07 Aug
|
Baseel Partners
|
Bengaluru
07 Aug
Baseel Partners
Bengaluru
Data Loss Prevention, Secure Web Gateway and EDR: Technology Architecture Lead
Role Overview
We are seeking an experienced and technically deep IAM Lead to own and advance the identity security foundations of one of Indias largest digital payments ecosystems. This is a hands-on technical leadership role responsible for designing, implementing, and operating the full spectrum of identity and access management capabilities from enterprise SSO and lifecycle governance through to privileged access vaulting, cloud security posture, endpoint protection, data loss prevention, email security, and emerging AI security controls. The IAM Lead bridges strategic design with day-to-day operational delivery, ensuring the security controls are robust, audit-ready, and aligned with regulatory obligations.
Key Responsibilities
Identity & Access Management
- Own end-to-end IAM governance including user lifecycle management, joiner-mover-leaver processes, access provisioning, and entitlement reviews.
- Design and operate enterprise single sign-on (SSO), federated identity, and conditional access policies across SaaS and on-premises applications.
- Enforce role-based access control (RBAC) frameworks and least-privilege principles across the organisation.
- Manage access exception handling, periodic access certifications, and segregation of duties (SoD) controls.
Privileged Access Governance
- Administer and mature the Privileged Access Management (PAM) platform – covering credential vaulting, session recording, and just-in-time (JIT) access provisioning for administrative accounts.
- Define and enforce policies for privileged account discovery, onboarding, rotation, and auditing.
- Ensure privileged session monitoring and forensic capability for high-risk administrative activities.
Cloud Security Posture Management (CSPM)
- Operate and tune cloud security posture management tooling to continuously assess misconfigurations, policy drift, and compliance gaps across cloud environments.
- Collaborate with cloud and infrastructure teams to remediate findings and harden cloud-native workloads.
- Maintain cloud security benchmarks aligned with CIS, NIST, and regulatory frameworks.
Secure Web Gateway (SWG) & Cloud Access Security Broker (CASB)
- Manage inline traffic inspection policies for web and SaaS application access, enforcing acceptable-use and data protection controls.
- Drive shadow IT discovery and risk assessment, with structured processes for SaaS application approval and onboarding.
- Enforce data loss prevention (DLP) policies across SaaS, web browsing, and endpoints – reducing data exfiltration risk without impeding business productivity.
Endpoint Detection & Response (EDR)
- Operate EDR platforms for behavioural threat detection across user endpoints and servers – tuning detection rules, investigating alerts, and driving real-time remediation.
- Own incident triage and fix workflows for endpoint security events, including root-cause analysis and configuration hardening.
- Maintain endpoint health baselines and proactively identify and close vulnerability gaps across the device fleet.
Data Loss Prevention (DLP)
- Design and maintain DLP policies spanning endpoints, cloud storage, email, and collaboration tools.
- Classify sensitive data assets in line with enterprise data classification frameworks and apply appropriate protection controls.
- Investigate DLP incidents, prepare evidence documentation, and drive remediation with data owners.
Mobile Device Management (MDM) & Endpoint Compliance
- Administer MDM platforms to enforce device enrolment, configuration baselines, and compliance policies for corporate and BYOD devices.
- Implement and maintain conditional access policies that gate application access based on device health and compliance posture.
- Manage endpoint lifecycle – provisioning, decommissioning, and remote wipe – in alignment with HR and IT processes.
Email Security
- Operate and optimise email security controls including anti-phishing, sandboxing, spoofing prevention (SPF, DKIM, DMARC), and attachment analysis.
- Design and execute phishing simulation programmes to measure and improve user security awareness.
- Investigate email-borne threats and coordinate incident response with the security operations team.
AI Security
- Govern approved AI tool access across the organisation – managing onboarding, usage policies, and data exposure controls for GenAI applications.
- Assess and mitigate risks arising from employee use of consumer AI tools, including data leakage and prompt injection exposure.
- Define and evolve the AI security framework as the organisation’s AI adoption matures.
Compliance, Audit & Governance
- Prepare and maintain audit-ready evidence, SOPs, and policy documentation for RBI, PCI-DSS, ISO 27001, and DPDP Act requirements.
- Support internal and external audit engagements across all IAM and security tooling domains.
- Maintain platform health metrics, security dashboards, and executive reporting for all in-scope tools.
Required Skills & Expertise
Deep technical expertise across the following domains is required:
- Enterprise IAM – user lifecycle, SSO (SAML, OIDC, OAuth),
conditional access, RBAC, and directory services (Entra ID / Active Directory).
- Privileged Access Management – credential vaulting, session recording, JIT provisioning, and PAM platform administration (e.g. CyberArk, BeyondTrust, or equivalent).
- Cloud Security Posture Management – continuous compliance monitoring, misconfiguration detection, and remediation across multi-cloud environments.
- Secure Web Gateway & CASB – inline traffic inspection, URL/app filtering, shadow IT visibility, and DLP enforcement for SaaS, web, and endpoints.
- Endpoint Detection & Response – behavioural threat detection, alert triage, root-cause analysis, and real-time remediation on user endpoints and servers.
- Data Loss Prevention – policy design and enforcement across endpoints, cloud, and email channels, underpinned by enterprise data classification frameworks.
- Mobile Device Management – MDM platform administration, device compliance enforcement, and conditional access integration.
- Email Security – anti-phishing controls, sandboxing, spoofing prevention (SPF/DKIM/DMARC), and phishing simulation programme management.
- AI Security – GenAI application governance, AI usage policy enforcement, and data exposure risk management.
- Tooling proficiency across Microsoft security suite (Entra ID, Defender, Purview, Intune), and complementary platforms for DLP, EDR, CASB, CrowdStrike, SWG, IAM, PAM, and Email Security.
Education
- Bachelor of Engineering or Bachelor of Technology (Computer Science, Information Technology, or related field).
- Certificate, Degree, or Diploma in Cybersecurity (advantageous but not mandatory).
Preferred Certifications
Not mandatory, but advantageous:
- CISSP – Certified Information Systems Security Qualified
- CISM – Certified Information Security Manager
- Microsoft Certified: Identity and Access Administrator Associate (SC-300)
- Microsoft Certified: Security Operations Analyst Associate (SC-200)
- Certified Identity and Access Manager (CIAM) or equivalent IAM-specialist certification
Compensation:
- Full time Role INR 24 lakh - 28 Lakh per annum
- Onsite working
- Immediate start
- This is a Full time consultant role.
- Possibility of onsite travel
Baseel:
Baseel Partners LLP (Baseel.com) is a company initially focused on cybersecurity and data protection. Today, Baseel Group has expanded significantly, providing a comprehensive suite of IT services and products to clients in over 100 countries. A distinguished global entity, Baseel Partners LLP has established a strong network of partners across Europe, the UK, Asia, and MENA countries. Baseel has some clients in the area of Data Governance who are looking for MDM implementation.
📌 EDR and DLP Specialist (Bengaluru)
🏢 Baseel Partners
📍 Bengaluru