24 Sep
|
Hoffmann-La Roche
|
Pune
24 Sep
Hoffmann-La Roche
Pune
Job Summary
PBAC Operations Engineer - RDT Identity Access Management
Location: Pune
As part of Roche Digital Technology (RDT), our Identity and Access Management (IAM) team protects the organization's global digital assets by developing and operating sophisticated security platforms. We work at the forefront of identity governance, fine-grained authorization, and hybrid cloud security to support users and business-critical systems in a highly regulated global healthcare ecosystem.
As a PBAC Operations Engineer in the Identity and Access Management (IAM) space, you will be part of a global team responsible for the design, implementation, and lifecycle management of our Policy Based Access Control (PBAC) infrastructure. You will play a critical role in protecting our information and assets by moving beyond traditional access models toward a dynamic, fine-grained authorization framework that supports our global Zero Trust strategy. In this role, you will be the technical owner of the PBAC infrastructure, ensuring it is scalable, resilient, and deeply integrated into the Roche digital ecosystem.
The Opportunity
In this role, you will lead complex PBAC implementations and shape the future of dynamic authorization across our global enterprise. You will:
- Architect and maintain core PBAC components (PDP/PEP) across a hybrid global landscape to ensure high availability, resilience, and performance.
- Lead the transition from initial use cases to enterprise-wide adoption while defining organization-wide standards for policy-based authorization.
- Act as the primary technical consultant for application and data owners to seamlessly integrate systems via RESTful APIs, SQL/JDBC, and LDAP.
- Drive the shift to Policy as Code (PaC) by designing automated pipelines for versioning, testing, and deploying authorization logic like software.
- Own the tactical lifecycle of the platform, including version upgrades, security patching, continuous performance tuning,
and managing external Managed Service Providers (MSPs).
- Streamline onboarding processes for new assets, ensuring strict alignment with global security standards, ITIL change principles, and regulatory requirements such as GDPR.
- Bridge the gap between vendor capabilities and internal business requirements while navigating complex stakeholder networks across global cluster squads.
- Collaborate with product managers and developers to resolve unusually complex problems and create secure, user-friendly authorization flows.
Who you are
We are looking for an expert technical leader who combines deep IAM expertise with strong stakeholder alignment skills. To excel in this role, you bring:
- Experience: 5-9 years of experience in IT/Security, with 4+ years dedicated to IAM and specific expertise in PBAC/ABAC within large enterprise environments
- Education: A Bachelors degree in a technical field is required; a Masters degree or Ph.D. is preferred
- Technical Mastery: Advanced knowledge of XACML, Policy as Code (PaC), and decentralized policy management alongside standard IAM protocols (SAML, OAuth, OIDC, SSO, and IGA)
- Development DevOps: Proficiency in Java or Python for custom integrations, paired with hands-on experience using Git and CI/CD pipelines for secure code deployment
- Architectural Mindset: Solid advocacy for Zero Trust principles, prioritizing configurable off-the-shelf capabilities over custom builds for long-term maintainability
- Consulting Analysis: Proven ability to apply systems thinking to complex business problems, conducting root cause analysis, eliciting requirements, and advising senior leadership
- Communication Collaboration: Excellent English communication skills to explain complex concepts to non-technical stakeholders, mentor team members, and navigate dynamic cross-functional environments
Disclaimer: This job posting has been aggregated from external source. Role details, content, and availability are subject to change. Applicants are advised to confirm the latest information directly on the company website before applying.
📌 PBAC Operations Engineer - RDT Identity & Access Management (Pune)
🏢 Hoffmann-La Roche
📍 Pune