We are seeking an experienced IAM Operations Associate to join our Access Management team. In this role, you will be responsible for processing access requests across Active Directory, UNIX, database, Cyberark and other directory systems while troubleshooting access-related issues within defined SLAs. You will support and administer IAM and PAM to ensure that applications and platforms across the enterprise adhere to corporate patterns and IAM security standards.
This position combines hands-on operational support with a governance mindset. You will help define access models, manage account lifecycles, operationalize provisioning and authentication tasks, and develop reporting to keep our access methods aligned with auditing and regulatory controls. Success in this role requires strong technical depth in AD, Cyberark and/or UNIX/Linux security with a solid grounding in IAM principles and the ability to collaborate effectively with application and platform owners.
Key Responsibilities
- Process access requests and incidents from a queue-based system spanning a broad range of IT systems, meeting or exceeding defined SLAs.
- Provide operational support for IAM processes using tools such as Active Directory Users and Computers, CyberArk, Sudo, BoKS, and SQL Studio.
- Support and process requests for the CyberArk privileged access management solution.
- Manage the full user lifecycle (Joiners, Movers, Leavers) across the enterprise.
- Define access models, support patterns, and account lifecycle management, and operationalize tasks related to provisioning, authentication, and authorization.
- Develop reporting and metrics to measure service performance, identify trends, and surface potential risks.
- Analyze queue metrics to identify improvement opportunities and refine processes.
- Define requirements and data flows to automate operationalized tasks.
- Assist with onboarding new applications and platforms to centralize IAM services, including developing new access models.
- Establish governance and produce reports that keep platform access methods compliant with auditing and regulatory controls.
- Coordinate with application and platform owners to ensure security controls are correctly understood and implemented.
- Lead workshops and discovery activities to fully capture security requirements.
- Escalate out-of-normal-process issues to SMEs and management as appropriate.
- Prepare and maintain IAM documentation, SOPs, and process workflows, including ServiceNow form enhancements.
- Track and document projects using tools such as Jira and MS Teams.
- Perform on-call duties as part of a 24-hour support model.
Educational Requirements
- University (Degree) Preferred
Work Experience
- 3+ Years Required; 5+ Years Preferred
Physical Requirements
- Physical Requirements: Sedentary Work
Career Level 7IC
About the Role
We are seeking an experienced IAM Operations Associate to join our Access Management team. In this role, you will be responsible for processing access requests across Active Directory, UNIX, database, Cyberark and other directory systems while troubleshooting access-related issues within defined SLAs. You will support and administer IAM and PAM to ensure that applications and platforms across the enterprise adhere to corporate patterns and IAM security standards.
This position combines hands-on operational support with a governance mindset. You will help define access models, manage account lifecycles, operationalize provisioning and authentication tasks,
and develop reporting to keep our access methods aligned with auditing and regulatory controls. Success in this role requires strong technical depth in AD, Cyberark and/or UNIX/Linux security with a solid grounding in IAM principles and the ability to collaborate effectively with application and platform owners.
Key Responsibilities
- Process access requests and incidents from a queue-based system spanning a broad range of IT systems, meeting or exceeding defined SLAs.
- Provide operational support for IAM processes using tools such as Active Directory Users and Computers, CyberArk, Sudo, BoKS, and SQL Studio.
- Support and process requests for the CyberArk privileged access management solution.
- Manage the full user lifecycle (Joiners, Movers, Leavers) across the enterprise.
- Define access models, support patterns, and account lifecycle management, and operationalize tasks related to provisioning, authentication, and authorization.
- Develop reporting and metrics to measure service performance, identify trends, and surface potential risks.
- Analyze queue metrics to identify improvement opportunities and refine processes.
- Define requirements and data flows to automate operationalized tasks.
- Assist with onboarding new applications and platforms to centralize IAM services, including developing new access models.
- Establish governance and produce reports that keep platform access methods compliant with auditing and regulatory controls.
- Coordinate with application and platform owners to ensure security controls are correctly understood and implemented.
- Lead workshops and discovery activities to fully capture security requirements.
- Escalate out-of-normal-process issues to SMEs and management as appropriate.
- Prepare and maintain IAM documentation, SOPs, and process workflows, including ServiceNow form enhancements.
- Track and document projects using tools such as Jira and MS Teams.
- Perform on-call duties as part of a 24-hour support model.
Required Qualifications
- Experience with Active Directory user and group administration.
- Working knowledge of IAM domains including Identity Management, Access Management, Directory Management, Single Sign-On, Federation, and Role-Based Access.
- Experience with identity management solutions such as SailPoint, OIM, or ForgeRock.
- Working knowledge of BoKS, Likewise, Cloud Secrets Manager, or similar products.
- Demonstrable PAM UNIX experience covering Sudoers, jump hosts, UNIX hosts/groups, internals, login keys, and system administration with proficiency in UNIX text editors such as VI and Notepad++.
- Solid understanding of information security and access management best practices, including RBAC, the principle of least privilege, and privileged access management for elevated access on both interactive and non-interactive IDs.
- Proficiency with version control systems such as Git and CVS.
- Experience with ticketing tools such as ServiceNow and Jira.
- Good working knowledge of the Microsoft Office suite (Word, Excel, Outlook, OneNote, SharePoint).
Key Competencies
- Strong written and verbal communication skills.
- Strong interpersonal and client management skills, with the ability to work effectively as part of a global team.
- Strong organizational skills, with the ability to manage multiple concurrent project deliverables.
- Strong analytical and problem-solving skills.
- Self-motivated, with the ability to work on their own initiative in a fast-paced environment.
- An excellent team player who can also work independently.
- Flexibility to work rotating shifts and support on-call duties.
Related SkillsAccountability, Adaptability, Business Continuity Planning, Cloud Computing Security, Collaboration, Communication, Compliance, Consultative Communication, Cybersecurity, Detail-Oriented, General Risk Management, Network Security, Prioritizes Effectively _____________________________________________________________________________________________________
Company Overview
TIAA Global Capabilities was established in 2016 with a mission to tap into a vast pool of talent, reduce risk by insourcing key platforms and processes, as well as contribute to innovation with a focus on enhancing our technology stack. TIAA Global Capabilities is focused on building a scalable and sustainable organization , with a focus on technology , operations and expanding into the shared services business space.
Working closely with our U.S. colleagues and other partners, our goal is to reduce risk, improve the efficiency of our technology and processes and develop innovative ideas to increase throughput and productivity.
We are an Equal Opportunity Employer. TIAA does not discriminate against any candidate or employee on the basis of age, race, color, national origin, sex, religion, veteran status, disability, sexual orientation, gender identity, or any other legally protected status.
Our Culture of Impact
At TIAA, we're on a mission to build on our 100+ year legacy of delivering for our clients while evolving to meet tomorrow's challenges. We equip our associates with future-focused skills and AI tools that enable us to advance our mission. Together, we are fighting to ensure a more secure financial future for all and for generations to come.
We are guided by our values: Champion Our People, Be Client Obsessed, Lead with Integrity, Own It, and Win As One. They influence every decision we make and how we work together to serve our clients every day. We thrive in a cooperative in-office environment where teams work across organizational boundaries with shared purpose, accelerating innovation and delivering meaningful results.
Our workplace brings together TIAA and Nuveen's entrepreneurial spirit, where we work hard and work together to create lasting impact. Here, every associate can grow through meaningful learning experiences and development pathways—because when our people succeed, our impact on clients' lives grows stronger.
Accessibility Support
TIAA offers support for those who need assistance with our online application process to provide an equal employment opportunity to all job seekers, including individuals with disabilities.
If you are a U.S. applicant and desire a reasonable accommodation to complete a job application please use one of the below options to contact our accessibility support team:
Phone: (800) 842-2755
Email:
[email protected]
Privacy Notices For Applicants of TIAA, Nuveen and Affiliates residing in US (other than California), click here.
For Applicants of TIAA, Nuveen and Affiliates residing in California, please click here.
For Applicants of TIAA Global Capabilities, click here.
For Applicants of Nuveen residing in Europe and APAC, please click here.
📌 Associate - Specialist - IT Service Management (Pune)
🏢 Tiaa External Schroder Internal
📍 Pune