Identity Engineer - Privilege Access

Ralliant

Mumbai

On-site

INR 3,000,000 - 6,000,000

Full time

2 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Ralliant in Mumbai seeks an Identity Engineer to administer and secure PAM and non-human identity environments, focusing on CyberArk Privileged Cloud and lifecycle governance of service accounts, API keys, and machine identities.

The role is hands-on, works with Security, Infrastructure, and App teams to onboard privileged and machine identities, enforce least privilege, rotate credentials, and respond to incidents affecting privileged or non-human access across on-prem, cloud, and hybrid setups.

Qualifications

  • 10+ years of experience in cybersecurity, IAM, or related fields; 5+ years with CyberArk Privileged Cloud.
  • Strong understanding of Privileged Access Security architecture including Vault/PSM/CPM and Cloud Entitlements Manager.
  • Experience managing non-human identities (service accounts, API keys, secrets, machine identities) at scale.
  • Proficiency in PowerShell and Python; working knowledge of REST APIs and CyberArk SDKs.
  • Familiarity with secrets management tooling (CyberArk Conjur/Secrets Hub, Vault) and CI/CD credential hygiene.
  • Experience with log analysis, SIEM integration, incident response, and monitoring privileged/non-human activity.
  • Knowledge of compliance frameworks (SOX, PCI-DSS, NIST, ISO 27001) and zero-trust principles.

Responsibilities

  • Administer and support CyberArk Privileged Cloud platform, including user/group management and vault configuration.
  • Configure and enforce password, access, and workflow policies for privileged accounts.
  • Own non-human identity (NHI) management end-to-end: service accounts, API keys, secrets, certificates, machine identities.
  • Implement NHI lifecycle governance: discovery, ownership, rotation, expiration tracking, decommissioning.
  • Administer secrets management and vaulting for apps, automation, CI/CD pipelines.
  • Resolve PSM/CPM issues including remote access connectivity and privileged account management failures.
  • Troubleshoot network, firewall, NAT, DNS, and certificate-chain issues affecting privileged access.
  • Support authentication/authorization across AD/LDAP, SAML, OAuth 2.0, MFA, SSO for privileged accounts.
  • Develop PowerShell and Python scripts to automate PAM/NHI onboarding and rotation using CyberArk SDKs.
  • Monitor CyberArk, system, and network logs; support SIEM integration and incident response.

Skills

CyberArk Privileged Cloud
Privileged Access Security
Non-human identities management
PowerShell
Python
REST APIs
SIEM integration
Cloud platforms (AWS/Azure/GCP)
Incident response
Compliance frameworks (SOX, PCI-DSS, N

Education

Bachelor's degree or equivalent

Tools

CyberArk Privileged Cloud
CyberArk Conjur/Secrets Hub
HashiCorp Vault
CyberArk SDKs

Job description

Job Description:

Role description

The Identity Engineer is responsible for administering, securing, and supporting the enterprises privileged access management (PAM) and non-human identity (NHI) environment, with a primary focus on CyberArk Privileged Cloud and the lifecycle governance of service accounts, API keys, certificates, and machine/workload identities. This role ensures secure, reliable, and well-governed access to critical systems through platform administration, proactive troubleshooting, and strong operational security practices.

This role acts as both a platform administrator and a technical troubleshooter, resolving complex privileged access, authentication, and non-human identity issues across on-premises, cloud, and hybrid environments. The engineer partners closely with Security, Infrastructure, and Application teams to onboard privileged and machine identities, enforce least-privilege and credential hygiene, and respond quickly to incidents affecting privileged or non-human access.

The role is hands‑on and execution‑focused while embracing the Ralliant Business System (RBS) by embedding operational discipline, staff training, and continuous improvement into tools, workflows, and standard work so endpoint management is scalable, measurable, and repeatable. The role operates in service to the enterprise and operating companies, ensuring standardized Identity practices while adapting to regional and business-specific needs.

Key responsibilities
  • Administer and support the CyberArk Privileged Cloud platform, including user and group management, safe management, vault configuration, and PSM/CPM operations.
  • Configure and enforce password, access, and workflow policies to manage privileged account onboarding, rotation, and least-privilege access.
  • Own non-human identity (NHI) management end to end, including service accounts, API keys, secrets, certificates, and machine/workload identities.
  • Implement NHI lifecycle governance, including discovery, ownership assignment, credential rotation, expiration tracking, and decommissioning of unused or orphaned identities.
  • Administer secrets management and vaulting for applications, automation, and CI/CD pipelines, reducing hard-coded credentials and standing privileged access.
  • Resolve PSM and CPM issues, including remote access connectivity (RDP, SSH, web‑based access) and privileged account management failures.
  • Troubleshoot complex network and connectivity issues, including firewall rules, NAT, DNS resolution, and certificate chain validation as they relate to privileged and non-human access.
  • Support authentication and authorization troubleshooting across Active Directory/LDAP, SAML, OAuth 2.0, multi‑factor authentication (MFA), and Single Sign‑On (SSO) integrations for privileged and service accounts.
  • Develop PowerShell and Python/REST API scripts to automate PAM and NHI onboarding, credential rotation, discovery, and reporting using CyberArk SDKs and vendor APIs.
  • Monitor and analyze CyberArk, system, and network logs, supporting SIEM integration, anomalous privileged/non‑human activity detection, and incident response.
  • Apply privileged access and non‑human identity security best practices, supporting compliance with frameworks such as SOX, PCI‑DSS, NIST, and ISO 27001.
  • Partner with Security, Infrastructure, and Application teams to integrate PAM and NHI solutions across enterprise and OpCo environments.
  • Document procedures, configurations, and incident reports, and train application owners and DevOps teams on secure credential and machine‑identity practices.
  • Build reports and Power BI dashboards to track PAM and NHI health metrics, including credential rotation status, orphaned/unmanaged accounts, safe and vault utilization, and audit/compliance posture for leadership and stakeholder visibility.
Qualifications
  • Bachelors degree recommended; equivalent experience considered.
  • 10+ years of experience in cybersecurity, systems administration, or identity and access management, with 5+ years hands‑on experience with CyberArk Privileged Cloud.
  • Strong understanding of Privileged Access Security architecture, including Vault, PSM, CPM, and Cloud Entitlements Manager.
  • Demonstrated experience managing non‑human identities, including service accounts, API keys, secrets managers, and machine/workload identities at scale.
  • Familiarity with secrets management tooling and practices (e.g., CyberArk Conjur/Secrets Hub, HashiCorp Vault, or equivalent) and CI/CD credential hygiene.
  • Proficiency in TCP/IP networking, firewalls, and DNS/certificate troubleshooting across on‑premises and cloud environments (AWS, Azure, GCP).
  • Experience with Active Directory/LDAP, Entra ID, SAML, OAuth 2.0, MFA, and SSO authentication and authorization troubleshooting.
  • Scripting experience in PowerShell and Python, with working knowledge of REST APIs and CyberArk SDKs.
  • Experience with log analysis and SIEM integration, incident response, and root cause analysis, with an emphasis on privileged and non‑human activity monitoring.
  • Knowledge of compliance frameworks (SOX, PCI‑DSS, NIST, ISO 27001) and zero trust security principles.
  • CyberArk Trustee or higher certification preferred; cloud platform or security certifications (AWS, Azure, GCP, CISSP, CISM, Security+) a plus.
  • Strong communication and documentation skills, with the ability to explain technical concepts to non‑technical stakeholders and train application owners and DevOps teams.
  • Ability to operate effectively across enterprise and OpCo environments, balancing global consistency with local context across multiple time zones and cultures.
  • Alignment with Ralliant values and the Ralliant Business System (RBS), including continuous improvement, transparency, and ownership.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Identity Engineer - Privilege Access
Identity Engineer - Privilege Access

Ralliant • Karnataka

On-site
INR 1,200,000 - 1,800,000
Bonus eligibility
Senior Identity & Access Management Engineer
Senior Identity & Access Management Engineer

India Fan Corporation • Hyderabad

On-site
INR 2,400,000 - 3,600,000
Identity Security Privileged Access Architect
Identity Security Privileged Access Architect

FNZ Group • Pune District

On-site
INR 2,500,000 - 4,200,000
CyberArk Engineer
CyberArk Engineer

JUARA IT SOLUTIONS • Chennai District

On-site
INR 1,500,000 - 2,300,000
CyberArk EPM
CyberArk Secrets Manager
CyberArk Identity
+7
CyberArk Security Engineer
CyberArk Security Engineer

Delta Tech Hub • Bengaluru

On-site
INR 1,200,000 - 2,000,000
CyberArk Engineer
CyberArk Engineer

Cognizant • Ernakulam

On-site
INR 1,500,000 - 2,800,000
Privileged Access Management Security Engineer
Privileged Access Management Security Engineer

healthcare • Bengaluru

Hybrid
INR 1,800,000 - 2,400,000
Hybrid work arrangement
Security Engineer, CyberArk
Security Engineer, CyberArk

Cyderes • Bengaluru

On-site
INR 1,200,000 - 2,000,000
Medical Insurance
Life Insurance
Hybrid Work Model
+5
Cyber Ark transformation lead
Cyber Ark transformation lead

Sutherland • Telangana

On-site
INR 4,000,000 - 6,500,000
CyberArk Architect
CyberArk Architect

Sutherland • Hyderabad

On-site
INR 1,500,000 - 2,100,000