Job Summary
Job Summary The IAM Operations Engineer (L2) is responsible for the administration, support, monitoring, and maintenance of Identity and Access Management solutions. The role ensures secure and compliant access to enterprise applications, systems, and privileged accounts through effective identity lifecycle management, access governance, and operational support.
Key Responsibilities
Key Responsibilities Identity Lifecycle Management Manage Joiner-Mover-Leaver (JML) processes for user provisioning, modification, and de-provisioning. Perform access requests, role assignments, entitlement changes, and account maintenance activities. Ensure timely execution of access reviews, certifications, and compliance requirements. IAM Platform Operations Provide L2 support for IAM platforms such as SailPoint, Azure AD (Entra ID), Okta, PingFederate, PingAccess, IBM ISIM, CyberArk, RSA, and Active Directory. Monitor IAM infrastructure health, performance, and availability. Troubleshoot authentication, authorization, SSO, MFA, federation, and directory synchronization issues. Support application onboarding and integration activities with IAM solutions. Access & Security Administration Manage user identities, access privileges, group memberships, and role-based access controls. Support Privileged Access Management (PAM) operations, password vaulting, account reconciliation, and privileged session controls. Ensure compliance with least-privilege and segregation-of-duty principles. Incident & Service Management Handle L2 incidents, service requests, and problem tickets within agreed SLAs. Perform root cause analysis (RCA) for recurring access and authentication issues. Coordinate with L3 teams, application owners, and security teams for issue resolution. Governance & Compliance Support audit activities and compliance reporting. Execute periodic access recertification and policy reviews. Maintain operational documentation, SOPs, and knowledge articles. Automation & Continuous Improvement Develop and support automation scripts using PowerShell, Python, or similar technologies. Identify opportunities to automate repetitive IAM processes and improve operational efficiency.
Skill Requirements
Required Technical Skills Identity & Access Management concepts (SSO, MFA, Federation, RBAC, ABAC, JML). Active Directory, LDAP, Azure AD / Microsoft Entra ID. SailPoint IIQ / ISC, Okta, Ping Identity, IBM ISIM, CyberArk or equivalent IAM/PAM tools. Authentication protocols: SAML, OAuth, OIDC, Kerberos, LDAP. ITSM tools such as ServiceNow. PowerShell, Python, or Shell scripting. Windows and Linux administration fundamentals. Experience & Qualifications 3 to 6 years of experience in IAM Operations or Cybersecurity Operations. Bachelor\'s degree in Computer Science, Information Technology, or related field. Experience in a 24x7 support environment. Understanding of ITIL processes (Incident, Problem, Change Management).