Source description
About the role
Identity & Access Management (IAM) Security Lead Location: Mumbai Reporting To: CISO Role Overview Accountable for defining, designing, and securing the enterprise Identity & Access Management (IAM) landscape across on-premises, hybrid, and cloud environments. Serve as the technical authority for identity security across the organization. Drive Zero Trust adoption, modern authentication, privileged access controls, and AI-driven automation to reduce security risks and operational overhead. Key Responsibilities IAM Strategy & Architecture Own the enterprise IAM architecture and roadmap aligned with Zero Trust and cloud-first strategies. Design scalable IAM solutions across:Active Directory (AD) Microsoft Entra ID (Azure AD) Hybrid environments Cloud platforms Act as the IAM Subject Matter Expert (SME) for security, infrastructure, and application teams. Identity Platforms & Access Controls Lead implementation, administration, and governance of:Microsoft Entra ID / Azure AD Conditional Access Policies Single Sign-On (SSO) Federation Services Implement strong authentication mechanisms including:Multi-Factor Authentication (MFA) Phishing-resistant MFA FIDO2 Security Keys Hardware Tokens Certificate-based Authentication Drive passwordless authentication initiatives:Windows Hello for Business FIDO2 Passkeys Manage enterprise identity providers and access policies. Protocols & Integration Standards Design and govern application integrations using:OAuth 2.0 OpenID Connect (OIDC) SAML 2.0 JWT SCIM Ensure secure and standardized authentication and authorization patterns across the enterprise. Identity Governance & Privileged Access Management Provide leadership and expertise in:Identity Governance & Administration (IGA) Access Management (AM) Privileged Access Management (PAM) Role-Based Access Control (RBAC) Implement and manage PIM/PAM solutions using:Just-In-Time (JIT) Access Least Privilege Principles Automate:Joiner-Mover-Leaver (JML) processes Access Reviews and Certifications User Provisioning and Deprovisioning Active Directory & Hybrid Identity Own Active Directory security, governance, modernization, and lifecycle management. Secure hybrid identity integrations supporting both legacy and modern applications. Define and enforce Active Directory Management (ADMgmt) standards, controls, and best practices. Identity Threat Detection & AI-Led Automation Implement Identity Threat Detection and Response (ITDR) capabilities. Leverage AI/ML-powered automation to:Detect anomalous identity behavior Identify access risks Automate access decisions Automate certifications and policy enforcement Reduce manual IAM operations Improve response and remediation times Integrate identity telemetry with:SIEM platforms SOAR platforms Security monitoring solutions Governance & Leadership Ensure IAM controls meet:Regulatory requirements Compliance standards Audit expectations Enterprise risk management requirements Develop and present executive-level IAM metrics and dashboards covering:Identity risk posture Access governance Privileged access controls Automation effectiveness Mentor IAM engineers and provide technical leadership. Influence cross-functional security and identity initiatives. Required Experience & Expertise 12+ years of IT and Cybersecurity experience with deep specialization in IAM. Proven experience designing and implementing IAM solutions for large enterprises across:On-Premises environments Hybrid environments Cloud environments Expert-level knowledge of:Identity Governance & Administration (IGA) Access Management (AM) Privileged Access Management (PAM) Active Directory Management (ADMgmt) Strong understanding of:Modern authentication frameworks Federation technologies Identity-centric security threats Zero Trust principles Hands-on experience with:Microsoft Entra ID (Azure AD) Active Directory SSO MFA Conditional Access OAuth 2.0 OIDC SAML 2.0 JWT .