Overview
We are seeking a Senior Security Engineer to design, build, and optimize enterprise identity infrastructure. The role leads implementation and daily administration of IAM, IGA, and continuous authorization frameworks using Okta, Saviynt, and SGNL across cloud and hybrid environments.
What you'll do
- Architect, deploy, and maintain robust enterprise identity solutions across Okta Workforce Identity Cloud, Saviynt IGA, and SGNL CA / Dynamic Access.
- Configure and optimize Saviynt for access requests, dynamic role-based access control (RBAC/ABAC), access certification campaigns, and automated provisioning/deprovisioning workflows.
- Manage and secure Okta configurations, including SAML 2.0, OIDC, adaptive MFA policies, passwordless authentication, and Directory Integrations with Active Directory, LDAP, and HRIS.
- Operationalize SGNL to enforce Zero Trust access, Just-In-Time (JIT) access, and continuous, event-driven authorization policies across enterprise applications and services.
- Develop custom connectors, workflows, and automated pipeline scripts using Python, PowerShell, and REST APIs to integrate target applications into Saviynt and Okta.
- Collaborate with SOC and Incident Response teams to investigate identity-related threats, privileged access abuses, and anomalous login behavior.
- Partner with Security Compliance to enforce least-privilege principles, generate audit-ready reporting, and remediate identity risk findings.
What you'll need
- 5+ years of direct, hands-on experience in information security with a primary focus on Identity and Access Management (IAM).
- Deep technical expertise in Okta, including Lifecycle Management (LCM), Universal Directory, Workflows, Adaptive MFA, and SSO integrations.
- Proven hands-on administration of Saviynt Enterprise IGA, including analytics, connector deployment, lifecycle workflows, and access request configuration.
- Experience with modern continuous authorization architectures, specifically hands-on exposure to SGNL or similar fine-grained, policy-based access control platforms (CA/ABAC/ReBAC).
- Strong understanding of OAuth 2.0, OIDC, SAML 2.0, SCIM, and LDAP.
- Proficiency in scripting and automation using Python, PowerShell, or Bash, alongside strong REST API integration capabilities.
- Solid grasp of Zero Trust Security frameworks and Least Privilege Access models.
Nice to have
- Experience with Privileged Access Management (PAM) integrations, such as CyberArk and BeyondTrust.
- Relevant industry certifications such as Okta Certified Professional, Administrator, or Consultant; Saviynt Certified Professional; CISSP; or CISM.
- Background in cloud identity security, including AWS IAM, Azure AD / Microsoft Entra ID, and GCP IAM.
Details
- Location: Bengaluru.
- Work model: Hybrid.
- Employees are required to work at least 3 days in the office per week, with flexibility to work from home 2 days a week, depending on the role requirement.
- Some businesses may require more time in the office due to the nature of the work.
Read the full description and apply on the company’s own careers page.