30 Sep
|
HCLTech
|
Bengaluru
SME - IAM Operations
Bengaluru, Karnataka
Job Summary
Location: IBM India, Pune/Bangalore/Hyderabad/NCR Role Type: Permanent Department: Cybersecurity Experience Level: 5–8 years | Proficiency Level: Experienced Role Overview: The IAM Operations Practitioner will support the day-to-day operation, administration, monitoring, and continual improvement of the Cyber Privileged Access Management (CPAM) service using HashiCorp Vault. The practitioner will manage privileged identities, secrets, authentication methods, policies, tokens, namespaces, and onboarding activities while ensuring secure, reliable, and audit-ready service delivery. The role requires strong operational ownership, structured troubleshooting, adherence to ITSM processes, and close collaboration with application, infrastructure, cloud, security, and service-management teams.
Key Responsibilities: • Operate and administer HashiCorp Vault environments supporting enterprise CPAM and secrets-management services. • Handle incidents, service requests, problems, and changes in accordance with agreed SLAs, operational procedures, and change controls. • Onboard applications, platforms, service accounts, and machine identities to Vault using approved authentication methods and secrets engines. • Configure and maintain Vault policies, roles, identity entities/groups, tokens, leases, namespaces, and access-control mappings based on least-privilege principles. • Support static and dynamic secrets, credential issuance, revocation, renewal, and rotation processes. • Monitor Vault availability, health, capacity, audit logs, replication status, and operational alerts; perform first-level analysis and coordinate recovery actions. • Troubleshoot authentication, authorization, policy, token, lease, API, certificate, connectivity, and application-integration issues. • Support high-availability, backup, restore, disaster-recovery, seal/unseal, rekey, and controlled failover activities under approved procedures. • Perform privileged access reviews, emergency-access validation,
evidence collection, and remediation of policy or credential exceptions. • Prepare root-cause analysis for recurring or major incidents and implement preventive actions to reduce repeat failures. • Maintain runbooks, SOPs, knowledge articles, troubleshooting guides, configuration records, and audit evidence. • Identify opportunities for automation, monitoring enhancement, operational simplification, and reduction of manual privileged-access activities. • Participate in shift handovers, service reviews, backlog reviews, audit support, and stakeholder communications. • Provide technical guidance and knowledge transfer to junior practitioners and collaborate effectively across distributed teams.
Required Skills and Qualifications: • 5–8 years of overall experience in IAM, PAM/CPAM, cybersecurity operations, platform operations, or secrets management, including hands-on HashiCorp Vault experience. • Practical knowledge of Vault architecture, storage concepts, high availability, seal/unseal, namespaces, audit devices, replication, and disaster-recovery concepts. • Hands-on experience with Vault authentication methods such as AppRole, LDAP, OIDC, Kubernetes, cloud-based authentication, or equivalent enterprise patterns. • Experience configuring Vault ACL policies, identity entities/groups, token lifecycle, leases, and least-privilege access controls. • Working knowledge of secrets engines such as KV, database, PKI, transit, SSH, cloud, or other applicable engines. • Ability to use Vault UI, CLI, REST API, and configuration files for administration and troubleshooting. • Experience in application and workload onboarding,
secret-path design, credential rotation, and integration troubleshooting. • Robust Linux/Unix administration skills and working knowledge of networking, TLS, certificates, DNS, load balancers, and firewalls. • Working knowledge of scripting or automation using Python, Shell, PowerShell, JSON, YAML, Terraform, Ansible, or equiva
Key Responsibilities
- Familiarity with monitoring and logging platforms and the ability to analyse Vault audit and operational logs.
- Good understanding of IAM/PAM principles, privileged-account lifecycle, machine identities, RBAC, least privilege, segregation of duties, and emergency access.
- Experience working with ITSM processes including incident, request, problem, change, knowledge, and service-level management.
- Strong troubleshooting, analytical, documentation, and stakeholder-communication skills.
Preferred Qualifications:
- HashiCorp Certified: Vault Associate or Vault Operations Professional certification.
- Experience operating Vault Enterprise in production and supporting performance or disaster-recovery replication.
- Exposure to Kubernetes/OpenShift and public-cloud environments such as AWS, Azure, or Google Cloud.
- Understanding of HSM, KMS, PKI, certificate lifecycle, encryption, and regulatory control requirements.
- Experience with enterprise monitoring, SIEM, observability, and automation platforms.
- Experience supporting 24x7 managed services or globally distributed operations.
Soft Skills:
- Strong ownership and disciplined follow-through in an operations environment.
- Clear written and verbal communication with technical and non-technical stakeholders.
- Collaborative and proactive approach to incident resolution and service improvement.
- Ability to prioritise multiple operational demands and work effectively under pressure.
- Attention to detail, security awareness, and commitment to accurate audit evidence and documentation.
Skill Requirements
Other Requirements
📌 SME - IAM Operations (Bengaluru)
🏢 HCLTech
📍 Bengaluru