05 Aug
|
HCL Technologies
|
Bengaluru
05 Aug
HCL Technologies
Bengaluru
Senior Administrator - IAM Operations
Experience: 3 to Not Available years
Location: Bengaluru, India
Skills: IAM, PAM, Access Management, CyberArk, Service Account Management, RBAC, AD/LDAP, ITIL, PowerShell, Python, SailPoint, Saviynt, Okta, Azure AD, Entra ID, Ping, CyberArk Conjur, HashiCorp Vault, AWS, Azure, GCP
Job Summary
Key Sourcing Information :Experience working on Identify and Access Management, Service Account Management with expertise on CyberArk Tool
Key Responsibilities
IAM & Access Governance
• Support and enhance enterprise IAM controls including provisioning, deprovisioning, RBAC, and access reviews.
• Implement and enforce least privilege access and segregation of duties (SoD) aligned with security policies.
• Assist with identity lifecycle processes, user access requests, and audit evidence collection.
Service Account Management (Core Focus)
• Manage end-to-end lifecycle of service accounts (creation, ownership assignment, approvals, periodic reviews, decommissioning).
• Define and enforce standards for:
o Service account naming conventions
o Ownership and accountability model
o Expiration/attestation and revalidation cycles
o Access entitlements & group memberships
• Reduce orphaned accounts, eliminate shared credentials, and ensure traceability to business owners and applications.
CyberArk PAM Administration & Operations
• Onboard privileged accounts and service accounts into CyberArk Vault with appropriate safes, platforms, and policies.
• Configure and manage CyberArk components such as (as applicable):
o PVWA, CPM (password rotation), PSM (privileged session management)
o AIM/Conjur for application credential retrieval (if in scope)
• Implement and tune:
o Password rotation schedules and complexity rules
o Dual control / approvals for critical accounts
o Session recording and command controls (where applicable)
• Perform troubleshooting related to onboarding failures, CPM errors, reconciliation issues, platform compatibility, and connectivity.
Required Skills & Experience
Must Have
• 3+ years (or relevant) experience in IAM / PAM / Access Management roles.
• Strong experience in Service Account Management and privileged credential governance.
• Hands-on expertise with CyberArk (Vault onboarding, safes, platforms, CPM/PSM operations).
• Understanding of authentication mechanisms and access controls:
o AD/LDAP concepts, group policies, privileges, role-based access
• Strong troubleshooting skills for PAM integrations and operational issues.
• Experience working in ITIL environments (incident, change, problem management).
Good to Have
• CyberArk integration experience with:
o Windows / Linux / Database accounts (SQL/Oracle), network devices, middleware
• Scripting/automation knowledge: PowerShell / Python (basic to intermediate).
• Exposure to IAM tools (any): SailPoint, Saviynt, Okta, Azure AD/Entra ID, Ping, etc.
• Knowledge of secrets management solutions (CyberArk Conjur, HashiCorp Vault, etc.)
• Cloud exposure: AWS/Azure/GCP PAM patterns and service identities.
Other Requirements
Key Responsibilities
IAM & Access Governance
• Support and enhance enterprise IAM controls including provisioning, deprovisioning, RBAC, and access reviews.
• Implement and enforce least privilege access and segregation of duties (SoD) aligned with security policies.
• Assist with identity lifecycle processes, user access requests, and audit evidence collection.
Service Account Management (Core Focus)
• Manage end-to-end lifecycle of service accounts (creation, ownership assignment, approvals, periodic reviews, decommissioning).
• Define and enforce standards for:
o Service account naming conventions
o Ownership and accountability model
o Expiration/attestation and revalidation cycles
o Access entitlements & group memberships
• Reduce orphaned accounts, eliminate shared credentials, and ensure traceability to business owners and applications.
CyberArk PAM Administration & Operations
• Onboard privileged accounts and service accounts into CyberArk Vault with appropriate safes, platforms, and policies.
• Configure and manage CyberArk components such as (as applicable):
o PVWA, CPM (password rotation), PSM (privileged session management)
o AIM/Conjur for application credential retrieval (if in scope)
• Implement and tune:
o Password rotation schedules and complexity rules
o Dual control / approvals for critical accounts
o Session recording and command controls (where applicable)
• Perform troubleshooting related to onboarding failures, CPM errors, reconciliation issues, platform compatibility, and connectivity.
Required Skills & Experience
Must Have
• 3+ years (or relevant) experience in IAM / PAM / Access Management roles.
• Strong experience in Service Account Management and privileged credential governance.
• Hands-on expertise with CyberArk (Vault onboarding, safes, platforms, CPM/PSM operations).
• Understanding of authentication mechanisms and access controls:
o AD/LDAP concepts, group policies, privileges, role-based access
• Strong troubleshooting skills for PAM integrations and operational issues.
• Experience working in ITIL environments (incident, change, problem management).
Positive to Have
• CyberArk integration experience with:
o Windows / Linux / Database accounts (SQL/Oracle), network devices, middleware
• Scripting/automation knowledge: PowerShell / Python (basic to intermediate).
• Exposure to IAM tools (any): SailPoint, Saviynt, Okta, Azure AD/Entra ID, Ping, etc.
• Knowledge of secrets management solutions (CyberArk Conjur, HashiCorp Vault, etc.)
• Cloud exposure: AWS/Azure/GCP PAM patterns and service identities.
📌 Senior Administrator IAM Operations (Bengaluru)
🏢 HCL Technologies
📍 Bengaluru