•
Proposed designation:
IAM Consultant
•
Role type:
Permanent
•
Reporting to: Associate Director
•
Geo to be supported:
KDN
•
Work timings:
Flexible
•
Design and implement scalable IAM solutions aligned with client business,
security, and compliance needs.
•
Act as a hands‑on technical lead for IGA (and PAM) implementations,
contributing to solution design and delivery execution.
•
Provide technical guidance and day‑to‑day mentoring to project team
members during delivery.
•
Engage stakeholders in a consulting and advisory role, including
workshops, requirement discovery, and solution walkthroughs.
•
Deliver solutions for identity lifecycle management, role engineering,
access certifications, and SoD, including integrations with PAM, SIEM,
ITDR, and adjacent platforms.
•
Apply strong understanding of authentication and federation protocols
(SAML, OAuth, OIDC, Kerberos) to support IGA and access integrations.
•
Demonstrate working knowledge of Privileged Access Management, including
privileged identity lifecycle and governance.
•
Support clients in defining IAM and PAM governance processes and baseline
identity standards.
•
Contribute to the definition and maintenance of IAM security policies and
technical standards aligned with best practices.
•
Provide practical recommendations to address process gaps, emerging
threats, and regulatory requirements.
•
Develop or enhance accelerators, templates, and reusable assets to improve
delivery efficiency.
Ensure delivered solutions meet audit, compliance, and security
requirements across applicable regions
Educational qualifications
·
Minimum Bachelor's degree in Computer Science, Information Technology or
MCA.
Work experience
·5
+ years of experience in Identity Governance and Administration &
Privileged Identity & Access Management
·
Need strong Java development experience.
·
Primary skills in Saviynt or SailPoint for Identity Governance and
Administration implementations & CyberArk for PAM.
·
5+ years of experience in at least one of IGA tools of SailPoint, Saviynt,
ForgeRock etc., and a hands-on experience on CyberArk or another PAM tool.
·
Deep understanding of digital identity concepts, identity lifecycle
management, governance, provisioning workflows, SoD, and cloud access
governance.
·
Intimately familiar with authentication and authorization protocols such
as SAML, SPML, XACML, SCIM, OpenID and OAuth.
·
Must hold advanced certifications such as SailPoint Engineer, Saviynt
Engineer, and other IAM-related certifications (e.g., CISSP, CISM, or
equivalent). CyberArk CDE certifications will be a bonus.
Key behavioral attributes/requirements
·
Hands‑on IAM/PAM engineering with contribution to COE assets and shared
frameworks.
·
Experience working in offshore/onshore delivery models.
·
Strong expertise in directories, SSO, federation, delegated admin, and
API integrations.
·
Practical understanding of cloud identity architectures (IaaS, PaaS,
SaaS).Working knowledge of scripting and automation (PowerShell,
JavaScript).Understanding of security, compliance, and regulatory
requirements.
·
Effective collaboration with business and technical teams.
·
Ability to work independently with minimal supervision.
·
Clear technical communication and documentation skills.
•
Interview process:
3
•
Does the job role involve travelling:
No
•
Does the busy season apply to this role?:
No