09 Aug
|
Su0026P Global
|
Hyderabad
09 Aug
Su0026P Global
Hyderabad
Description
- Partner with technology stakeholders to identify and assess identity-related vulnerabilities and control gaps through grey box testing.
- IAM architecture experience, including MFA and tools such as SailPoint and CyberArk.
- Act as a subject matter expert in IAM security testing, providing deep insights into exploitation techniques across IAM solutions.
- Assess the effectiveness of Identity Governance & Administration controls (provisioning, RBAC, access certifications) through control testing, abuse-case simulation, and privilege escalation scenarios.
- Conduct risk-based vulnerability assessments focused on identity attack vectors, including credential compromise, privilege misuse, and lateral movement.
- Drive and assess adoption of Secure-by-Design principles, validating implementation through security testing across the SDLC and pre-production environments.
- Lead testing and validation of advanced IAM capabilities such as MFA bypass scenarios, SSO misconfigurations, and Privileged Access Management (PAM) weaknesses.
- Continuously monitor and emulate emerging IAM threat techniques, attack vectors, and adversary tactics, integrating them into test scenarios and audit coverage.
- Collaborate with other technology auditors to develop and execute audit programs to support coverage for established, emerging, frontier technologies and related applications/workflows (IAM, Cybersecurity, and AI/GenAI).
Requirements
- 8+ years of experience in IAM and cybersecurity,
with solid hands-on expertise in vulnerability assessment and security testing of identity platforms and access control mechanisms. Broader information security experience is a plus.
- Strong experience in testing identity governance and access management controls, including provisioning, RBAC models, privilege escalation, and access certification bypass scenarios.
- Experience performing security testing of IAM solutions in cloud environments (AWS, Azure, GCP), including validation of authentication, authorization, and federation controls.
- Understanding of cryptographic controls, PKI, and their exploitation risks, with the ability to assess weaknesses in identity and authentication mechanisms.
- Knowledge of Zero Trust architectures, DevSecOps pipelines, and modern application environments with a focus on identifying identity-driven attack paths.
- Knowledge of security frameworks and regulatory standards (ISO 27001/27002, NIST, GDPR, PCI-DSS etc.)
- Experience in cloud IAM architectures (hybrid, multi-cloud, cloud-native), with the ability to identify misconfigurations and vulnerabilities.
- Strong stakeholder management skills with the ability to translate technical findings into risk-focused audit insights.
- Ability to analyze, synthesize, and communicate complex security testing results to both technical and non-technical stakeholders.
- Excellent written and verbal communication skills
- Willingness to travel as needed
📌 Senior Information Technology Audit Manager (Hyderabad)
🏢 Su0026P Global
📍 Hyderabad