Security Platform Engineering

ITC Infotech

Gurugram District

Hybrid

INR 900,000 - 1,500,000

Full time

6 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Job summary

ITC Infotech is seeking a specialist in identity and access management and secrets management to drive secure architecture across Azure, AWS, on-prem platforms, and Kubernetes. You will work with development teams in India and abroad to define target-state IAM and secrets governance, and to implement enterprise standards for rotation, access control and audit.

The role requires hands-on experience with multi-cloud IAM, secrets platforms, and CI/CD integrations, with a focus on secure, auditable

Qualifications

  • Hands-on experience with enterprise IAM and secrets management across multiple platforms.
  • Experience in hybrid/multi-cloud environments and on-premise workloads.
  • Knowledge of authentication, authorization, and audit controls in regulated settings.
  • Experience with CI/CD integrations for secure pipelines and governance.

Responsibilities

  • Assess current IAM and secrets practices across cloud and on-prem platforms.
  • Define target-state architecture for secrets management and IAM integration.
  • Create enterprise standards for secrets storage, rotation, ownership and tagging.
  • Define centralized vs cloud-native secrets tooling and governance.
  • Design IAM access models using Entra ID, AWS IAM, and workload identities.
  • Support onboarding and migrations with secure, auditable processes.
  • Integrate secrets management with CI/CD, Kubernetes, databases and APIs.
  • Develop documentation and reference architectures for engineering teams.

Skills

IAM concepts
Azure Entra ID
AWS IAM
Least privilege
Federation
RBAC/ABAC
Service principals
Workload identity
Secrets management
PAM
DevSecOps
CI/CD
Governance
Audit controls
Kubernetes

Tools

Azure Entra ID
AWS IAM
Azure Key Vault
AWS Secrets Manager
HashiCorp Vault
CyberArk Conjur
Secrets Store CSI Driver
Terraform

Job description

Strong IAM knowledge across Azure Entra ID, AWS IAM, workload identity, federation, RBAC/ABAC, least privilege, service principals and managed identities/cyberark.

This position will support a hybrid, multi-cloud environment covering Azure, AWS, on-premises platforms, Kubernetes, CI/CD pipelines, and enterprise security controls. The successful candidate must understand both secrets management and IAM end to end, including identities, roles, policies, access models, workload identity, privileged access, service accounts, federation, and audit controls.

The role will involve working closely with development teams in India, UK and Dalian.

Additional support outside India business hours is also required (including working in weekend).

The key responsibilities of this role are:

  • Assess current secrets management and IAM practices across Azure, AWS, on-premises, Kubernetes, CI/CD, applications, databases, APIs, and service accounts.
  • Define target-state architecture for secrets management, IAM integration, workload identity, privileged access, credential rotation, audit, and governance.
  • Create enterprise standards for secrets storage, access, rotation, ownership, naming, tagging, expiry, exception handling, and decommissioning.
  • Define when to use centralized secrets platforms versus cloud-native tools such as Azure Key Vault and AWS Secrets Manager.
  • Design IAM access models using Azure Entra ID, AWS IAM, roles, policies, groups, service principals, managed identities, OIDC federation, and least-privilege access.
  • Support onboarding and migration of application teams from insecure or inconsistent secrets and IAM practices.
  • Integrate secrets management with IAM, PAM, CI/CD pipelines, Kubernetes, databases, APIs, legacy applications, logging, monitoring, and SIEM.
  • Help establish operating model components such as ownership, support processes, governance, exception management, control monitoring, and reporting.
  • Produce practical documentation, reference architectures, onboarding playbooks, and implementation patterns for engineering teams.

Your skills and experience

  • 0-15 years of hands-on experience on below mentioned skills.
  • Proven experience delivering at least one enterprise transformation in secrets management, IAM, PAM, DevSecOps, cloud security, or machine identity.
  • Strong understanding of IAM concepts, including authentication, authorization, RBAC, ABAC, least privilege, federation, workload identity, privileged access, service accounts, access reviews, and audit controls.
  • Hands-on experience with Azure and AWS IAM services, including Entra ID, Azure Managed Identity, service principals, AWS IAM roles, policies, STS, and OIDC.
  • Experience with at least two secrets management technologies, such as Azure Key Vault, AWS Secrets Manager, HashiCorp Vault, CyberArk Conjur, Akeyless, Thales CipherTrust, External Secrets Operator, or Secrets Store CSI Driver.
  • Experience working in hybrid environments with cloud and on-premises workloads.
  • Experience integrating secrets and IAM controls with CI/CD tools such as Azure DevOps, GitHub Actions, Jenkins, GitLab, or similar.
  • Ability to define enterprise standards, target-state architecture, migration plans, governance models, and practical engineering patterns.
  • Strong stakeholder management skills across security, cloud, platform, infrastructure, application, risk, and audit teams.

Essential skills

  • Experience in regulated enterprise environments such as financial services, banking, insurance, healthcare, or similar.
  • Experience with CyberArk PAM, HashiCorp Vault Enterprise, machine identity, certificate lifecycle, or dynamic secrets.
  • Experience with policy-as-code, Terraform, Azure Policy, AWS Organizations/SCPs, OPA, Sentinel, Checkov, Prisma Cloud, Wiz, or similar tools.
  • Experience with secret scanning and remediation using tools such as GitHub Advanced Security, GitGuardian, Gitleaks, TruffleHog, or similar.
  • Experience defining dashboards or metrics for secrets compliance, IAM access hygiene, rotation status, onboarding progress, exceptions, and risk reduction.

Personal Skills:

  • Able to Set, communicate and manage stakeholder's expectations.
  • Ability to prioritize and co-ordinate activities.
  • Always open to learn and adopt new tools/technologies
  • Experience of working to tight deadlines on a regular basis.
  • Good Analytical and problem solving skills.
  • Ability to adapt to changing business needs (Flexible) and learning new skills quickly.
  • Good written and oral communications skills, together with the ability to communicate with management and other business groups.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Platform Engineer
Security Platform Engineer

Infyshine • Gurugram District

On-site
INR 3,500,000 - 7,000,000
Security Platform Engineering
Security Platform Engineering

Infyshine • Gurugram District

On-site
INR 4,000,000 - 7,000,000
Cloud Security Architect, Secrets Management & Key Vault
Cloud Security Architect, Secrets Management & Key Vault

Purview Services • Dadri

Hybrid
INR 1,800,000 - 3,200,000
IAM Engineer
IAM Engineer

Enphase Energy, Inc. • Bengaluru

On-site
INR 1,200,000 - 1,800,000
IAM Engineer
IAM Engineer

Enphase Energy • Bengaluru

Hybrid
INR 1,400,000 - 2,200,000
IAM Architect
IAM Architect

Gas Strategies • Bengaluru

On-site
INR 3,500,000 - 5,500,000
Sr. Security Tools Engineer - HashiCorp Vault & AppViewX
Sr. Security Tools Engineer - HashiCorp Vault & AppViewX

Global Software Solutions Group • Bengaluru

On-site
INR 2,500,000 - 5,000,000
Sr. Security Tools Engineer - HashiCorp Vault & AppViewX
Sr. Security Tools Engineer - HashiCorp Vault & AppViewX

GSS Group • India

On-site
INR 2,400,000 - 4,200,000
Sr. Security Tools Engineer - HashiCorp Vault & AppViewX
Sr. Security Tools Engineer - HashiCorp Vault & AppViewX

GSSTech Group • Bengaluru

On-site
INR 1,800,000 - 3,000,000
Senior IAM Engineer
Senior IAM Engineer

Jobtailor • Hyderabad

On-site
INR 1,500,000 - 2,300,000