Search by job, company or skills

Senior IAM Support Analyst

Early Applicant
  • Posted 4 days ago
  • Be among the first 10 applicants

Job Description

Talent500 is hiring for one of its clients.

Who are we:

Core Insurance Platforms (CIP) is Zurich's global capability responsible for building, running, and evolving core insurance technology. We set a unified, scalable operating model—covering governance, standards, architecture, service delivery, and reuse—so our business units can deliver at speed and scale.

CIP is the strategic steward of Zurich's Guidewire ecosystem, aligning platform roadmaps to business strategy while driving stability, modernization, reduced supplier dependency, and long term cost efficiency.

India delivery center is one of our global delivery and capability hub. We bring together experts in AI, engineering, analysis, quality, and architecture to deliver product & process solutions, application run services, change and transformation initiatives, and centralized platform services across both on prem and Guidewire Cloud environments. Our teams operate from multiple global delivery centers, supporting Zurich's business units worldwide.

Senior IAM Support Analyst

Job Summary:

The Senior IAM Developer is responsible for engineering, enhancing, and integrating Zurich's global Workforce IAM and Customer Identity and Access Management (CIAM) capabilities to enable secure, resilient, and scalable access to applications and digital services.

This role delivers secure by design IAM, CIAM, and Conditional Access solutions across cloud and on prem environments, with a strong emphasis on Zero Trust enforcement, customer identity journeys, automation, identity lifecycle management, and access governance.

The role works closely with IAM product owners, architects, cybersecurity, application teams, and strategic vendors and is engineering led, with no primary responsibility for day to day operational support.

Key Responsibilities:

IAM & CIAM Engineering and Solution Delivery:

  • Design, develop, and enhance Workforce IAM and CIAM solutions across Okta, Okta Auth0, Okta Access Gateway, Microsoft Entra ID (Azure AD), and Conditional Access.
  • Engineer authentication solutions supporting Zero Trust and CIAM use cases, including MFA, password less authentication, adaptive and risk based access, privileged access, and customer identity flows.
  • Design and implement secure authentication, authorization, and federation patterns using SAML 2.0, OAuth 2.0, OpenID Connect, and SCIM.
  • Deliver identity lifecycle and access models for workforce users, partners, and customers, including CIAM sign up, sign in, profile management, and consent flows.

CIAM (Customer Identity) Enablement – Okta Auth0:

  • Design and implement CIAM architectures using Okta Auth0 for customer facing and digital applications.
  • Engineer secure and scalable customer authentication flows, including social identity providers, progressive profiling, step up authentication, and fraud aware access controls.
  • Define CIAM patterns that balance security, regulatory compliance, and customer experience.
  • Partner with digital application teams to integrate Auth0 into customer platforms and APIs.
  • Ensure CIAM implementations align with privacy, data protection, and regulatory requirements (e.g., consent, minimal data collection).

Conditional Access & Zero Trust Enablement:

  • Design, implement, and continuously improve Conditional Access policies aligned with Zurich security standards and Zero Trust architecture.
  • Define scalable Conditional Access patterns for workforce users, privileged roles, devices, applications, and workload identities.
  • Engineer policy automation, validation, and safe deployment mechanisms to reduce risk and configuration drift.
  • Partner with security and architecture teams to evolve baseline protections and Zero Trust strategy.

Platform Engineering & Automation:

  • Develop automation using APIs, SDKs, scripting, and configuration as code to improve IAM and CIAM platform reliability and efficiency.
  • Support CI/CD pipelines and controlled promotion of IAM, CIAM, and Conditional Access changes across environments.
  • Contribute to platform upgrades, new feature adoption, and continuous reduction of technical debt across Okta, Auth0, and Entra ID.
  • Proactively implement engineering improvements that enhance security, resilience, and scalability.

Application & Cloud Integration:

  • Partner with application teams to design and deliver secure IAM, CIAM, and Conditional Access integrations for SaaS, cloud, custom, API based, and legacy applications.
  • Lead IAM and CIAM technical assessments during application onboarding, migrations, and cloud transformations.
  • Validate IAM and CIAM designs to ensure production readiness, security compliance, and user experience.
  • Resolve complex federation and access challenges across hybrid and multi tenant environments.

Security, Risk & Architecture Alignment:

  • Ensure all IAM, CIAM, and Conditional Access solutions comply with Zurich security policies, architectural standards, and regulatory requirements.
  • Implement controls supporting least privilege, strong authentication, continuous access evaluation, and defense in depth.
  • Provide technical input to risk assessments, audits, security reviews, and regulatory engagements.
  • Contribute to threat modeling and design decisions related to identity compromise, customer fraud, and access abuse scenarios.

Technical Leadership & Collaboration:

  • Act as a senior technical authority and mentor for IAM engineers and developers.
  • Collaborate with IAM architects and product owners to influence platform roadmaps, CIAM strategy, Conditional Access standards, and solution direction.
  • Work with strategic vendors and partners (e.g., Okta/Auth0, Microsoft) to support advanced integrations and feature adoption.
  • Provide engineering level guidance during complex IAM and CIAM incidents and escalations.

Documentation & Continuous Improvement:

  • Maintain technical designs, integration standards, CIAM and Conditional Access guidelines, and engineering runbooks.
  • Contribute to post implementation and post incident reviews from a solution and architecture perspective.
  • Continuously evaluate IAM and CIAM technologies to improve security posture, service quality, and developer experience.

Additional Information:

  • Operates in a global IAM and CIAM environment with cross regional collaboration.
  • Occasional participation in after hours releases for IAM, CIAM, or Conditional Access may be required.

Technical Skills:

  • Extensive experience (typically 8+ years) in IAM and/or CIAM engineering within a large enterprise environment.
  • Strong hands on experience with Okta Workforce IAM and Okta Auth0 (CIAM) and/or Microsoft Entra ID Conditional Access.
  • Deep understanding of Zero Trust architecture, CIAM patterns, authentication, authorization, and identity lifecycle management.
  • Proven experience with SAML, OAuth, OpenID Connect, and SCIM.
  • Experience developing integrations using APIs, scripting, or programming languages (Java, .NET, Python, PowerShell, JavaScript).
  • Experience supporting cloud first, SaaS, API driven, and hybrid identity architectures.

Soft Skills:

  • Strong analytical mindset with a security first, customer aware engineering approach.
  • Ability to clearly articulate complex IAM, CIAM, and Conditional Access designs to diverse stakeholders.
  • Comfortable operating in a global, regulated, and risk focused environment.
  • Strong collaboration, influencing, and stakeholder management skills.
  • High standards of ownership, accountability, and engineering excellence.

Education:

  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or equivalent professional experience.

Candidate Data Privacy Notice:

Applicability of This Notice: This job posting relates to opportunities with Zurich Digital International Private Ltd. (Zurich) and is published with the support of ANSR Inc., (ANSR) an authorized recruitment service provider engaged by Zurich for its hiring activities.

Participation in the Recruitment Process: When you apply for this role, personal data provided as part of your application (such as your name, email address, contact details, address, financial information, background information, medical history, and details of previous employers/employment) is collected for the purposes of recruitment and selection and may be reviewed by Zurich, and transferred/disclosed to Zurich's affiliates, subsidiaries, and related entities and ANSR (Transferees), solely for recruitment and selection purposes (in accordance with their respective privacy policies).

The Transferees maintain at least the same level of protection for your data as maintained by Zurich, and do not further transfer/disclose/share or publish your data.

More Info

Job Type:
Industry:
Employment Type:

About Company

Job ID: 151431281

Similar Jobs

Hyderabad, India

Skills:

saml 2.0 ServicenowOktaOpenID ConnectMulti-factor authenticationOAuth 2.0SCIMOkta Access GatewayAzure Conditional Access