I've been part of the IAM platform team at Allianz Australia for years now, working across Australia, New Zealand and Malaysia. Insurance is one of the more interesting verticals to do identity in: heavily regulated, deeply integrated with intermediaries, and full of long-running processes that all assume someone, somewhere, has authoritative access.
The shape of the problem
Identity at an insurer is not just employees. It is contractors, brokers, agents, claims assessors, panel suppliers, and service partners โ each with their own access lifecycle, each governed by a different set of contracts and regulators. Multiply that by three countries with three different regulatory regimes and you end up with a problem that does not look anything like "log people in".
What I actually work on
- SailPoint platform engineering โ connectors, workflows, custom rules, and lifecycle automation across our application estate.
- RBAC modelling โ translating business roles into entitlement bundles that survive contact with reality.
- Joiner / Mover / Leaver automation โ getting the right access in front of someone on day one, and getting it off them the moment they leave.
- Audit + certification โ keeping access reviews meaningful instead of theatre, and making the evidence easy for auditors to consume.
The lessons that scaled
A few things I have learned that I would carry into any large enterprise:
- Treat HR as the contract, not just the source. If HR data is wrong, governance is wrong. Fix the source before automating the downstream.
- Build for the auditor first. Every workflow should produce evidence by default โ not as a post-hoc effort.
- Country differences are real. AU, NZ and MY each have different regulators, different definitions of "sensitive data", and different appetites for outsourcing access decisions. Bake that into the role model from the start.
- Talk to the brokers. External users always teach you more about your own model than internal ones do.
The best part of doing IAM at an insurer is that the work matters in a quiet, durable way. Nobody throws a launch party when access reviews actually work โ and that is exactly why doing them well is high-leverage.
What I'd tell engineers eyeing this kind of role
Enterprise IAM is not glamorous, but it is one of the safest career bets in software right now. Every regulated industry needs it; very few engineers go deep on it; and the senior end of the market pays accordingly. If you enjoy systems thinking, like reading audit reports, and don't mind that "shipping" can mean a connector that runs once a night, this is a great place to live.