30 Sep
|
Teciem
|
Bengaluru
Join Teciem, a global fintech company delivering cutting-edge Treasury & Capital Markets software solutions to financial institutions worldwide.
We're looking for a talented IAM and PAM Security Lead who is passionate about building resilient, scalable, and high-performing systems. If you thrive in a fast-paced environment and enjoy solving complex infrastructure challenges, we'd love to hear from you.
Key Responsibilities
IAM Governance & Identity Security
- Define, maintain, and enforce IAM policies, standards, procedures, and security baselines.
- Ensure effective Joiner-Mover-Leaver (JML) processes are implemented and followed across all platforms.
- Review and approve role models, access profiles, RBAC structures, and entitlement frameworks.
- Monitor identity lifecycle activities to ensure timely provisioning, modification, and deprovisioning of accounts.
- Govern Microsoft Entra ID, Active Directory, and enterprise SaaS identity integrations from a security and compliance perspective.
- Review and monitor implementation of MFA, passwordless authentication, Conditional Access, Identity Protection, and risk-based authentication controls.
- Maintain an inventory of privileged, service, shared, and non-human accounts, ensuring ownership and accountability exist for all identities.
- Identify excessive permissions, toxic combinations, dormant accounts, orphan accounts, and access anomalies.
Privileged Access Management Governance
- Act as the Information Security SME for enterprise PAM initiatives.
- Define and maintain standards for privileged access, vaulting, credential management, session monitoring, and privileged account lifecycle management.
- Review and validate privileged access requests and ensure appropriate approvals and business justifications exist.
- Ensure privileged access follows least-privilege, just-in-time (JIT), and just-enough-access (JEA) principles.
- Govern emergency and break-glass account management processes.
- Review privileged account onboarding across servers, cloud environments, databases, applications, network devices, and client environments.
- Validate credential rotation policies and monitor adherence to privileged account management requirements.
- Review privileged session monitoring reports and identify unauthorized or risky privileged activities.
Access Reviews & Compliance
- Manage enterprise-wide User Access Review (UAR) and access recertification programs.
- Coordinate periodic privileged access reviews with business owners and application custodians.
- Validate Segregation of Duties (SoD) controls and identify conflicting access combinations.
- Track remediation of access-related audit findings and risk exceptions.
- Maintain evidence repositories supporting:
- ISO 27001
- SOC 2
- DORA
- NYDFS
- Client security audits
- Internal audits
- Develop and maintain IAM/PAM compliance dashboards and reporting metrics.
IAM & PAM Risk Management
- Perform identity-related risk assessments across cloud, infrastructure, applications, and managed services environments.
- Assess risks associated with privileged access, service accounts, shared accounts, and third-party access.
- Review access control design for new applications, systems, acquisitions, and cloud services.
- Identify gaps in identity security controls and drive remediation plans with IT and technology teams.
- Monitor identity threats including credential abuse, privilege escalation, excessive permissions, account compromise, and insider threats.
Security Monitoring & Incident Response
- Collaborate with SOC, SIEM, and incident response teams during identity-related security incidents.
- Support investigation of:
- Account compromise
- Privileged misuse
- Unauthorized access
- Credential theft
- Suspicious authentication activities
- Review identity and PAM logs to support forensic investigations and audit requests.
- Coordinate rapid access revocation activities during security incidents.
Preferred Skills
- Experience with Identity Governance & Administration (IGA) platforms such as SailPoint, Saviynt, Omada, or Microsoft Identity Governance.
- Understanding of cloud IAM across Azure, AWS, and GCP.
- Familiarity with Cyber Security controls, Zero Trust Architecture, and Identity Threat Detection & Response (ITDR).
- Experience within banking, financial services, fintech, treasury, capital markets, or managed services environments.
- Knowledge of service account governance and secrets management solutions such as CyberArk Conjur, HashiCorp Vault, or Azure Key Vault.
- Scripting knowledge in PowerShell, Python, or API integrations is advantageous.
Essential skills and experience
- 8+ years in information security or infrastructure, with at least 5 years hands-on in IAM and PAM administration.
- Demonstrable administration experience with Microsoft Entra ID (Azure AD) and Active Directory, including conditional access, PIM, group and entitlement management.
- Hands-on administration of at least one enterprise PAM platform — CyberArk, Delinea, BeyondTrust, One Identity or equivalent — covering vaulting, rotation, session management and account onboarding.
- Practical understanding of authentication and federation protocols: SAML 2.0, OAuth 2.0, OIDC, Kerberos, LDAP, SCIM.
- Experience administering privileged access across mixed Windows and Linux estates, databases and cloud platforms.
- Scripting and automation capability in PowerShell and/or Python, including REST API integration.
- Experience operating access controls in a regulated workplace and producing evidence for external audit.
Qualifications and certifications
- Bachelor's degree in computer science, information systems, engineering or related discipline, or equivalent practical experience.
- One or more of the following is valued: CyberArk Defender/Sentry, Delinea or BeyondTrust certification, Microsoft SC-300 (Identity and Access Administrator), Microsoft SC-200, CISSP, CISM, or CIAM/IDPro credentials.
📌 IAM and PAM Security Lead (Bengaluru)
🏢 Teciem
📍 Bengaluru