23 Sep
|
HCLTech
|
Chennai
SME - Identity And Access Management, Service-Oriented Architecture
Chennai, Tamil Nadu
Job Summary
The L3 IAM Engineer is responsible for designing, implementing, and maintaining Identity and Access Management solutions that ensure secure, compliant, and efficient access to enterprise systems and applications. This role operates with a high degree of independence, handling complex access provisioning, authentication, and authorization challenges, while contributing to process improvements, automation initiatives, and IAM governance frameworks. The L3 skilled serves as a technical escalation point for L1/L2 team members and collaborates closely with security, infrastructure, and application teams to align IAM practices with organizational risk and compliance requirements.
Key Responsibilities
Design, configure, and maintain IAM solutions including identity lifecycle management, single sign-on (SSO), multi-factor authentication (MFA), privileged access management (PAM), and role-based access control (RBAC). Manage end-to-end user provisioning/de-provisioning processes across on-premises and cloud environments (Active Directory, Azure AD/Entra ID, LDAP, SaaS applications). Serve as an escalation point for complex access issues, troubleshooting authentication/authorization failures across integrated systems. Perform periodic access reviews, certifications, and audits to ensure compliance with internal policies and external regulations (e.g., SOX, GDPR, ISO 27001). Develop and maintain IAM automation scripts/workflows (e.g., using PowerShell, Python, or IAM platform APIs) to streamline provisioning,
deprovisioning, and access certification processes. Support integration of IAM tools with enterprise applications via SAML, OAuth, OpenID Connect, and SCIM protocols. Collaborate with security teams to define and enforce access control policies, least-privilege principles, and segregation-of-duties (SoD) rules. Participate in IAM tool upgrades, patching, and vendor coordination (e.g., SailPoint, CyberArk, Okta, Ping Identity, Microsoft Entra). Document IAM processes, standard operating procedures (SOPs), and knowledge base articles. Mentor and provide guidance to L1/L2 IAM analysts on technical issues and best practices. Contribute to incident response efforts related to identity compromise, unauthorized access, or credential misuse. Support internal and external audit requests by providing evidence of access controls and remediation activities.
Skill Requirements
Strong hands-on experience with IAM platforms (e.g., SailPoint IdentityIQ/IdentityNow, CyberArk, Okta, Ping Identity, Microsoft Entra ID/Azure AD, IBM Security Identity Manager). Solid understanding of authentication/authorization protocols: SAML, OAuth 2.0, OpenID Connect, SCIM, Kerberos, LDAP. Experience with Active Directory administration, group policies, and directory services. Familiarity with Privileged Access Management (PAM) tools and concepts. Scripting/automation skills (PowerShell, Python, or similar) for workflow automation. Knowledge of cloud IAM concepts across AWS IAM, Azure AD, or GCP IAM. Understanding of RBAC, ABAC, and least-privilege access models.
Other Requirements
📌 SME - Identity And Access Management, Service-Oriented Architecture (Chennai)
🏢 HCLTech
📍 Chennai