Identity Access Management Operations and Engineering Manager

StoneX Group Inc.

Bengaluru

On-site

INR 4,000,000 - 7,000,000

Full time

2 hours ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

StoneX Group Inc. is seeking an Identity Access Management Operations and Engineering Manager for IT Risk and Security in Bengaluru.

You will lead the IAM Operations and Engineering function overseeing Entra ID, AD, Okta, PKI and SSO, managing a distributed team across time zones and regions. The role requires deep hands-on IAM experience in a regulated financial environment, plus leadership to drive automation, governance and audits.

Qualifications

  • 10+ years of professional experience, including 6+ years in IAM and 3+ years leading an IAM team.
  • Experience designing and managing IAM processes within large organizations.
  • Deep knowledge of Entra ID and AD in hybrid environments, including prerequisites like PKI and entitlement models.
  • Hands-on experience with Okta policies, authentication journeys, and federation at scale.
  • Automation and scripting ability to lead engineers (PowerShell, APIs, CI/CD).

Responsibilities

  • Own IAM service catalogue end to end: joiner/mover/leaver, access requests, and privileged accounts.
  • Set engineering/operations roadmap; act as design authority across core identity platforms.
  • Lead incident, change, capacity planning and on-call across time zones.
  • Design and maintain IAM policies, standards, and data protection controls.
  • Lead a distributed team (1-3 engineers) across regions; ensure coverage and resilience.
  • Automate provisioning/deprovisioning via HR-driven workflows and RBAC.
  • Collaborate with security, IT, HR, compliance and business units to meet IAM needs.
  • Manage vendors and licensing, and maintain runbooks and documentation.

Skills

Identity & access management
Microsoft Entra ID
Okta
Active Directory
PKI
SSO / Federation
Automation
PowerShell
Audit & compliance
Leadership
Cross-functional collaboration

Education

Bachelor's or master's in CS/Info Security
SC-300 certification
Okta Certified Professional/Administrator
CISSP/CISM/CyberArk Defender
ITIL Foundation

Tools

Microsoft Entra ID
Active Directory
Okta
PKI
Federation & SSO
Microsoft Graph
PowerShell
CyberArk

Job description

Overview
Connecting clients to markets – and talent to opportunity.

With 5,400+ employees and over 80,000 institutional, commercial, and payments clients, we operate from more than 80 offices spread across six continents. As a Fortune 100, Nasdaq-listed provider, we connect clients to the global markets – focusing on innovation, human connection, and providing world-class products and services to all types of investors.

Overview
Connecting clients to markets – and talent to opportunity.

With 5,400+ employees and over 80,000 institutional, commercial, and payments clients, we operate from more than 80 offices spread across six continents. As a Fortune 100, Nasdaq-listed provider, we connect clients to the global markets – focusing on innovation, human connection, and providing world-class products and services to all types of investors.

Whether you want to forge a career connecting our retail clients to potential trading opportunities, or ingrain yourself in the world of institutional investing, StoneX Group is made up of four business segments that offer endless potential for progression and growth.

Business Segment Overview
Corporate:

Engage in a deep variety of business-critical activities that keep our company running efficiently. From strategic marketing and financial management to human resources and operational oversight, you’ll have the opportunity to optimize processes and implement game-changing policies.

Position Purpose:

As Identity Access Management Operations and Engineering Manager for IT Risk and Security, you will lead an IAM Operations and Identity Engineering function within StoneX, owning both the day-to-day identity service the firm depends on and the engineering of the platforms that deliver it. The estate runs core identity platforms such as Microsoft Entra ID with Active Directory, and Okta. Around them sit enterprise PKI, privileged access management, modern authentication and identity governance tooling, alongside legacy platforms now being retired. The ideal candidate will have experience working in a regulated financial environment and is a highly skilled, experienced and motivated leader willing to drive and grow our identity function across a globally distributed team.

Responsibilities
Primary duties will include:
  • Own the identity service catalogue end to end - joiner, mover and leaver processing, access request, entitlement and group administration, privileged account issuance, certificate services and application onboarding and the service levels each commitment carries.
  • Set the engineering and operations roadmap and act as technical design authority across both core identity platforms; Entra ID with hybrid directory services and Okta as well as identity governance and administration, privileged access management, PKI and certificate lifecycle, federation and single sign-on, and modern authentication.
  • Run the operational disciplines behind the service: incident and problem management for identity outages, change control, capacity and availability planning, and a documented escalation and on-call model that holds across time zones.
  • Design, implement and maintain IAM policies, procedures and standards to ensure the confidentiality, integrity and availability of sensitive data and resources.
  • Manage and lead a team (1-3) of identity engineers and analysts and building coverage so that every platform has more than one engineer, in more than one region, who can safely operate it.
  • Drive standing privilege down across the estate: run the access certification and recertification cycle, enforce segregation of duties and least privilege, eliminate orphaned and dormant accounts, and bring service, workload and other non-human identities under the same lifecycle discipline as people.
  • Act as identity manager you will be working with the team and supporting internal audit, external audit and client or scheme assessments including SWIFT CSP, inc. producing evidence on request, owning remediation actions and closing findings to agreed dates.
  • Automate the routine work out of the service: provisioning and deprovisioning driven from authoritative HR sources, policy and role-based entitlement in place of ticket-by-ticket approval and reporting instrumented so identity risk is visible without a manual data pull.
  • Own identity data quality and metrics, account ownership, lifecycle state, entitlement mapping and application registration as the foundation every downstream control, report and detection depends on.
  • Lead directory and tenant consolidation and legacy platform decommissioning, including the absorption of acquired identity estates onto the strategic Entra ID and Okta platforms, working directly with the application teams that depend on those platforms rather than routing every migration through the identity team.
  • Collaborate with cross-functional teams - security architecture, security operations, enterprise IT, HR, compliance and the business to assess IAM requirements and develop solutions that meet business needs.
  • Manage external partners and vendors against their commitments, and contribute to forecasting and planning for identity licensing, tooling and headcount.
  • Maintain IAM process documentation, including end-user guidance, runbooks and team processes and procedures, to a standard that allows work to move between regions without loss.
Qualifications

To land this role you will need

  • This individual must be capable of working with internal and customer-facing teams to facilitate process improvement and customer support resulting in an enhanced security posture, reduction in risk and improvement in end-user experience. Excellent communication, strong organizational skills and attention to detail are essential.
  • 10+ years of overall professional experience, including at least 6 years in identity and access management and 3+ years leading and directly managing an IAM team, with accountability for both a production service and an engineering backlog; experience in financial services a plus.
  • Proven experience designing, implementing and managing complex IAM processes and solutions within large organizations.
  • Deep, current, hands‑on knowledge of both core platforms. Microsoft Entra ID and Active Directory in a hybrid estate — tenant and forest design, synchronisation, conditional access, privileged role management and entitlement models. Okta — policy architecture, authentication journeys, application integration, lifecycle management and federation at scale.
  • Production delivery experience across at least three of: identity governance and administration tooling, privileged access management such as CyberArk, PKI and certificate lifecycle management, federation and single sign‑on, and multi‑factor or passwordless authentication.
  • Knowledge and implementation of key security concepts such as RBAC, zero trust, identity lifecycle automation, least privilege and identity governance, together with command of the underlying protocols SAML 2.0, OIDC, OAuth 2.0, SCIM, Kerberos and LDAP.
  • Automation and scripting ability sufficient to lead engineers credibly e.g. PowerShell, Microsoft Graph and the Okta management APIs with practical use of source control, pipelines and configuration‑as‑code applied to identity change.
  • Demonstrated operational management discipline: service level definition and reporting, incident, problem and change management, and oversight of vendors or managed service providers.
  • Direct experience owning identity controls through audit - preparing evidence, defending design decisions to auditors or regulators, and closing findings.
  • Understanding of a broad range of general information security domains, including networking, cybersecurity, governance and risk, and cloud.
  • Strong leadership skills with a track record of successfully leading distributed and cross‑functional teams across time zones, including offshore or GCC‑based staff.
  • Excellent communication and interpersonal skills to effectively collaborate with technical and non‑technical stakeholders.
What makes you stand out:
  • You have an operations mindset and an engineer's instinct; you see an inefficient process and immediately think of how to automate it away rather than staff it.
  • You thrive in a fast‑paced, collaborative environment and are comfortable juggling a live service and a delivery roadmap at the same time.
  • You are equally comfortable in both platforms and can reason about where a capability belongs — Entra ID or Okta — rather than defaulting to the one you know best.
  • You build people as deliberately as you build platforms, and you measure your team by the cover and capability it has, not by the hours it works.
  • You have experience in a Zero Trust program, or with securing non‑human identities including service accounts, workload identities and emerging agentic and AI workloads.
Education / Certification Requirements:
  • Bachelor's or master's degree in computer science, information security or a related field (or equivalent experience).
  • Microsoft Certified: Identity and Access Administrator Associate (SC-300) preferred.
  • Okta Certified Professional or Okta Certified Administrator preferred.
  • CISSP, CISM, CyberArk Defender or Sentry, or an equivalent identity governance credential preferred; ITIL foundation or equivalent service management training is a plus.
Working environment:
  • 4 days' work from office
  • Working hours aligned to India business hours, with overlap into CET / BST.
  • Team distributed across UK, US and Latam locations; participation in an escalation and on-call rotation should be expected.
  • Travel requirements, for leadership meetings and conferences.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

IAM Architect
IAM Architect

Gas Strategies • Bengaluru

On-site
INR 3,500,000 - 5,500,000
Senior Engineer, Identity and Access Management
Senior Engineer, Identity and Access Management

ICE Clear Europe Limited • Hyderabad

On-site
INR 1,400,000 - 2,100,000
Senior Engineer, Identity and Access Management
Senior Engineer, Identity and Access Management

ICE • Hyderabad

On-site
INR 2,000,000 - 4,000,000
Senior Engineer Identity And Access Management
Senior Engineer Identity And Access Management

ICE • Hyderabad

On-site
INR 1,800,000 - 2,400,000
Identity & Access Management Lead
Identity & Access Management Lead

Capgemini • Navi Mumbai

On-site
INR 2,500,000 - 3,500,000
Senior IAM Engineer
Senior IAM Engineer

Jobtailor • Dadri

On-site
INR 900,000 - 1,500,000
Analyst - IAM SSO Engineer
Analyst - IAM SSO Engineer

PepsiCo Deutschland GmbH • Hyderabad

On-site
INR 1,500,000 - 2,300,000
Manager - Identity & Access Management (IAM) Service Owner
Manager - Identity & Access Management (IAM) Service Owner

Davies • Pune District

On-site
INR 1,800,000 - 2,400,000
Senior Technical Analyst - IAM
Senior Technical Analyst - IAM

Computacenter AG & Co. oHG • Bengaluru

On-site
INR 3,000,000 - 4,500,000
Sr Director of Identity & Access Management
Sr Director of Identity & Access Management

Hitachi Digital • New Delhi

Hybrid
INR 2,500,000 - 3,500,000
Industry-leading benefits
Flexible work arrangements
Commitment to health and wellbeing