Job Role – IAM and PAM Security Lead

Teciem

India

On-site

INR 2,400,000 - 4,200,000

Full time

7 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Teciem is seeking an experienced IAM/PAM security professional to lead governance, lifecycle management, and privileged access across cloud and on‑prem environments. You will implement least privilege, Just‑In‑Time controls, and monitor identity threats while collaborating with security operations and engineering teams.

The ideal candidate has 8+ years in security, strong hands-on PAM experience, and a track record with enterprise IAM platforms such as CyberArk or Delinea.

Qualifications

  • 8+ years in information security or infrastructure with 5+ years IAM/PAM hands-on.
  • Hands-on admin for at least one enterprise PAM platform (CyberArk, Delinea, BeyondTrust, One Identity).
  • Proficient in Azure AD, AD, and conditional access implementations.
  • Strong scripting in PowerShell and Python; REST API integrations.

Responsibilities

  • IAM Governance & Identity Security: enforce policies, manage JML, RBAC and entitlements.
  • Privileged Access Management Governance: standardize vaulting, rotation and sessions.
  • Access Reviews & Compliance: run SoD checks, refresh recertifications and evidence.
  • IAM & PAM Risk Management: assess identity risks across cloud, apps, and infra.
  • Security Monitoring & Incident Response: coordinate with SOC for identity incidents.

Skills

IAM administration
PAM administration
Azure AD administration
Conditional access
Scripting PowerShell
Python scripting
REST API integration
Identity governance
Zero Trust
Security incident response

Education

Bachelors in CS/IT or related
CyberArk Defender/Sentry cert
CISSP/CISM or CIAM/IDPro
Microsoft SC-300/SC-200

Tools

CyberArk
Delinea
BeyondTrust
One Identity
Azure Key Vault
HashiCorp Vault
SailPoint
Saviynt
Omada

Job description

**The Work We Do**Teciem designs, builds, and delivers treasury and capital markets software solutions for financial institutions worldwide. We serve banks of every size and geography, offering the right setup for the right need.Our solutions are designed to replace multiple disconnected systems with one complete, front-to-back platform, helping customers to capture trading and business opportunities quickly, clearly and with control. We cover the entire trading lifecycle, ensuring that everything - from execution to position keeping, to risk management – runs smoothly.With decades of experience and one of the largest, most diverse client bases in the industry, we turn deep industry knowledge into software that covers most asset classes, meets complex real-world treasury and capital market's needs, and adapts as markets evolve.**Key Responsibilities****IAM Governance & Identity Security*** Define, maintain, and enforce IAM policies, standards, procedures, and security baselines.* Ensure effective Joiner-Mover-Leaver (JML) processes are implemented and followed across all platforms.* Review and approve role models, access profiles, RBAC structures, and entitlement frameworks.* Monitor identity lifecycle activities to ensure timely provisioning, modification, and deprovisioning of accounts.* Govern Microsoft Entra ID, Active Directory, and enterprise SaaS identity integrations from a security and compliance perspective.* Review and monitor implementation of MFA, passwordless authentication, Conditional Access, Identity Protection, and risk-based authentication controls.* Maintain an inventory of privileged, service, shared, and non-human accounts, ensuring ownership and accountability exist for all identities.* Identify excessive permissions, toxic combinations, dormant accounts, orphan accounts, and access anomalies.**Privileged Access Management Governance*** Act as the Information Security SME for enterprise PAM initiatives.* Define and maintain standards for privileged access, vaulting, credential management, session monitoring, and privileged account lifecycle management.* Review and validate privileged access requests and ensure appropriate approvals and business justifications exist.* Ensure privileged access follows least-privilege, just-in-time (JIT), and just-enough-access (JEA) principles.* Govern emergency and break-glass account management processes.* Review privileged account onboarding across servers, cloud environments, databases, applications, network devices, and client environments.* Validate credential rotation policies and monitor adherence to privileged account management requirements.* Review privileged session monitoring reports and identify unauthorized or risky privileged activities.**Access Reviews & Compliance*** Manage enterprise-wide User Access Review (UAR) and access recertification programs.* Coordinate periodic privileged access reviews with business owners and application custodians.* Validate Segregation of Duties (SoD) controls and identify conflicting access combinations.* Track remediation of access-related audit findings and risk exceptions.* Maintain evidence repositories supporting:* ISO 27001* SOC 2* DORA* NYDFS* Client security audits* Internal audits* Develop and maintain IAM/PAM compliance dashboards and reporting metrics.**IAM & PAM Risk Management*** Perform identity-related risk assessments across cloud, infrastructure, applications, and managed services environments.* Assess risks associated with privileged access, service accounts, shared accounts, and third-party access.* Review access control design for new applications, systems, acquisitions, and cloud services.* Identify gaps in identity security controls and drive remediation plans with IT and technology teams.* Monitor identity threats including credential abuse, privilege escalation, excessive permissions, account compromise, and insider threats.**Security Monitoring & Incident Response*** Collaborate with SOC, SIEM, and incident response teams during identity-related security incidents.* Support investigation of:* Account compromise* Privileged misuse* Unauthorized access* Credential theft* Suspicious authentication activities* Review identity and PAM logs to support forensic investigations and audit requests.* Coordinate rapid access revocation activities during security incidents.**Preferred Skills*** Experience with Identity Governance & Administration (IGA) platforms such as SailPoint, Saviynt, Omada, or Microsoft Identity Governance.* Understanding of cloud IAM across Azure, AWS, and GCP.* Familiarity with Cyber Security controls, Zero Trust Architecture, and Identity Threat Detection & Response (ITDR).* Experience within banking, financial services, fintech, treasury, capital markets, or managed services environments.* Knowledge of service account governance and secrets management solutions such as CyberArk Conjur, HashiCorp Vault, or Azure Key Vault.* Scripting knowledge in PowerShell, Python, or API integrations is advantageous.**Essential skills and experience*** 8+ years in information security or infrastructure, with at least 5 years hands-on in IAM and PAM administration.* Demonstrable administration experience with Microsoft Entra ID (Azure AD) and Active Directory, including conditional access, PIM, group and entitlement management.* Hands-on administration of at least one enterprise PAM platform — CyberArk, Delinea, BeyondTrust, One Identity or equivalent — covering vaulting, rotation, session management and account onboarding.* Practical understanding of authentication and federation protocols: SAML 2.0, OAuth 2.0, OIDC, Kerberos, LDAP, SCIM.* Experience administering privileged access across mixed Windows and Linux estates, databases and cloud platforms.* Scripting and automation capability in PowerShell and/or Python, including REST API integration.* Experience operating access controls in a regulated environment and producing evidence for external audit.**Qualifications and certifications*** Bachelor's degree in computer science, information systems, engineering or related discipline, or equivalent practical experience.* One or more of the following is valued: CyberArk Defender/Sentry, Delinea or BeyondTrust certification, Microsoft SC-300 (Identity and Access Administrator), Microsoft SC-200, CISSP, CISM, or CIAM/IDPro credentials.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Job Role – IAM and PAM Security Lead
Job Role – IAM and PAM Security Lead

TI2 Tupargon India Private Limited • Bengaluru

On-site
INR 3,000,000 - 6,000,000
Senior Identity & Access Management Engineer
Senior Identity & Access Management Engineer

India Fan Corporation • Hyderabad

On-site
INR 2,400,000 - 3,600,000
IAM Platform Owner – SailPoint, PingFederate, SSO & IGA
IAM Platform Owner – SailPoint, PingFederate, SSO & IGA

Synechron • Bengaluru

On-site
INR 3,000,000 - 6,000,000
Technical IAM
Technical IAM

Metaphor Infotech Mumbai • Gurugram District, Bengaluru

On-site
INR 1,400,000 - 2,000,000
Lead IAM Analyst
Lead IAM Analyst

NationsBenefits, LLC • Hyderabad

On-site
INR 1,800,000 - 3,200,000
IAM Architect
IAM Architect

Gas Strategies • Bengaluru

On-site
INR 3,500,000 - 5,500,000
Privileged Access Management Security Engineer
Privileged Access Management Security Engineer

3mcompany • Bengaluru

Hybrid
INR 1,500,000 - 2,600,000
Identity And Access Management Analyst
Identity And Access Management Analyst

Feuji Software Solutions • Hyderabad

On-site
INR 1,300,000 - 1,700,000
IAM & DLP Lead, APAC
IAM & DLP Lead, APAC

Liberty Specialty Markets • India

On-site
INR 1,800,000 - 3,000,000
Senior Engineer, Identity and Access Management
Senior Engineer, Identity and Access Management

Intercontinental Exchange Holdings • Hyderabad

On-site
INR 1,500,000 - 2,100,000