CyberSigma Consulting Services
Website:
cybersigmacs.com
Job details:
IAM Lead – Identity & Access Management
Location: Bengaluru, India
Experience: 7–12 Years
Role: Lead Security Engineer
Reporting To: Enterprise Identity & Security Operations Leader / CISO
About the Role
PayU is looking for an experienced IAM Lead to lead the design, implementation, governance, and operations of enterprise Identity & Access Management and related security capabilities.
The role is hands-on and covers IAM, PAM, Zero Trust, cloud security, endpoint security, DLP, MDM, email security, and AI security. The candidate will work closely with Security Operations, Cloud, Infrastructure, IT, Engineering, Risk, and Compliance teams to build secure, scalable, and audit-ready security controls.
Key Responsibilities
- Own enterprise IAM, including JML lifecycle, provisioning/deprovisioning, SSO, federation, RBAC, least privilege, conditional access, access reviews, and SoD.
- Design and operate SSO and identity integrations using SAML, OAuth 2.0, and OIDC.
- Manage PAM capabilities including privileged account discovery, credential vaulting, rotation, session recording, and JIT access.
- Operate and improve CSPM controls across cloud environments, addressing misconfigurations, excessive permissions, and compliance gaps.
- Manage SWG/CASB controls for SaaS, web access, shadow IT, application governance, and data protection.
- Operate EDR platforms, investigate endpoint alerts, support incident response, and drive endpoint hardening.
- Design and enforce DLP policies across endpoints, email, cloud, SaaS, and collaboration platforms.
- Manage MDM/UEM, device compliance, endpoint baselines, and conditional access integration.
- Manage email security, including anti-phishing, malware protection, sandboxing, SPF, DKIM, and DMARC.
- Establish security governance for GenAI/AI applications, including access, usage, and data-protection controls.
- Support security incidents, audits, risk assessments, compliance activities, and remediation programmes.
- Maintain security dashboards, KPIs/KRIs, SOPs, audit evidence, and executive reporting.
- Drive security automation, platform optimisation, technical standards, and continuous improvement.
Required Skills
- 7–12 years of experience in IAM, cybersecurity, security engineering, or related domains.
- Strong hands-on experience with Microsoft Entra ID / Active Directory.
- Strong knowledge of SSO, SAML, OIDC, OAuth, RBAC, conditional access, and identity governance.
- Experience with CyberArk, BeyondTrust, or equivalent PAM platforms.
- Experience with CSPM, CASB/SWG, EDR, DLP, MDM/UEM, and email security.
- Strong experience with the Microsoft security ecosystem, including Entra ID, Defender, Purview, and Intune.
- Experience with CrowdStrike or equivalent EDR is desirable.
- Knowledge of Zero Trust, cloud security, data protection, and AI security.
- Understanding of RBI, PCI-DSS, ISO 27001, NIST, CIS, and DPDP Act requirements.
- Strong incident investigation, troubleshooting, stakeholder management, and technical leadership skills.
Education & Certifications
- Bachelor's degree in Computer Science, Information Technology, Engineering, Cybersecurity, or related field.
- Preferred certifications: CISSP, CISM, SC-300, SC-200, CIAM, or relevant PAM/cloud/security certifications.
Why PayUJoin PayU's security organisation and help protect a large-scale fintech ecosystem serving millions of customers and merchants across India. This role offers broad technical ownership across
identity, privileged access, cloud, endpoint, data, SaaS, and AI security in a highly regulated environment.
Click on Apply to know more.