24 Sep
|
Network Dot Com
|
India
24 Sep
Network Dot Com
India
Job Title: Security Engineer - IAM Platform
Exp: 8+ year.
Remote The role is the identity and access management platform for the Software portfolio.
As Security Engineer, you are the right hand of the Platform Architect on every security specific topic across the platform, and the person who makes sure the rest of builds on top of it securely. The role has two sides. In the first phase, you work deep inside the architecture and the software development lifecycle of itself: securing the identity core, the authorization layers, and the pipelines that build and deploy them. As the platform matures and other product teams connect to it,
your focus shifts toward supporting those teams: helping them implement security correctly against the IAM architecture, the platform's guidelines, and our security policies, and acting as the person other teams turn to when they need to get security right. This is a hands-on role. You build tooling and produce evidence yourself. It is also a teaching role. Part of your job is making sure other engineering teams understand and adopt the security approach,
not just following it because you told them to. You report to the Global
Produce Security Manager and work closely with the Platform Architect and the
Product Security function. What you will do During the platform build phase,
close to the Platform Architect: ·
Own and run static and agile security testing tools in the continuous integration pipeline, and decide when a finding should block a release. · Review the architecture and implementation of the identity, authorization, and token layers for security gaps, working directly alongside the Platform Architect. · Run threat modeling and risk assessments on platform components, with particular attention to how tokens are issued and revoked and how services authenticate to each other. · Build the security tooling, automation, and secure defaults that later get handed to consuming teams as self-service capability. ·
Produce compliance evidence for security certifications directly, as a personal deliverable, not a coordination task. As other product teams connect to:
· Act as the main point of contact for product teams implementing security against the platform's IAM architecture, guidelines, and the policies set by the security officer. · Evangelize secure implementation practices across teams: run sessions, write practical guidance,
and review designs before they ship, rather than only auditing after the fact. · Support incident response when a security event touches the identity platform or a connected product. · Test authentication and authorization integrations for common vulnerability patterns, including token handling issues and unsafe redirect behavior. ·
Work with product teams to fix findings from security audits, and help them build the secure coding habits that prevent the same finding from recurring.
Technical skills we are looking for ·
Strong infrastructure and cloud security background (IaaS), including cloud security architecture, network segmentation, secure landing zones, and Zero
Trust design principles. This is a core requirement, not a secondary one. · Hands-on ownership of static and dynamic application security testing tools inside a CI/CD pipeline.
You should be able to describe pipelines you personally built or ran, and how you decided when to block a release. ·
Strong application security background: secure code review, vulnerability assessment, and working directly with engineers to fix what you find. · IAM and PAM architecture knowledge: single sign-on, multi-factor authentication, role based access control, and privileged access management, well enough to guide other teams'
implementation decisions, not just review them. ·
Direct experience producing compliance evidence for security certifications such as SOC 2 or ISO 27001,
ideally evidence that went to an external auditor. · Strong Azure security experience, including Microsoft Entra ID, Key Vault, Defender, Sentinel, and managed identity patterns. ·
Working knowledge of OAuth 2.0 and OpenID Connect from an attacker's perspective: the common implementation mistakes and how you test for them.
Skills that strengthen your application ·
Experience across multiple cloud providers, not only Azure, since you will be advising product teams that do not all run on the same stack. · Experience with security testing and vulnerability management practices, manual and automated. · Enough scripting or automation ability to extend or build your own security tooling rather than relying only on vendor products. ·
Familiarity with product security regulations for connected software, and what secure by-default and vulnerability disclosure obligations mean in practice. · Experience running training, workshops, or internal guild sessions to spread a security practice across teams that do not report to you. Who succeeds in this role · You build things and ship them. You are not satisfied with recommending a fix; you want to own it through to done. · You can teach a security concept to a team that does not have your background, and get them to adopt it because they understand it, not because you insisted. · You can hold a firm line on a security standard while staying constructive when a product team pushes back. · You communicate risk clearly to engineers and to non-technical stakeholders, without exaggerating or minimizing it. · You are comfortable operating close to architecture early on, then shifting toward cross team enablement as the platform matures, without needing the role redefined for you each time. · You take ownership of compliance evidence as a personal deliverable, with the same rigor you would apply to production code. ·
You are comfortable using AI tools to support security analysis and automation,
and you know how to check their output rather than trust it blindly.
📌 Security engineer IAM plateform (India)
🏢 Network Dot Com
📍 India