- Location
- Cape Town, Mariendahl House, South Africa
- Type
- Full-time
- Department
- Customer Service
- Education
- Bachelor
- Source
- Workday
Description
The Apex Group was established in Bermuda in 2003 and is now one of the world’s largest fund administration and middle office solutions providers.
Our business is unique in its ability to reach globally, service locally and provide cross-jurisdictional services. With our clients at the heart of everything we do, our hard-working team has successfully delivered on an unprecedented growth and transformation journey, and we are now represented by over circa 13,000 employees across 112 offices worldwide.Your career with us should reflect your energy and passion.
That’s why, at Apex Group, we will do more than simply ‘empower’ you. We will work to supercharge your unique skills and experience.
Take the lead and we’ll give you the support you need to be at the top of your game. And we offer you the freedom to be a positive disrupter and turn big ideas into bold, industry-changing realities.
For our business, for clients, and for you
The Role
As an Identity & Privileged Access Management (IPAM) Analyst, you will play a key role in protecting Apex's identity security environment by supporting the governance, administration, and lifecycle management of user, privileged, non-employee, and service account access across the organisation.
You will be responsible for ensuring that access is provisioned, modified, reviewed, and revoked in accordance with Apex policies, security standards, and regulatory requirements. Working closely with Business Units, HR, Application Owners, IT Support, Security Engineering, Audit, and Risk teams, you will help ensure that identity-related controls remain effective, compliant, and audit-ready.
The role requires a strong understanding of Identity Governance and Administration (IGA), Joiner-Mover-Leaver (JML) processes, User Access Reviews (UARs), Privileged Access Management (PAM), and access governance controls. You will contribute to the continuous improvement and automation of identity processes while supporting strategic identity transformation initiatives across the organisation.
Success in this role is measured through strong governance outcomes, timely and accurate access management, successful audit results, reduced identity-related risk, improved operational efficiency, and positive stakeholder engagement.
Key duties and responsibilities:
Identity Operations & Access Administration
- Administer and support identity and access management processes across enterprise applications, platforms, and directories.
- Manage Joiner, Mover, and Leaver (JML) activities, ensuring access is provisioned, modified, and revoked in accordance with approved processes and SLAs.
- Perform user account lifecycle management for employees, contractors, third parties, service accounts, and privileged identities.
- Support authentication, authorisation, and access control processes across Entra ID, Active Directory, CyberArk, and connected applications.
- Investigate and resolve access-related incidents, requests, and provisioning issues while maintaining high service levels.
- Maintain operational procedures, knowledge articles, and support documentation to ensure consistent service delivery.
Identity Governance, Reviews & Compliance
- Administer and coordinate User Access Reviews (UARs), certification campaigns, and attestation processes across business and technology environments.
- Ensure user and privileged access assignments comply with Apex policies, standards, segregation of duties requirements, and regulatory obligations.
- Monitor and report on access governance metrics, policy compliance, certification completion rates, and control effectiveness.
- Support internal and external audits by providing evidence, reporting, control documentation, and audit responses.
- Identify and remediate access governance risks, control deficiencies, and policy exceptions while implementing appropriate compensating controls.
- Maintain governance artefacts, role models, ownership records, entitlement inventories, and access control documentation.
Identity Lifecycle Management, Automation & Transformation
- Support and continuously improve Joiner, Mover, Leaver (JML), Non-Employee Identity Management, and Service Account Management processes.
- Assist with the implementation and support of Identity Governance and Administration (IGA) capabilities, workflows, and integrations.
- Collaborate with application owners to establish access models, role structures, entitlement definitions, and ownership accountability.
- Support identity transformation projects, cloud migration initiatives, and modernisation programmes across the organisation.
- Contribute to the expansion of governance controls for workforce, non-workforce, and privileged identities.
Identity Security, Stakeholder Engagement & Risk Management
- Support identity security controls across Entra ID, Active Directory, cloud platforms, CyberArk, and enterprise applications.
- Partner with Business Units, HR, Service Desk, Security Engineering, Infrastructure Teams, Application Owners, Risk, and Audit stakeholders.
- Provide guidance on identity governance processes, access management standards, and security best practices.
- Participate in investigations relating to inappropriate access, policy violations, orphaned accounts, and segregation of duties conflicts.
- Communicate risks, control weaknesses, remediation actions, and governance recommendations to stakeholders and management.
- Contribute to the adoption of Zero Trust principles and enterprise identity security strategies across Apex.
Experience and Knowledge:
- 5+ years' experience in Identity & Access Management (IAM), Identity Governance (IGA), Information Security, or related IT disciplines.
- Experience supporting Joiner, Mover, Leaver (JML) processes, User Access Reviews (UARs), access certifications, and access governance controls.
- Strong understanding of identity lifecycle management, role-based access control (RBAC), least privilege, segregation of duties, and Zero Trust principles.
- Experience working with Microsoft Entra ID, Active Directory, ServiceNow, Workday, CyberArk, SailPoint, or similar identity and access management platforms.
- Knowledge of workforce, third-party, non-employee, service account, and privileged identity management practices.
- Experience supporting audit, compliance, and regulatory requirements related to access governance and identity security.
- Strong analytical and problem-solving skills with the ability to investigate access issues and identify control improvements.
- Ability to analyse business requirements and translate them into effective access governance and identity management solutions.
- Excellent communication and stakeholder management skills with the ability to engage both technical and non-technical audiences.
- Self-motivated, organised, and able to manage multiple priorities while maintaining high levels of accuracy and attention to detail.
Qualifications & Certifications:
- Bachelor's Degree in Information Technology, Information Security, Computer Science, Business Information Systems, or a related discipline, or equivalent industry experience.
- Microsoft Identity and Access Administrator (SC-300) training and certification preferred.
- Certifications such as Security+, AZ-500, SC-900, ITIL Foundation, or equivalent are advantageous.
- Exposure to Identity Governance and Administration (IGA), Privileged Access Management (PAM), or IAM-related technologies is required.
- Experience working within regulated, audit-driven, or highly controlled environments is advantageous.
Disclaimer: Unsolicited CVs sent to Apex (Talent Acquisition Team or Hiring Managers) by recruitment agencies will not be accepted for this position. Apex operates a direct sourcing model and where agency assistance is required, the Talent Acquisition team will engage directly with our exclusive recruitment partners.