16 Sep
|
Kornferry
|
Navi Mumbai
16 Sep
Kornferry
Navi Mumbai
JOB OVERVIEW The Sr. Information Security Operations Engineer is responsible for owning and operating the enterprise Okta platform and supporting broader Identity and Access Management capabilities across a global workplace.
This role is approximately 80% focused on IAM platform ownership, with primary responsibility for Okta, Microsoft Entra ID integrations, AWS IAM, IAM governance, privileged access, application access, identity lifecycle management, and non-human identity security.
The remaining 20% supports incident response activities, with emphasis on identity-related alert triage, account compromise investigations, unauthorized access, privilege misuse, cloud IAM misuse, and containment support.
This position serves as the technical owner and escalation lead for Okta and key IAM services, ensuring secure, compliant, and resilient access to enterprise systems, cloud platforms, applications, and data.
ESSENTIAL DUTIES AND RESPONSIBILITIES
- Own and administer the enterprise Okta platform, including configuration, operations, governance, standards, support, and continuous improvement.
- Serve as the technical lead and escalation point for Okta, IAM platform issues, application access issues, integrations, outages, and platform changes.
- Administer Okta capabilities including Universal Directory, SSO, MFA, Lifecycle Management, group rules, profile mappings, authentication policies, application assignments, and admin roles.
- Design, configure, and troubleshoot Okta application integrations using SAML, OIDC, OAuth 2.0, SCIM, SWA, APIs, and Okta agents.
- Lead onboarding, migration, testing, deployment, and ongoing support of enterprise applications integrated with Okta.
- Maintain and troubleshoot identity flows between authoritative sources, Okta, Microsoft Entra ID, AWS IAM, IAM tools, and downstream applications.
- Administer Microsoft Entra ID identity controls related to enterprise applications, authentication, conditional access, groups, and identity security.
- Administer AWS IAM capabilities including users, roles, policies, permissions, federation,
access keys, and identity-related logging.
- Support identity lifecycle processes for employees, contractors, vendors, privileged users, and other user populations.
- Support IAM governance processes including access reviews, entitlement reviews, role reviews, certifications, access exceptions, audit evidence, and compliance reporting.
- Lead non-human identity security efforts for service accounts, automation accounts, application identities, API accounts, cloud roles, certificates, secrets, and access keys.
- Identify and reduce identity risks related to excessive permissions, stale access, orphaned accounts, inactive accounts, privileged access, and long-lived credentials.
- Support privileged access processes including approvals, emergency access, credential rotation, privileged access reviews, and audit evidence.
- Monitor, triage, and investigate identity-related security alerts from Okta, Entra ID, AWS IAM, IAM tools, privileged access tools, SIEM, and related platforms.
- Support containment and remediation for identity-related incidents, including suspicious logins, account compromise, privilege misuse, cloud IAM misuse, and unauthorized access.
- Partner with Security Operations, Cloud, Infrastructure, HR, Application, and business teams to resolve identity and access issues.
- Develop and maintain IAM SOPs, runbooks, diagrams, application records, control documentation, and troubleshooting guides.
- Recommend improvements to strengthen identity security, reduce manual access work, and improve IAM operations.
- Participate in rotational on-call or escalation support as needed for IAM and identity-related security incidents.
- Perform other duties as assigned.
TECHNICAL COMPETENCIES (Knowledge, Skills & Abilities)
- Expert hands-on experience owning and administering Okta in an enterprise environment.
- Strong experience with Okta SSO, MFA, Lifecycle Management, Universal Directory, application integrations, group rules, profile mappings, and authentication policies.
- Strong experience with IAM integration standards and protocols, including SAML, OIDC, OAuth 2.0, SCIM, SWA, APIs, and identity agents.
- Strong understanding of IAM governance, including least privilege, role-based access, access reviews, certifications, entitlement management, and segregation of duties.
- Working knowledge of Microsoft Entra ID and AWS IAM identity controls, including enterprise applications, conditional access, federation, roles, policies, and access keys.
- Strong understanding of non-human identity security, including service accounts, automation accounts, API credentials, certificates, secrets, cloud roles, and long-lived credentials.
- Experience with privileged access tools and processes, including approvals, credential rotation, emergency access, privileged access reviews, and audit evidence.
- Ability to troubleshoot complex identity and access issues across Okta, Entra ID, AWS IAM, SaaS applications, cloud platforms, and IAM tools.
- Experience supporting identity-related investigations, including suspicious authentication activity, account compromise, unauthorized access, and privilege misuse.
- Strong documentation, communication, stakeholder management, analytical, and problem-solving skills.
EDUCATION AND EXPERIENCE Associates or Bachelors Degree in Computer Science, or equivalent experience in related field, and 5+ years of related experience. Bachelors degree preferred.
Certifications:
Required
- Okta Certified Administrator
Preferred:
- Okta Certified Consultant
- Okta Certified Technical Architect
- AWS, Microsoft, or cloud security certification
- CISSP, CISM, Security+, or equivalent certification
📌 Sr. Information Security Operations Engineer (Navi Mumbai)
🏢 Kornferry
📍 Navi Mumbai