Execute technical deployment, configuration, and maintenance of IAM toolsets: SailPoint, Saviynt, CyberArk, ForgeRock, Okta, Azure AD, etc.
Lead daily operations including user lifecycle automation, connector management, rule tuning, patching, and upgrade planning
Manage integration of IAM platforms with IT and OT systems (ERP, SCADA gateways, cloud directories, HRMS, SIEMs)
Maintain compliance with global frameworks (ISO 27001, NIST, IEC 62443) and internal security policies
Ensure proper functioning of access reviews, policy violations, SoD checks, and automated certifications
Develop scripts, APIs, and tool extensions to enable seamless operations and self-service functions
Act as SME for all IAM tools during internal and external audits, client discussions, and incident response
Monitor tool health, implement KPIs and dashboards, and proactively identify areas of improvement
Work closely with Delivery, PAM, and Engineering teams for smooth handovers and incident resolution
Required Skills & Qualifications
7 + years of experience in IAM domain, with minimum 5 years in hands-on tool/platform management
Strong implementation and operational knowledge of one or more IAM platforms: SailPoint IIQ, Saviynt, CyberArk, ForgeRock, Okta, Azure AD
Proven track record managing IAM connectors, schema mapping, rule-based provisioning, and API integrations
Solid grasp of authentication protocols (LDAP, SAML, OAuth, OIDC), scripting (PowerShell, Python), and cloud IAM (Azure, AWS)
Experience supporting OT IAM implementations or integration with SCADA/ICS components is a strong plus
Working knowledge of identity governance workflows, SoD policies, privileged access controls, and identity analytics
Strong documentation, troubleshooting, and RCA/reporting abilities
Preferred Certifications
Tool-specific certifications (e.g., SailPoint Implementation Engineer, CyberArk Defender, Saviynt CPAM)
ITIL v4 Foundation, ISO 27001 Implementer or similar
Basic CISSP/CISA-level understanding desirable