Destaca-te para esta função — cria um currículo personalizado e uma carta de apresentação em cerca de um minuto.
Sysmatch in Lisbon seeks an IAM Team Leader to design and govern end-to-end IAM architecture, including AD DS, AD FS, AD CS, and Microsoft Entra ID, with hybrid work options.
You will coordinate security across PAM/CyberArk, PIM, SSO, SCIM automation, scripting in PowerShell and Python, and partner with ServiceNow to automate changes and governance for clients worldwide.
IAM Team Leader – Hybrid (Lisbon) M/F Who we are: With over 25 years of experience, Sysmatch is a well-established name in IT Consultancy and Outsourcing, involved in both national and international projects that promote excellence in technology and services.
Our secret? A team that blends talent, creativity, and experience to deliver robust, scalable, and tailored solutions. We're not just tech experts — we're partners who support our clients' transformation, anticipate trends, and drive their evolution.
Flexibility, innovation, and a forward-thinking mindset are part of our DNA. We're hiring: IAM Team Leader – Hybrid - (Lisbon 3x) M/F
Design and govern the end-to-end IAM architecture, including Active Directory Domain Services (AD DS) domain structure, FSMO roles, replication topology, Group Policy, DNS/DHCP integration, and forest trust relationships.
Architect and oversee Active Directory Federation Services (AD FS), Single Sign-On (SSO) configurations, and trust relationships with external identity providers.
Design and maintain the Active Directory Certificate Services (AD CS/PKI) architecture, including Certification Authority (CA) hierarchy, certificate templates, and auto-enrollment policies.
Govern the Microsoft Entra ID architecture, including identity lifecycle management, Conditional Access policies, MFA and passwordless authentication strategies, SSO integrations, external identities (B2B/B2C), and SCIM automation.
Define Identity Governance frameworks, including Privileged Identity Management (PIM) role lifecycle, Access Review schedules, access assignment policies, and privileged identity protection standards.
Oversee the Privileged Access Management (PAM) architecture and integrations with CyberArk and SailPoint, ensuring least-privilege enforcement and privileged session monitoring.
Lead identity security initiatives, including Identity Protection signals, risk-based access policies, threat correlation with the Security Operations Center (SOC), and audit evidence preparation.
Conduct architecture reviews, capacity planning, and lifecycle governance across the entire IAM infrastructure.
Act as the highest technical escalation point for complex identity-related incidents that cannot be resolved by IAM or PAM teams.
Define and maintain automation frameworks using PowerShell and Python for identity lifecycle operations, compliance validation, and drift detection.
Coordinate IAM workflow orchestration through ServiceNow, ensuring that Change, Request, Incident, and lifecycle processes are automated, auditable, and compliant.
Produce architecture documentation, technical design decisions, compliance reports, and governance documentation for internal teams and customers.
Support recruitment, onboarding, and training of new IAM team members.
Minimum of 7 years of hands-on experience in Identity and Access Management, including at least 2 years in a team leadership, architecture, or supervisory role.
Microsoft Certified: Identity and Access Administrator Associate certification (or equivalent).
Expert knowledge of Active Directory (AD DS, AD FS, and AD CS), Kerberos, LDAP and Group Policy.
Extensive experience with Microsoft Entra ID (Azure AD), Conditional Access, Privileged Identity Management (PIM), MFA and passwordless authentication strategies, SSO integrations, external identities (B2B/B2C), and SCIM automation.
Strong understanding of authentication protocols, including SAML, OAuth 2.0, OpenID Connect (OIDC), and RADIUS.
Experience with CyberArk Privileged Access Management and SailPoint identity governance platforms.
Proven experience designing and governing Public Key Infrastructure (PKI) architectures and digital certificate services.
Strong scripting and automation skills using PowerShell and Python.
Familiarity with ServiceNow, including Incident, Change, Request and CMDB modules.
Excellent analytical and structured problem-solving skills.
Strong written and verbal communication skills in English (B2 level or above), with the ability to interact with customers and produce governance reports.
Proven experience managing shift-based teams and coordinating distributed teams across multiple time zones.
Microsoft Certified: Security, Compliance, and Identity Fundamentals or Microsoft Cybersecurity Architect Expert certification.
Previous experience in Managed Service Provider (MSP) environments or the financial services sector. Experience automating identity lifecycle processes using SCIM and API integrations.
Knowledge of regulatory frameworks such as DORA, FCA, or PRA.
Experience designing and implementing Zero Trust architectures.
Familiarity with BeyondTrust or other Privileged Access Management (PAM) platforms in addition to CyberArk.
Knowledge of Active Directory Domain Services (AD DS) decommissioning strategies and cloud identity migration.