Iam Team Leader

Dellent

Almada

Híbrido

EUR 70 000 - 90 000

Tempo integral

há 9 horas
Torna-te num dos primeiros candidatos
Gerador de candidaturas

Destaca-te para esta função — cria um currículo personalizado e uma carta de apresentação em cerca de um minuto.

Ultrapassa os filtros ATS

Resumo da oferta

Sysmatch is seeking an IAM Team Leader for a hybrid role in Lisbon. You will lead a 24x7 IAM engineering team and govern AD DS, AD FS, PKI, and Entra ID across multiple environments.

The role requires strong automation skills (PowerShell, Python), ServiceNow, and experience coordinating distributed teams. You\'ll design secure identity architectures and drive governance for clients.

Qualificações

  • 7+ years in IAM with 2+ years in leadership or architecture.
  • Microsoft Certified: Identity and Access Administrator Associate.
  • Expert knowledge of AD DS, AD FS, AD CS, Kerberos, LDAP, and Group Policy.
  • Extensive experience with Microsoft Entra ID, CA, MFA/Passwordless, SSO, and governance.
  • Strong understanding of SAML, OAuth 2.0, OIDC, and RADIUS.
  • Experience with CyberArk and SailPoint.
  • Scripting and automation using PowerShell and Python.
  • Familiarity with ServiceNow modules.
  • Excellent analytical and English communication (B2+) skills.
  • Experience managing shift-based teams across multiple time zones.

Responsabilidades

  • Lead IAM team, manage 24x7 shift planning, workload distribution, and career development.
  • Design and govern end-to-end IAM architecture including AD DS, AD FS, PKI.
  • Oversee Entra ID, MFA/Passwordless, SSO, and external identities integration.
  • Define governance for PIM, access reviews, and privileged access protection.
  • Coordinate PAM with CyberArk and SailPoint to enforce least privilege.
  • Automate identity lifecycle using PowerShell and Python; ensure drift detection.
  • Coordinate IAM workflows via ServiceNow across Change, Incident, and Request.
  • Produce governance docs and support recruitment and onboarding.

Conhecimentos

Active Directory
Azure Entra ID
Privileged Identity Management
MFA/Passwordless
SSO
SAML/OAuth/OIDC
PKI
CyberArk
SailPoint
PowerShell
Python
ServiceNow

Ferramentas

CyberArk
SailPoint
ServiceNow

Descrição da oferta de emprego

IAM Team Leader – Hybrid (Lisbon) M/F

Who we are:With over 25 years of experience, Sysmatch is a well-established name in IT Consultancy and Outsourcing, involved in both national and international projects that promote excellence in technology and services.

Our secret?

A team that blends talent, creativity, and experience to deliver robust, scalable, and tailored solutions.

We're not just tech experts — we're partners who support our clients' transformation, anticipate trends, and drive their evolution.

Flexibility, innovation, and a forward-thinking mindset are part of our DNA.

We're hiring:IAM Team Leader – Hybrid - (Lisbon 3x) M/F

Responsibilities:
  • Lead and manage the Identity and Access Management (IAM) team, including shift planning for 24x7 IAM engineers, workload distribution, performance reviews, coaching, and career development.
  • Design and govern the end-to-end IAM architecture, including Active Directory Domain Services (AD DS) domain structure, FSMO roles, replication topology, Group Policy, DNS/DHCP integration, and forest trust relationships.
  • Architect and oversee Active Directory Federation Services (AD FS), Single Sign-On (SSO) configurations, and trust relationships with external identity providers.
  • Design and maintain the Active Directory Certificate Services (AD CS/PKI) architecture, including Certification Authority (CA) hierarchy, certificate templates, and auto-enrollment policies.
  • Govern the Microsoft Entra ID architecture, including identity lifecycle management, Conditional Access policies, MFA and passwordless authentication strategies, SSO integrations, external identities (B2B/B2C), and SCIM automation.
  • Define Identity Governance frameworks, including Privileged Identity Management (PIM) role lifecycle, Access Review schedules, access assignment policies, and privileged identity protection standards.
  • Oversee the Privileged Access Management (PAM) architecture and integrations with CyberArk and SailPoint, ensuring least-privilege enforcement and privileged session monitoring.
  • Lead identity security initiatives, including Identity Protection signals, risk-based access policies, threat correlation with the Security Operations Center (SOC), and audit evidence preparation.
  • Conduct architecture reviews, capacity planning, and lifecycle governance across the entire IAM infrastructure.
  • Act as the highest technical escalation point for complex identity-related incidents that cannot be resolved by IAM or PAM teams.
  • Define and maintain automation frameworks using PowerShell and Python for identity lifecycle operations, compliance validation, and drift detection.
  • Coordinate IAM workflow orchestration through ServiceNow, ensuring that Change, Request, Incident, and lifecycle processes are automated, auditable, and compliant.
  • Produce architecture documentation, technical design decisions, compliance reports, and governance documentation for internal teams and customers.
  • Support recruitment, onboarding, and training of new IAM team members.
Mandatory Requirements:
  • Minimum of 7 years of hands-on experience in Identity and Access Management, including at least 2 years in a team leadership, architecture, or supervisory role.
  • Microsoft Certified: Identity and Access Administrator Associate certification (or equivalent).
  • Expert knowledge of Active Directory (AD DS, AD FS, and AD CS), Kerberos, LDAP, and Group Policy.
  • Extensive experience with Microsoft Entra ID (Azure AD), Conditional Access, Privileged Identity Management (PIM), MFA/Passwordless, Single Sign-On (SSO), and identity governance.
  • Strong understanding of authentication protocols, including SAML, OAuth 2.0, OpenID Connect (OIDC), and RADIUS.
  • Experience with CyberArk Privileged Access Management and SailPoint identity governance platforms.
  • Proven experience designing and governing Public Key Infrastructure (PKI) architectures and digital certificate services.
  • Strong scripting and automation skills using PowerShell and Python.
  • Familiarity with ServiceNow, including Incident, Change, Request, and CMDB modules.
  • Excellent analytical and structured problem-solving skills.
  • Strong written and verbal communication skills in English (B2 level or above), with the ability to interact with customers and produce governance reports.
  • Proven experience managing shift-based teams and coordinating distributed teams across multiple time zones.
Nice to Have:
  • Microsoft Certified: Security, Compliance, and Identity Fundamentals or Microsoft Cybersecurity Architect Expert certification.
  • Previous experience in Managed Service Provider (MSP) environments or the financial services sector.
  • Experience automating identity lifecycle processes using SCIM and API integrations.
  • Knowledge of regulatory frameworks such as DORA, FCA, or PRA.
  • Experience designing and implementing Zero Trust architectures.
  • Familiarity with BeyondTrust or other Privileged Access Management (PAM) platforms in addition to CyberArk.
  • Knowledge of Active Directory Domain Services (AD DS) decommissioning strategies and cloud identity migration.
What we offer:
  • A personalized onboarding experience that welcomes and supports you throughout your journey.
  • Regular and constructive feedback to boost your growth and development.
  • A dynamic project with a prestigious client.
  • A competitive salary package, aligned with your experience and skills.
  • Career development opportunities through ambitious and innovative tech projects.
  • A collaborative culture that values creativity and individual progress.
  • Access to exclusive discounts in a wide network of partners, including health, wellness, travel, culture, gastronomy, leisure and much more.
  • Team-building events and initiatives that create memorable shared experiences.
  • Salary Range: ******€ - ******€ Gross Annual + Benefits
Obtém a tua avaliação gratuita e confidencial do currículo.

ou arrasta e larga o ficheiro aqui.

Similar jobs

Ofertas semelhantes que vale a pena comparar

Iam Team Leader
Iam Team Leader

Dellent • Setúbal

Híbrido
EUR 60 000 - 100 000
Onboarding experience
Dynamic projects
Competitive salary
+3
IAM Team Leader – Hybrid (Lisbon) M/F
IAM Team Leader – Hybrid (Lisbon) M/F

SysMatch • Lisboa

Presencial
EUR 40 000 - 50 000
Hybrid work in Lisbon
Career development
Team-building events
Devoteam Cyber Trust |IAM Engineer | Retail & E-commerce Sector
Devoteam Cyber Trust |IAM Engineer | Retail & E-commerce Sector

Devoteam | Cyber Trust • Porto

Presencial
EUR 40 000 - 60 000
IAM Service Owner
IAM Service Owner

Hiire • Portugal

Híbrido
EUR 48 000 - 64 000
Performance bonus
Health insurance extendable to household
Flexible working hours
+3
IAM Team Leader M/F
IAM Team Leader M/F

Sysmatch • Lisboa

Híbrido
EUR 70 000 - 100 000
Onboarding personalizado
Descontos exclusivos
Team Buildings
Iam Service Owner
Iam Service Owner

Hiire • Lisboa

Presencial
EUR 48 000 - 64 000
Health insurance extendable to household
Performance bonus
Flexible working hours
+1
Devoteam Cyber Trust |IAM Project Management | Banking Sector
Devoteam Cyber Trust |IAM Project Management | Banking Sector

Devoteam | Cyber Trust • Lisboa

Presencial
EUR 50 000 - 70 000
Professional development opportunities
Collaborative work culture
Commitment to diversity
IAM Engineer
IAM Engineer

mainfyld • Lisboa

Presencial
EUR 55 000 - 75 000
IAM Engineer
IAM Engineer

Fyld • Lisboa

Presencial
EUR 42 000 - 64 000
Continuous training
Certification opportunities
Collaborative culture
+1
IAM Team Leader - Hybrid (Lisbon)
IAM Team Leader - Hybrid (Lisbon)

SysMatch • Lisboa

Híbrido
EUR 40 000 - 50 000
Hybrid work in Lisbon
Career development
Team-building events