Senior IAM Engineer

Jobtailor

Hyderabad

On-site

INR 1,500,000 - 2,300,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Jobtailor seeks an experienced IAM leader to drive the implementation and governance of enterprise IAM and PAM programs. You will coordinate with vendors, design privileged access models, and define lifecycle management across cloud and on‑prem environments.

The role requires deep experience with PAM tooling (BeyondTrust, CyberArk, Delinea), zero trust concepts, and strong collaboration with engineering and security teams.

Qualifications

  • Experience designing, implementing, and managing complex IAM solutions.
  • Strong understanding of identity and privileged constructs within cloud environments.
  • Understanding and demonstrated use of DevOps tools (CI/CD) with automation.
  • Experience with PAM solutions such as BeyondTrust, CyberArk, Delinea for enterprises.
  • Experience with password safe tools for Windows and Linux environments.
  • Experience with LDAP, directory services, and various IAM protocols (SAML, OAuth, IdPs).
  • Proficiency with CD/CI tooling and configuration management (Terraform, Ansible).
  • Strong leadership and communication skills for cross‑functional collaboration.

Responsibilities

  • Lead the implementation and development for the IAM program with a security focus.
  • Develop strategy roadmaps and enterprise standards for IAM.
  • Oversee PAM and Secrets Management platforms, providing technical guidance.
  • Coordinate remediation, audits, and policy compliance for IAM controls.

Skills

IAM
Privileged Access
Zero Trust
PKI
CIEM
ITDR
IGA
SAML/OAuth
MFA
SSO

Education

Bachelor's degree in CS/IS

Tools

BeyondTrust
CyberArk
Delinea
Terraform
Ansible
Jenkins

Job description

Responsibilities
  • Lead the implementation and development process for the Identify and access Management (IAM) program with a security focus.
  • Work with vendors and business partners to develop, implement and manage the IAM program.
  • Lead program design and review working directly with business lines on the integration requirements including provisioning, de-provision, and identity lifecycle into the IAM platforms.
  • Develop strategy roadmaps for the IAM systems and the IAM program, develop enterprise-wide standards for IAM.
  • Implement or coordinate remediation required by policies, standards, reviews, and audits, documenting exceptions as necessary.
  • Define the user access security model for all systems and platforms. Enforce least‑privilege model.
  • Provide subject matter expertise in multiple domain focus areas including but not limited to: Privileged Access Management and Secrets Management tooling such as CyberArk, Delinea, and HashiCorp.
  • Operate and maintain the Privileged Access Management and Secrets Management platforms to support various business use cases, providing in‑depth technical consultation to business application development teams to ensure efficient application systems.
  • Support PAM Security Strategy including provisioning, password management and access policies, SSH key management, API key management and reporting.
  • Support the operation of the PAM platform to ensure secure and efficient operation and usage for all lines of business.
  • PAM administration: Manage and mature the PAM platform including safe design, policy configuration, and session isolation for privileged accounts.
  • Credential lifecycle: Own automated password/secret rotation, onboarding of privileged and service accounts, and just‑in‑time access workflows to reduce standing privilege.
  • Certificate/PAM convergence: Support the integration of certificate lifecycle operations into the PAM platform, leveraging automation to reduce manual certificate handling.
  • Auditing & reporting: Produce privileged access usage reports and support audit evidence requests for SOC 2, PCI DSS, and ITGC controls.
  • Integrate PAM solution with various technologies. Provide security consultation on internal projects focusing on business needs, security's role in change management, and data transmission internally and externally.
  • Design, configure, and maintain PAM solutions for Linux and Windows tools.
  • Access governance: Support periodic access certifications, least‑privilege reviews, and segregation‑of‑duties analysis in partnership with Access Governance and GRC teams.
  • RBAC/ABAC design: Define and maintain role‑based and attribute‑based access models for critical applications.
  • Provisioning integrations: Build and maintain SCIM, API, and directory‑based integrations connecting HR systems, Active Directory, and downstream applications.
  • Lifecycle ownership: Manage issuance, renewal, revocation, and inventory of internal and external TLS/SSL certificates across cloud and on‑prem environments.
  • Automation: Build automated monitoring and renewal pipelines to eliminate expiration‑driven outages, integrating with CyberArk and internal CI/CD tooling.
  • PKI hygiene: Maintain certificate authority relationships, key management standards, and rotation policies aligned to industry best practice.
  • Platform administration: Configure and maintain Okta as the enterprise SSO and MFA provider, including application integrations (SAML, OIDC, OAuth, SWA), policies, and group rules.
  • Authentication engineering: Implement adaptive MFA, conditional access policies, and passwordless authentication initiatives.
  • App onboarding: Partner with application and engineering teams to onboard new applications into Okta, including custom OIDC/SAML integrations for internal tools.
  • AI identity operations: Support emerging identity controls for AI agents and machine identities, including scoped OAuth tokens and service‑to‑service authentication.
  • Lead IAM engineering strategy and execution, set the direction for engineering efforts, drive technology selection (including bus vs build decision), and act as the functional technical leader during implementation.
  • Establish CIEM, ITDR, IGA strategy, implementation and operationalization.
  • Evaluate and monitor project efforts, timelines, and task management.
Requirements
  • A minimum of 5 years of experience.
  • Bachelor’s degree in computer science, Information Systems, or an equivalent combination of education and experience.
  • Relevant security certifications.
  • Experience designing, implementing, and managing complex IAM solutions.
  • Strong understanding of identity and privileged constructs within cloud environments.
  • Understanding and demonstrated use of DevOps tools (Bitbucket, GitLab, GitHub, Jenkins, automated deployment tools) with CI/CD capabilities.
  • Experience designing and implementing PAM solutions such as BeyondTrust, CyberArk, Delinea for enterprise organizations.
  • Experience with password safe tools such as BeyondTrust Password Safe and PowerBroker for both Windows and Linux environments.
  • Experience with databases, LDAP and directory services, application servers, operating systems and network infrastructure.
  • Strong understanding of identity lifecycle in regard to privileged accounts and how people use accounts.
  • Experience with Zero Trust security.
  • Proficiency in Active Directory, LDAP, SAML, OAuth, IdPs.
  • Demonstrate an advanced understanding of troubleshooting and configuring privileged applications, privileged ID management, and API integrations.
  • Understanding of emerging authorization mechanisms based on Zanzibar/ReBAC.
  • Experience with CIEM, ITDR and IGA platforms.
  • Maintain documentation related to IAM processes, configurations, incident response procedures and run books.
  • Working knowledge of certificate management / PKI concepts (TLS, CA hierarchies, key rotation).
  • Experience with configuration management tools like Terraform, Ansible, etc.
  • Experience with cloud technologies, e.g., AWS, Azure, GCP, OCI.
  • Advanced programming experience (Python, Go, etc.).
  • Strong critical thinking and analytical skills.
  • Ability to approach problem solving in a constructive and collaborative way that does not require absolute security.
  • Ability to communicate complicated technical issues and risks to programmers, network engineers and managers.
  • Strong leadership, project, and team‑building skills.
  • Exceptional communication skills with diverse audiences; the ability to be an infrastructure security subject matter expert who can explain relevant topics to general audiences.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

IAM Architect
IAM Architect

Gas Strategies • Bengaluru

On-site
INR 3,500,000 - 5,500,000
Senior Engineer, Identity and Access Management
Senior Engineer, Identity and Access Management

ICE • Hyderabad

On-site
INR 1,200,000 - 2,100,000
Architect - Identity & Access Management
Architect - Identity & Access Management

PepsiCo • Hyderabad

On-site
INR 1,800,000 - 2,400,000
Architect - Identity & Access Management
Architect - Identity & Access Management

PepsiCo Deutschland GmbH • Hyderabad

On-site
INR 1,400,000 - 2,200,000
Senior Identity & Access Management Engineer
Senior Identity & Access Management Engineer

India Fan Corporation • Hyderabad

On-site
INR 2,400,000 - 3,600,000
Identity & Access Management Lead
Identity & Access Management Lead

Capgemini • Navi Mumbai

On-site
INR 2,500,000 - 3,500,000
Iam Support Engineer
Iam Support Engineer

Elabs Infotech • Hyderabad, Pune District, Bengaluru

On-site
INR 1,200,000 - 2,300,000
Senior Lead – Access Management
Senior Lead – Access Management

Northern Trust • Pune District

On-site
INR 3,000,000 - 4,200,000
Architect - Identity and Access Management - IAM SME
Architect - Identity and Access Management - IAM SME

PepsiCo • Hyderabad

On-site
INR 3,000,000 - 6,000,000
IAM Analyst(Delinea)-Senior Associate-Cyber Managed services-Consult
IAM Analyst(Delinea)-Senior Associate-Cyber Managed services-Consult

PwC Acceleration Center India • Hyderabad

On-site
INR 1,200,000 - 1,800,000