Role Overview
The IAM L2 Specialist is responsible for managing and supporting enterprise Identity & Access Management platforms to ensure secure, compliant, and efficient access across on-prem and cloud environments. The role focuses on identity lifecycle management, access governance, authentication controls, and incident escalation.
Key Responsibilities
IAM Administration & Governance
- Administer and support IAM platforms such as Azure AD, Okta, SailPoint, Ping Identity, ForgeRock
- Manage user lifecycle (joinermoverleaver), RBAC, and least-privilege access
- Enforce IAM policies aligned with ISO 27001, NIST, PCI-DSS, GDPR, HIPAA
Access Control & Authentication
- Implement and manage SSO, MFA, passwordless authentication
- Perform periodic access reviews, audits, and compliance reporting
- Manage privileged and non-privileged access across hybrid environments
Incident Management & Risk
- Act as L2 escalation point for identity-related incidents
- Investigate suspicious access activity and support forensic analysis
- Collaborate with SOC and security teams for remediation and prevention
Integration & Automation
- Integrate IAM with PAM, SIEM, ITSM, CMDB platforms
- Automate onboarding/offboarding and access provisioning workflows
- Build dashboards and reports for operational and compliance visibility
Stakeholder Collaboration
- Serve as IAM SME for IT and business teams
- Work closely with application, infrastructure, and security teams
- Support IAM awareness, documentation, and best practices
Required Skills & Experience
- 68 years of IT/Security experience with 24 years in IAM
- Strong understanding of identity lifecycle, RBAC, authentication, and authorization
- Hands-on experience with Azure AD, Okta, SailPoint, Ping Identity
- Experience with ITIL processes and ITSM integrations
- Strong analytical, communication, and stakeholder management skills
Preferred Qualifications
- CISSP, CISM, or equivalent security certifications
- IAM vendor certifications (Okta, SailPoint, Azure AD)
- ITIL v4 certification
- Experience in cloud and hybrid IAM environments