Sr. Associate I - Identity and Access management Security

alcon

Bengaluru

On-site

INR 2,500,000 - 4,500,000

Full time

10 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Alcon is seeking a Senior Active Directory Engineer to lead the design, deployment, and optimization of our enterprise identity infrastructure in Bengaluru. This role emphasizes AD, Azure AD, Group Policy, and hybrid identity solutions to secure user access and support audits.

You will collaborate with IT and business teams to align IAM with security goals, mentor colleagues, and ensure resilient authentication across environments, including on‑prem and cloud components.

Qualifications

  • 6–8 years total IT experience with 5+ years in identity and access management.
  • Experience designing and deploying hybrid identity solutions (Azure AD, on‑prem AD).
  • Expertise in Active Directory, DNS, DHCP, Kerberos, and authentication protocols.

Responsibilities

  • Lead design, implementation, and optimization of enterprise identity infrastructure including AD/Hybrid Identity.
  • Maintain and secure IAM systems; ensure compliance with security policies and audits.
  • Collaborate with IT and business units to meet security requirements and improve IAM processes.
  • Mentor team members to foster security awareness and best practices.
  • Support risk assessments and implement security controls; troubleshoot access issues.

Skills

Active Directory
Azure AD
Group Policy
PowerShell
RBAC
SSO
MFA
PAM
Identity & Access Management

Tools

Intune
Azure AD Connect
Saviynt
Secret Server
Okta

Job description

Summary of Position:

At Alcon, we're passionate about enhancing sight and helping people see brilliantly. With more than 25,000 associates, we innovate fearlessly, champion progress, and act swiftly to impact global eye health. We foster an inclusive culture, recognizing your contributions and offering opportunities to grow your career like never before. Together, we make a difference in the lives of our patients and customers. Are you ready to join us?

This role is part of Alcon's Information Technology function, a team that delivers cutting-edge technology solutions to Alcon associates and customers to help our people and the world see brilliantly.

Sr. Associate I, Identity & Access Management Security (Science/Tech/Engineering Path)

The Sr. Associate I, Identity & Access Management Security (Science/Tech/Engineering Path), is primarily responsible for supporting the development, deployment, and maintenance of secure IAM systems, ensuring compliance with identity and access management policies, and resolving access control and system vulnerabilities.

Specifics include:

  • Drive adoption of the strategy for IAM security, aligning with organizational risk management and security goals
  • Design secure, enterprise-wide IAM solutions, implementing industry best practices
  • Collaborate with IT and business teams to ensure IAM systems meet business needs and compliance requirements, and to optimize IAM processes and improve system security
  • Mentor team members to foster a culture of security awareness and innovation
  • Support complex risk assessments and work with cross-functional teams to implement security protocols
  • Assist in implementing IAM systems, ensuring secure user access and adherence to policies
  • Participate in audits of IAM systems to ensure compliance with security and regulatory standards
  • Provide technical support for IAM-related issues, troubleshooting access control problems
  • Document IAM procedures and provide reports on system performance and security audits
  • Support the IAM team in maintaining and optimizing access control and identity management systems, contributing to addressing security vulnerabilities and maintaining compliance
  • Handle day-to-day operational tasks, including troubleshooting, issue resolution, application onboarding, and data cleanup for IAM systems.
Key Responsibilities:

We are seeking a highly experienced Senior Active Directory Engineer to lead the design, implementation, and optimization of our enterprise identity infrastructure. This role demands deep technical expertise in Active Directory, Azure AD, Group Policy, and hybrid identity solutions.

Key Requirements/Minimum Qualifications:
Active Directory:
  • Expertise in maintaining complex Active Directory environments including multi-domain forests, trusts, replication, and domain controller placement.
  • 6-8 years of total experience with 5+ years of relevant experience.
  • Experience in design and deployment of hybrid identity solutions integrating Azure AD, Intune, and on-prem AD.
  • Domain Controller Management Promotion, decommissioning and health monitoring of DCs.
  • Develop and enforce Group Policy Objects (GPOs) to support enterprise-wide security and configuration standards.
  • Manage and troubleshoot DNS, DHCP, Kerberos, and authentication protocols.
  • Expertise in managing and configuring Azure AD and Azure AD Connect for hybrid cloud environments.
  • Familiarity with PowerShell scripting for automation of Active Directory and server management tasks.
  • Good knowledge in networking, storage, and security within virtualized environments.
  • Experience with disaster recovery and high availability (HA) strategies in a virtualized infrastructure.
  • Managing Azure Entra ID solutions including user provisioning, group management, role-based access control (RBAC), and conditional access policies.
  • Strong knowledge on IAM solutions including authentication, authorization, SSO, MFA, and privileged access management (PAM).
  • Having knowledge on solutions like Saviynt, Secret Server and Okta is plus.
Preferred Certifications:
  • MCSE/MCSA or relevant certifications.
PKI:
  • Strong knowledge on deployment and management of PKI and Managed PKI solutions.
  • Strong knowledge on PKI, HSM, Encryption and Cryptography solution.
Work hours:

8PM - 5AM and 1PM - 10PM and 5AM - 2PM (Rotational bi- weekly). Rotational weekend on-call.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Engineer, Identity and Access Management
Senior Engineer, Identity and Access Management

ICE Data Services • Hyderabad

On-site
INR 1,500,000 - 2,600,000
Senior Engineer, Identity and Access Management
Senior Engineer, Identity and Access Management

ICE • Hyderabad

On-site
INR 1,200,000 - 2,100,000
Senior Identity & Access Management Engineer
Senior Identity & Access Management Engineer

India Fan Corporation • Hyderabad

On-site
INR 2,400,000 - 3,600,000
Senior AWS IAM & Okta Engineer
Senior AWS IAM & Okta Engineer

UST • Ernakulam

On-site
INR 1,800,000 - 3,000,000
Senior Lead – Access Management
Senior Lead – Access Management

Northern Trust • Pune District

On-site
INR 3,000,000 - 4,200,000
Senior IAM Engineer
Senior IAM Engineer

Jobtailor • Hyderabad

On-site
INR 1,500,000 - 2,300,000
Executive Manager - IAM / Azure AD
Executive Manager - IAM / Azure AD

PepsiCo • Hyderabad

On-site
INR 1,500,000 - 2,000,000
Iam Support Engineer
Iam Support Engineer

Elabs Infotech • Hyderabad, Pune District, Bengaluru

On-site
INR 1,200,000 - 2,300,000
IAM Engineer
IAM Engineer

Enphase Energy • Bengaluru

Hybrid
INR 1,400,000 - 2,200,000
IAM Engineer
IAM Engineer

UST • Chennai District

Hybrid
INR 900,000 - 1,500,000