Role: GTM Product Owner - Identity and Compliance Ops
Location: Noida / Chennai /Bengaluru
Role Purpose
Owns IdentityOps and ComplyOps as one governance proposition — human and non-human identity containment plus certifications kept in positive standing — sold as managed, outcome-committed services with an agentic-identity future.
Key Responsibilities
- Own the joint roadmap and commercial model for IAM-as-a-service and compliance-as-a-service across the client estate.
- Define the target-state identity architecture — Entra ID/Okta workforce IAM, SailPoint-class IGA and PAM — and the standards partner delivery teams implement.
- Own the compliance-as-a-service catalogue (ISO 27001, SOC 2, PCI DSS, GDPR, DORA readiness) with certification/outcome-linked pricing.
- Set the agentic/non-human identity roadmap — machine, workload and AI-agent identities as a first-class governed population.
- Run GRC platform strategy (ServiceNow GRC/IRM, Archer, Vanta/Drata-class automation) and continuous control monitoring across regimes.
- Represent identity and compliance posture in client and executive forums as one consolidated risk narrative tied to audit calendars.
Hard Skills
- Workforce IAM platform depth — Microsoft Entra ID (Conditional Access, PIM, Identity Governance)
and Okta Workforce Identity Cloud; comparative fluency with Ping Identity/ForgeRock.
- IGA & PAM architecture — SailPoint/Saviynt-class JML lifecycle, access certification and role mining; CyberArk/BeyondTrust/Delinea vaulting with JIT/zero-standing-privilege design.
- Non-human & agentic identity — NHI/workload/AI-agent identity lifecycle and secrets governance (CSA guidance); CIEM and ITDR as emerging control layers.
- Framework & standards depth — ISO/IEC 27001 ISMS, SOC 2 Trust Services Criteria, NIST CSF 2.0, PCI DSS, GDPR; DORA ICT and third-party risk provisions.
- GRC platform configuration — ServiceNow GRC/IRM and RSA Archer; Vanta/Drata/Sprinto-class compliance automation for continuous evidence collection.
- Audit & assurance methodology — ISO 27001 Lead Auditor/Implementer or CISA-level literacy; control testing and operating-effectiveness evidence standards.
- Identity standards & protocols — NIST SP 800-63 (IAL/AAL/FAL), Zero Trust (SP 800-207), SAML/OAuth 2.0/OIDC/SCIM.
- Outcome-based commercial design — RU/seat pricing, SLAs for access-request and certification turnaround, certification-linked pricing and service credits.
- Cross-domain evidence integration — mapping IAM controls into SOC 2 CC6 / ISO 27001 Annex A control libraries for combined audit narratives.