Privileged Access Platform Owner - L2

MKS Instruments, Inc.

Gurugram District

On-site

INR 1,800,000 - 3,200,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

MKS Instruments is seeking a hands-on product owner for identity and endpoint security platforms. Lead Evidian, Admin By Request, and 1Password strategy, roadmaps, and governance, ensuring zero trust, least privilege, and compliant configurations across the estate.

Collaborate with IAM, Endpoint, IT Ops, Security, and Compliance to implement secure integrations with AD/Entra ID, SSO, and secrets pipelines, while delivering reliable security services globally.

Qualifications

  • 5+ years in IAM/Security Engineering or Endpoint Security.
  • 2+ years administering Evidian, Admin By Request, and/or 1Password at enterprise scale.
  • Strong experience with Entra ID/Azure AD & SSO.
  • Scripting/automation proficiency: PowerShell.
  • Familiarity with data protection principles.

Responsibilities

  • Own roadmaps, backlog, release planning, and stakeholder communication for Evidian, Admin By Request, and 1Password.
  • Define architecture baselines aligned to zero trust and least privilege.
  • Design integrations with directories, HRIS, MDM/UEM, SIEM/SOAR, and ticketing systems.
  • Implement least-privilege controls and 1Password enterprise policies.
  • Own SLAs/OLAs, incident/change management, and vendor management.
  • Provide L3 support and enable L1/L2 through documentation and training.

Skills

IAM/IGA
PAM/JIT
SSO/SCIM
Directory services
Scripting/automation
SIEM
Least privilege
FIDO2/WebAuthn

Tools

Azure AD
Entra ID
Active Directory
Delinea/CyberArk
1Password Business
ServiceNow
Jira
PowerShell

Job description

A Day in Your Life at MKS We are seeking a hands‑on professional to own the strategy, engineering, and lifecycle of core identity and endpoint security tools—Evidian (Authentication Manager / Enterprise SSO), Admin By Request (privileged access elevation), and 1Password (password management & secrets). As product owner and technical authority, you will ensure these platforms are securely designed, integrated, monitored, and continuously improved to meet business and regulatory needs, partnering with IAM, Endpoint, IT Ops, Enterprise Architecture, Security Operations, and Compliance to deliver reliable, audited, and user‑friendly security services globally


You Will Make an Impact

By Platform Ownership & Strategy- Act as product owner for Evidian (Authentication Manager / Enterprise SSO), Admin By Request, and 1Password—owning roadmaps, backlog, release planning, and stakeholder communication. Define architecture and configuration baselines aligned to zero trust, least privilege, and separation of duties, while maintaining platform governance across access models, workflows, policies, standards, and lifecycle management. Engineering & Integration- Design and implement integrations with enterprise directories (e.g., Azure AD/Entra ID, AD), HRIS (for joinermoverleaver), MDM/UEM (e.g., Intune), SIEM/SOAR, ticketing (ServiceNow/Jira), and secrets pipelines (CI/CD). Security & Compliance-Implement least‑privilege controls with Admin By Request (approval policies, just‑in‑time elevation, allow/deny lists, session auditing) and operate 1Password enterprise policies (domain capture, vault hygiene, phishing‑resistant MFA, secrets access controls, recovery processes). Operations & Service Management -Own SLAs/OLAs, incident/problem/change management, patching, upgrades, and vendor management. Provide L3 support and enable L1/L2 teams through documentation and training.


Skills you bring

5+ years in IAM/Security Engineering or Endpoint Security, with 2+ years administering at least two of the following: Evidian (Authentication Manager / Enterprise SSO), Admin By Request (or equivalent PAM/JIT elevation), 1Password (or enterprise password/secrets managers). Strong experience with Entra ID/Azure AD & Active Directory, SSO (SAML/OIDC), and SCIM provisioning. Scripting/automation proficiency: PowerShell Hands‑on with SIEM (e.g., Sentinel, Splunk, Chronicle) for log forwarding, correlation, and alerting. Solid understanding of least privilege, JIT/JEA, secrets management, and credential hygiene with Familiarity on data protection principles.


Preferred Skills

Prior ownership of Evidian (Authentication Manager / Enterprise SSO), Admin By Request at enterprise scale, and 1Password Business/Enterprise, including policies, SSO, domain capture, recovery, and secrets automation. 3+ years of engineering experience in Delinea /CyberArk. RBAC/ABAC design, SoD rulesets, entitlement modeling, and access recertifications. Knowledge of modern identity patterns (FIDO2/WebAuthn, conditional access, device trust). Certifications (nice to have): CISSP, CCSP, Azure Security Engineer (AZ500), GIAC (e.g., GCLD/GSEC), ITIL.


Core Skills

Technical: IAM/IGA, PAM/JIT, enterprise password/secrets management, SSO/SCIM, directory services, endpoint management, scripting/automation, log engineering.


MKS Policy Statement

Globally, our policy is to recruit individuals from wide and diverse backgrounds. However, certain positions require access to controlled goods and technologies subject to various export control regulations. Applicants for these positions may be limited (by, for example, their countries of citizenship, country of origin, or immigration status) where required by law or governmental contact, and/or employment made contingent upon the issuance of appropriate governmental licensing. MKS Inc. and its affiliates and subsidiaries (“MKS”) is an affirmative action and equal opportunity employer: diverse candidates are encouraged to apply. We win as a team and are committed to recruiting and hiring qualified applicants regardless of race, color, national origin, sex (including pregnancy and pregnancy‑related conditions), religion, age, ancestry, physical or mental disability or handicap, marital status, membership in the uniformed services, veteran status, sexual orientation, gender identity or expression, genetic information, or any other category protected by applicable law. Hiring decisions are based on merit, qualifications and business needs. We conduct background checks and drug screens, in accordance with applicable law and company policies. MKS is generally only hiring candidates who reside in states where we are registered to do business. MKS is committed to working with and providing reasonable accommodations to qualified individuals with disabilities. If you need a reasonable accommodation during the application or interview process due to a disability, please contact us at: accommodationsatMKS@mksinst.com . If applying for a specific job, please include the requisition number (ex: RXXXX), the title and location of the role At MKS, it's all about courage, big ideas, and a serious passion for innovation. Winning here is about exploring possibilities, taking action, and solving our customers’ toughest challenges. It's not just a job – it's what you make of it. While you shape your role and make it unique, we invest in you with on‑the‑job and formal training, as well as educational assistance. Curiosity is key at MKS - ask questions, own your path. Our success comes from celebrating the unique skills, diverse perspectives, and lived experience of employees from over 100 countries. The goal is to make sure that everyone feels that they belong. Diversity isn't just a nice‑to‑have; making sure everyone feels included is a big deal for us. Our group of ~10,000 employees serves semiconductor manufacturing, electronics and packaging, and specialty industrial markets. With over 3,800 patents, our products are enabling advancements in 5G, renewable energy & storage, artificial intelligence, cloud technology, and big data. We're the behind‑the‑se‑sides support for some amazing technology. MKS Instruments enables technologies that transform our world. MKS Instruments Product Overview

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Engineer II
Senior Engineer II

MKS Instruments, Inc. • Gurugram District

On-site
INR 1,200,000 - 1,800,000
Teritory Manager
Teritory Manager

MKS Instruments, Inc. • India

Hybrid
INR 600,000 - 1,000,000
Finance Manager (GL Accounting & Reporting)
Finance Manager (GL Accounting & Reporting)

MKS Instruments, Inc. • Bengaluru

On-site
INR 4,500,000 - 6,000,000
Equipment Service Specialist I
Equipment Service Specialist I

MKS Instruments, Inc. • Mysuru

On-site
INR 650,000 - 900,000
Senior Network Engineer
Senior Network Engineer

MKS Instruments • Gurugram District

On-site
INR 2,500,000 - 4,000,000
Senior Software Engineer I
Senior Software Engineer I

MKS Instruments • Bengaluru

On-site
INR 1,200,000 - 1,800,000
Major Incident Manager
Major Incident Manager

MKS Instruments • Gurugram District

On-site
INR 1,500,000 - 2,500,000
Sourcing Specialist - Cost Out
Sourcing Specialist - Cost Out

MKS Instruments, Inc. • India

On-site
INR 1,800,000 - 3,000,000
Senior Network Engineer
Senior Network Engineer

MKS Inc. • Gurgaon

On-site
INR 1,200,000 - 1,800,000
NOC Engineer
NOC Engineer

MKS Instruments • Gurugram District

On-site
INR 600,000 - 900,000
null