02 Oct
|
Orcapod Consulting Services
|
Hyderabad
02 Oct
Orcapod Consulting Services
Hyderabad
Role & responsibilities
Non-Human Identity (NHI) Specialist
We are seeking a Non-Human Identity (NHI) Specialist to design and implement up-to-date identity security controls for machines, services, applications, and AI agents. This role blends traditional Privileged Access Management (PAM) expertise with modern cloud-native and workload identity security, ensuring secrets, certificates, and non-human credentials are governed with the same rigor as human identities.
Responsibilities
- Design, implement, and manage secrets management solutions (e.g., CyberArk Conjur, HashiCorp Vault, Azure Key Vault, AWS Secrets Manager) including secret rotation, dynamic secrets, and vaulting policies
- Architect and enforce least-privilege IAM/PAM policies, roles, and entitlements for service accounts, applications, and automation identities
- Implement Just-In-Time (JIT), and ephemeral credential models to eliminate persistent privileged access for non-human identities
- Manage Certificate/PKI lifecycle (issuance, rotation, revocation) for machine and workload identities
- Configure and govern Cloud IAM across AWS, Azure, and GCP, including IAM roles and cross-account access (AWS), service principals and managed identities (Azure), and service accounts with workload identity federation (GCP)
- Implement OAuth 2.0, OpenID Connect, and JWT-based authentication/authorization flows for service-to-service and API access
- Design and deploy Workload Identity solutions (e.g., SPIFFE/SPIRE, Kubernetes service accounts, cloud workload identity federation) to eliminate long-lived credentials
- Establish access control frameworks and guardrails for AI agents and autonomous systems, including scoped permissions, audit trails, and behavioral monitoring
- Establish continuous discovery of non-human identities (service accounts, API keys, tokens, certificates, secrets) through automated tooling or repeatable processes across cloud, on-prem, CI/CD, and SaaS environments
- Build, analyze and maintain NHI inventory, risk scoring, and remediation programs to identify and eliminate orphaned, over-privileged, or stale non-human credentials
- Onboard and integrate platforms (cloud, on-prem, containers, databases) into NHI/PAM governance frameworks
- Develop automation using PowerShell, Python, Terraform, and REST APIs for identity provisioning, rotation, and compliance reporting
- Support integrations with SIEM, MFA, CI/CD pipelines, and secret scanning tools
- Conduct risk assessments and drive remediation of non-human identity findings across the enterprise
- Document architecture, standards, and runbooks; collaborate with security, platform, and application teams
Required Qualifications
- Bachelor's or Master's degree in Computer Science, Information Security, or related field
- Hands-on experience with secrets management platforms (CyberArk Conjur, HashiCorp Vault,
or cloud-native equivalents)
- Experience with IAM/PAM concepts including roles, policies, entitlements, and least-privilege enforcement
- Practical experience implementing Just-In-Time access, and ephemeral credential/session models
- Proficiency building NHI remediation and governance programs, including inventory, risk scoring, and lifecycle management of non-human identities
- Working knowledge of PKI/certificate lifecycle management
- Practical experience with Cloud IAM across at least one major provider (AWS, Azure, or GCP)
- Solid understanding of OAuth 2.0, OpenID Connect, and JWT token-based authentication
- Familiarity with workload identity concepts (SPIFFE/SPIRE, managed identities, federated identity)
- Proficiency in PowerShell, Python, or API/SDK-based automation
- Strong communication, documentation, and cross-team collaboration skills
Preferred Qualifications
- Experience securing AI agent/agentic workflows, including scoped credential issuance and runtime access control
- Certifications: CyberArk CDE, AWS/Azure Security certifications, HashiCorp Vault Associate
- Experience with Kubernetes secrets, service mesh identity (Istio/Linkerd), or SPIFFE/SPIRE
- Background in DevSecOps, CI/CD pipeline security, or secret scanning tooling
- Experience deploying or operating NHI discovery tooling (Token, Astrix, Oasis, Clutch etc. ) to continuously identify and inventory non-human identities across environments
Work Model : Hybrid model.
Exp range : 3 to 8 years
Shift Timing : 1 PM IST to 10 PM IST
📌 Non Human Identity (NHI) SpecialistH (Hyderabad)
🏢 Orcapod Consulting Services
📍 Hyderabad