Avantor Logo

Avantor

Senior Systems Engineer - IAM Services

Posted 6 Days Ago
Be an Early Applicant
In-Office
2 Locations
Senior level
In-Office
2 Locations
Senior level
The Senior IAM Engineer leads IAM system implementation, ensuring security and compliance. Responsibilities include managing identity systems and automation processes, collaborating across teams, and providing global support for IAM tools.
The summary above was generated by AI
The Opportunity:
Under limited supervision, responsible for the operations of secure and highly available computing platforms, servers, and networks. Install, maintain, upgrade, and continuously improve the company’s operating environment. Maintain the ongoing reliability, performance and support of the infrastructure. Deploy the release of new technologies as well as design, install, configure, maintain and perform testing of PC/server operating systems, networks, and related utilities and hardware.

The Senior Identity Access Management (IAM) Engineer will lead the implementation, administration, and optimization of IAM systems across enterprise environments.  This role is essential for maintaining security, compliance, and operational efficiency in unregulated, government-regulated, and cloud-based environments.  The Engineer will collaborate with cross-functional teams, provide expert guidance on IAM and PAM practices, and ensure secure management of identities, accounts, and privileged access.
 

The Senior IAM Engineer will provide global 3rd level support and troubleshooting for Saviynt, CyberArk, Active Directory services, EntraID services, related AD management tools and cloud single sign-on integrations.

What we’re looking for 

Education: Bachelor's degree in Computer Science, Information Systems, or related field (or equivalent experience).

Certification:

  • Active CyberArk Defender and Sentry certifications are a plus.

  • Additional certifications (e.g., Microsoft, AWS, Azure, CISSP) are a plus.

Experience:

  • 10+ years of IT experience with a focus on IAM and security solutions.

  • 5+ years of experience with IAM Tools like Saviynt implementations and management.

Preferred Qualifications:

  • Proven expertise in Active Directory, Azure AD, LDAP, PKI, SSO, and 2FA systems.

  • Hands-on experience with scripting (PowerShell, Python, Java or other) for automation and system integration.

  • Deep understanding of privileged access management principles, including least privilege enforcement and session monitoring.

  • Strong knowledge of Active Directory services, group policies, DNS, and certificate services.

  • Proficiency in integrating IAM tools with cloud environments (e.g., AWS, Azure).

  • Excellent troubleshooting, analytical thinking, and communication skills.

  • Ability to define and drive projects from concept to completion, ensuring alignment with deadlines.

How will you thrive and create an impact:

Saviynt Identity Governance Administration (IGA)

  • Design, implement, and optimize Identity Governance Administration (IGA) workflows, access policies, and role-based access controls (RBAC).

  • Automates Joiner/leaver/mover (JLM) operations across applications.

  • Review orphaned accounts, excessive privileges, and policy violations.

  • Manages identity attributes, entitlements, and access rights.

  • Automates identity synchronization across cloud and on-premises systems.

  • Implements approval workflows to enforce security policies before granting access.

  • Enables access delegation and emergency access (Break Glass Accounts) when needed.

  • Uses Role Mining & Role Engineering to define least-privileged access.

  • Automates periodic access certifications for user accounts and entitlements.

  • Provides review campaigns for managers, application owners, and auditors.

  • Tracks all user access changes, requests, and approvals for auditability.

  • Generates detailed audit reports to meet compliance requirements.

  • Support self-service portal for users to request access to applications, roles, and entitlements.

CyberArk Privileged Access Management

  • Design, deploy, and maintain CyberArk solutions, including Enterprise Password Vault (EPV), Privileged Session Manager (PSM), and Central Policy Manager (CPM).

  • Develop privileged access policies, procedures, and standards aligned with industry best practices and regulatory compliance (e.g., CMMC, PCI-DSS, HIPAA).

  • Monitor, audit, and optimize CyberArk configurations and policies to mitigate security risks.

  • Integrate CyberArk with identity providers (e.g., Active Directory, Azure AD, LDAP) and other IT infrastructure.

  • Automate PAM processes using scripting languages like PowerShell or Python.

  • Lead incident response activities for privileged access abuse or unauthorized access attempts.

Identity and Access Management

  • Support and enhance IAM tools and services, focusing on secure user privileges, credential management, and access control.

  • Configure and optimize identity systems, including Active Directory, Azure AD, LDAP, PKI, and SSO/2FA solutions.

  • Lead IAM-related projects, including domain consolidations, decommissioning, and cloud migrations.

  • Develop processes for IAM governance, compliance, and reporting.

  • Define and implement workflows for user provisioning, deprovisioning, and role management.

  • Troubleshoot and resolve IAM and PAM-related issues.

Collaboration and Leadership

  • Collaborate with IT, security, and compliance teams to design and implement IAM and PAM strategies.

  • Act as a subject matter expert on Saviynt and IAM technologies, providing training and mentorship to team members.

  • Ensure alignment of IAM solutions with organizational security and compliance requirements.

  • Represent the IAM function during audits, assessments, and stakeholder discussions.

Disclaimer:
The above statements are intended to describe the general nature and level of work being performed by employees assigned to this classification. They are not intended to be construed as an exhaustive list of all responsibilities, duties and skills required of employees assigned to this position. Avantor is proud to be an equal opportunity employer.

Why Avantor?

Dare to go further in your career. Join our global team of 14,000+ associates whose passion for discovery and determination to overcome challenges relentlessly advances life-changing science.
 
The work we do changes people's lives for the better. It brings new patient treatments and therapies to market, giving a cancer survivor the chance to walk his daughter down the aisle. It enables medical devices that help a little boy hear his mom's voice for the first time. Outcomes such as these create unlimited opportunities for you to contribute your talents, learn new skills and grow your career at Avantor.
 
We are committed to helping you on this journey through our diverse, equitable and inclusive culture which includes learning experiences to support your career growth and success. At Avantor, dare to go further and see how the impact of your contributions set science in motion to create a better world. Apply today!

EEO Statement:

We are an Equal Employment/Affirmative Action employer and VEVRAA Federal Contractor. We do not discriminate in hiring on the basis of sex, gender identity, sexual orientation, race, color, religious creed, national origin, physical or mental disability, protected Veteran status, or any other characteristic protected by federal, state/province, or local law.

If you need a reasonable accommodation for any part of the employment process, please contact us by email at [email protected] and let us know the nature of your request and your contact information. Requests for accommodation will be considered on a case-by-case basis. Please note that only inquiries concerning a request for reasonable accommodation will be responded to from this email address.

3rd party non-solicitation policy:

By submitting candidates without having been formally assigned on and contracted for a specific job requisition by Avantor, or by failing to comply with the Avantor recruitment process, you forfeit any fee on the submitted candidates, regardless of your usual terms and conditions. Avantor works with a preferred supplier list and will take the initiative to engage with recruitment agencies based on its needs and will not be accepting any form of solicitation

Top Skills

Active Directory
AWS
Azure
Azure Ad
Cyberark
Java
Ldap
Pki
Powershell
Python
Saviynt

Similar Jobs

3 Hours Ago
Hybrid
Mumbai, Maharashtra, IND
Mid level
Mid level
Artificial Intelligence • Big Data • Cloud • Information Technology • Software • Big Data Analytics • Automation
Drive sales growth through targeted acquisition efforts, manage customer accounts, consult with executives, and expand partnerships in enterprise software sales.
Top Skills: AIAWSGCPMicrosoftObservabilitySales Engineering
3 Hours Ago
In-Office
Mumbai, Maharashtra, IND
Senior level
Senior level
Big Data • Cloud • Fintech • Financial Services • Conversational AI
The Vice President of Employee Relations manages investigations and employee matters, liaising with HR and legal to ensure fair treatment and compliance across APAC.
3 Hours Ago
Hybrid
Maharashtra, IND
Entry level
Entry level
Automotive • Hardware • Robotics • Software • Transportation • Manufacturing
Provide L1 support for IT systems, troubleshoot hardware and software issues, assist users via calls and tickets, and maintain IT asset records.
Top Skills: LanMS OfficeWi-FiWindows Os

What you need to know about the Pune Tech Scene

Once a far-out concept, AI is now a tangible force reshaping industries and economies worldwide. While its adoption will automate some roles, AI has created more jobs than it has displaced, with an expected 97 million new roles to be created in the coming years. This is especially true in cities like Pune, which is emerging as a hub for companies eager to leverage this technology to develop solutions that simplify and improve lives in sectors such as education, healthcare, finance, e-commerce and more.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account