### IAM Team Leader – Hybrid (Lisbon) M/FWho we are:With over 25 years of experience, Sysmatch is a well-established name in IT Consultancy and Outsourcing, involved in both national and international projects that promote excellence in technology and services. Our secret? A team that blends talent, creativity, and experience to deliver robust, scalable, and tailored solutions.We’re not just tech experts — we’re partners who support our clients’ transformation, anticipate trends, and drive their evolution. Flexibility, innovation, and a forward-thinking mindset are part of our DNA.We’re hiring:IAM Team Leader – Hybrid - (Lisbon 3x) M/FResponsibilities:- Lead and manage the Identity and Access Management (IAM) team, including shift planning for 24x7 IAM engineers, workload distribution, performance reviews, coaching, and career development.- Design and govern the end-to-end IAM architecture, including Active Directory Domain Services (AD DS) domain structure, FSMO roles, replication topology, Group Policy, DNS/DHCP integration, and forest trust relationships.- Architect and oversee Active Directory Federation Services (AD FS), Single Sign-On (SSO) configurations, and trust relationships with external identity providers.- Design and maintain the Active Directory Certificate Services (AD CS/PKI) architecture, including Certification Authority (CA) hierarchy, certificate templates, and auto-enrollment policies.- Govern the Microsoft Entra ID architecture, including identity lifecycle management, Conditional Access policies, MFA and passwordless authentication strategies, SSO integrations, external identities (B2B/B2C), and SCIM automation.- Define Identity Governance frameworks, including Privileged Identity Management (PIM) role lifecycle, Access Review schedules, access assignment policies, and privileged identity protection standards.- Oversee the Privileged Access Management (PAM) architecture and integrations with CyberArk and SailPoint, ensuring least-privilege enforcement and privileged session monitoring.- Lead identity security initiatives, including Identity Protection signals, risk-based access policies, threat correlation with the Security Operations Center (SOC), and audit evidence preparation.- Conduct architecture reviews, capacity planning, and lifecycle governance across the entire IAM infrastructure.- Act as the highest technical escalation point for complex identity-related incidents that cannot be resolved by IAM or PAM teams.- Define and maintain automation frameworks using PowerShell and Python for identity lifecycle operations, compliance validation, and drift detection.- Coordinate IAM workflow orchestration through ServiceNow, ensuring that Change, Request, Incident, and lifecycle processes are automated, auditable, and compliant.- Produce architecture documentation, technical design decisions, compliance reports, and governance documentation for internal teams and customers.- Support recruitment, onboarding, and training of new IAM team members.Mandatory Requirements:- Minimum of 7 years of hands-on experience in Identity and Access Management, including at least 2 years in a team leadership, architecture, or supervisory role.- Microsoft Certified: Identity and Access Administrator Associate certification (or equivalent).- Expert knowledge of Active Directory (AD DS, AD FS, and AD CS), Kerberos, LDAP, and Group Policy.- Extensive experience with Microsoft Entra ID (Azure AD), Conditional Access, Privileged Identity Management (PIM), MFA/Passwordless, Single Sign-On (SSO), and identity governance.- Strong understanding of authentication protocols, including SAML, OAuth 2.0, OpenID Connect (OIDC), and RADIUS.- Experience with CyberArk Privileged Access Management and SailPoint identity governance platforms.- Proven experience designing and governing Public Key Infrastructure (PKI) architectures and digital certificate services.- Strong scripting and automation skills using PowerShell and Python.- Familiarity with ServiceNow, including Incident, Change, Request, and CMDB modules.- Excellent analytical and structured problem-solving skills.- Strong written and verbal communication skills in English (B2 level or above), with the ability to interact with customers and produce governance reports.- Proven experience managing shift-based teams and coordinating distributed teams across multiple time zones.Nice to Have:- Microsoft Certified: Security, Compliance, and Identity Fundamentals or Microsoft Cybersecurity Architect Expert certification.- Previous experience in Managed Service Provider (MSP) environments or the financial services sector.Experience automating identity lifecycle processes using SCIM and API integrations.- Knowledge of regulatory frameworks such as DORA, FCA, or PRA.- Experience designing and implementing Zero Trust architectures.- Familiarity with BeyondTrust or other Privileged Access Management (PAM) platforms in addition to CyberArk.- Knowledge of Active Directory Domain Services (AD DS) decommissioning strategies and cloud identity migration.What we offer:• A personalized onboarding experience that welcomes and supports you throughout your journey.• Regular and constructive feedback to boost your growth and development.• A dynamic project with a prestigious client.• A competitive salary package, aligned with your experience and skills.• Career development opportunities through ambitious and innovative tech projects.• A collaborative culture that values creativity and individual progress.• Access to exclusive discounts in a wide network of partners, including health, wellness, travel, culture, gastronomy, leisure and much more.• Team-building events and initiatives that create memorable shared experiences.Salary Range: 40.000€ - 50.000€ Gross Annual + BenefitsTo apply, just send your updated CV with the reference RS/IAM/C to: emprego@sysmatch.com