managing privileged accounts, and securing Joiner, Mover, and Leaver processes, you will mitigate identity threats and continuously harden authentication pathways against compromise.
In this role, you will lead and manage the following domains:
Conditional Access and Authentication: Designing and managing Conditional Access policies, MFA, and passwordless capabilities.
Privileged Identity Management (PIM): Engineering and governing high-privilege access workflows and just-in-time access controls.
Identity Lifecycle and Governance: Implementing secure Joiner, Mover, and Leaver processes and identity lifecycle frameworks.
Identity Threat Monitoring and Remediation: Monitoring identity-centric attack vectors and rapidly remediating active authentication weaknesses.
Identity Improvement Initiatives: Leading technical projects aimed at modernizing and securing federation and single sign-on (SSO) pathways.
Key Skills and Qualifications
- Bachelor's degree in computer science, Cybersecurity, Information Technology, or a related field (or equivalent practical experience).
- A minimum of 5 to 7 years of hands-on cybersecurity experience specializing in Identity and Access Management (IAM) within enterprise environments.
- Deep hands-on experience designing and operating enterprise identity controls, federation protocols, and directory services.
- Industry certifications such as Microsoft Certified: Identity and Access Administrator Associate (SC-300), CISSP, or CISM are highly desirable.
Security Expertise and Architecture
In-depth technical knowledge of modern identity protocols (SAML 2.0, OAuth 2.0, OIDC, FIDO2) and threat vectors targeting identities (password spraying, token theft, phishing-resistant MFA bypass).
Tooling and Technical Proficiency
Hands-on engineering expertise in Entra ID (Azure AD), Privileged Identity Management (PIM), Conditional Access, Entra ID Governance, SSO, Federation, and MFA controls.
Risk Management and Prioritisation
Ability to identify identity exposure risks, prioritize identity security controls based on privilege and threat context, and minimize identity attack surfaces.
Governance, Process and Control Design
Experience designing automated lifecycle management workflows (Joiner, Mover, Leaver) and establishing granular access control governance frameworks.
Service Delivery and Operational Management
Proven track record of managing identity control platforms, meeting operational SLAs, and executing seamless tenant-wide identity migrations.
Data Analysis, Reporting and Insight
Ability to extract insights from authentication logs and identity risk scores to visualize identity posture, sign-in risks, and policy enforcement effectiveness.
Stakeholder Management and Influence
Strong communication skills to collaborate with infrastructure, HR, and business applications teams to embed secure identity practices without hindering productivity.
Threat Intelligence Integration
Ability to incorporate real-time identity risk signals and CTI feeds into dynamic, risk-based authentication and access policies.
Leadership and Influence
Capability to drive identity security outcomes across technical groups through influence, clear technical guidance, and collaborative problem-solving.
Continuous Improvement and Automation
A strong focus on automation using PowerShell, Graph API, or SCIM provisioning to eliminate manual access assignments and reduce operational drift.
Key Accountabilities and Success Measures
Conditional Access and Policy Engineering
Accountability: Engineer, maintain, and continuously tune adaptive Conditional Access policies to enforce risk-based, zero-trust controls.
Success Measures: 100 percent of workforce sign-ins protected by modern MFA or passwordless authentication standards; zero unauthorized access breaches resulting from misconfigured access policies.
Privileged Identity and Lifecycle Governance
Accountability: Implement PIM and engineer lifecycle processes to govern privileged access and automate Joiner, Mover, and Leaver security controls.
Success Measures: 100 percent of administrative roles subject to Just-In-Time (JIT) access and approval workflows via PIM; 0 percent residual active accounts remaining for departed personnel beyond defined SLA windows.
Threat Remediation and Weakness Mitigation
Accountability: Continuously monitor identity telemetry, identify vulnerabilities in authentication, and execute swift remediation workflows.
Success Measures: Substantial reduction in MTTR for risky user alerts and identity threat detections; active reduction of legacy authentication protocols across the organization to less than 1 percent.
Dyson is an equal opportunity employer. We know that great minds don’t think alike, and it takes all kinds of minds to make our technology so unique. We welcome applications from all backgrounds and employment decisions are made without regard to race, colour, religion, national or ethnic origin, sex, sexual orientation, gender identity or expression, age, disability, protected veteran status or other any other dimension of diversity.
How we rate this
Lead Engineer – Identity & Access Security at Dyson rates 10 out of 100 for how much of the daily work is AI. That makes it Little AI (AI Level 1 of 4). The level is about AI in the job, not seniority.
Little AI. AI is not part of the work.
- ●●●● Builds AI80 to 100
- ●●●○ Works on AI60 to 79
- ●●○○ Uses AI40 to 59
- ●○○○ Little AI0 to 39
Levels come from how often the tools, models and workflows of the role are named in the posting itself. Open the description and count.
Prepare for this job
A free preview built only from this posting: what it asks for, what you could be asked in an interview, and how to adjust your resume.
Skills and AI tools this role asks for
Questions you could be asked
- What's a project where you used Entra Id hands-on?
- Walk me through how you've used Azure Ad in your day-to-day work.
- What are the limits of Pim that you've run into, and how did you work around them?
- What's a project where you used Mfa hands-on?
- Walk me through how you've used Saml in your day-to-day work.
Adapt your resume
- List these exact terms on your resume: Entra Id, Azure Ad, Pim, Mfa, and Saml. An applicant tracking system matches the wording, not the idea.
- Attach one line of real, concrete experience to at least one of them — a tool named with nothing behind it rarely survives a human read.
Want an expert to read your CV for this job?
Free. Send your CV and the role you want next. We reply by email within 2 to 4 business days.
Get a free CV reviewGet new software engineering jobs by email
One email a week with the new software engineering jobs, each rated for how much AI is in the work. No recruiter spam, unsubscribe in one click.
Free. One email a week. Unsubscribe in one click.
Similar roles
Software Engineering roles that involve little AI, at other companies.
What kind of AI work fits you?
Answer 12 practical questions in about three minutes. Get a simple profile, the work it points to, and live roles to explore next.
Find my next step