Hi All,
We have an opening for the role of Identity Access Management for one of our leading Investment Banking client in Mumbai location.
Experience : 5- 7 years
Location : Mumbai
Responsibilities
any one
Application Lifecycle Management
- Perform sanity checks and validate requests for onboarding of new assets (applications, shared drives, and entitlements) in MyIAM tool
- Review and validate requests for modification or removal of existing assets in IAM tool.
- Execute security controls and validate business role creation/modification
- Validate workflow creation/modifications of an asset in MyIAM tool
- Ensure applications are registered in an authorized referential and the security criticality in MyIAM is aligned with the referential
- Ensure Functional Role Codes (FRCs) are assigned to entitlements at a minimum for all critical applications (trading, payment, accounting, etc.) to manage SOD breaches
- Following a periodic reconciliation between application referential and MyIAM tool, ensure applications mandated by policy/audit requirements are onboarded on MyIAM
- Review and validate the setup of SOD & TOX rules in MyIAM tool
- Strengthen data quality in MyIAM tool by mitigating feed file issues arising from auto-reconciliation (unknown entitlements and orphan accounts)
- Monitor manual reconciliation of applications performed by Production Security and ensure adherence to group/CIB IAM policy
Identity Lifecycle Management
- Validate requests for extended rights, remote access etc. in MyIAM
- Validate SoD violations generated by FRC mismatch and mitigate them by obtained appropriate approvals
- Supervise all user access recertification campaigns throughout the year, perform chasers to certifiers to ensure 100% completion of the exercise before the deadline
- Provide L2 support to the Joiner/Mover/Leaver process triggered by MyIAM tool
- Handle L2 queries from end-users via emails and/or service now on various IAM topics
- Coordinate with the IT Production for any technical assistance required on MyIAM tool
- Ensure regional IAM requirements/issues are assessed and converted into appropriate tickets
- Perform business analysis, UAT for any new IAM feature within MyIAM tool
Audit and Controls
- Ensure toxic access violations between critical applications are adequately detected and mitigated. Obtain appropriate risk cards when necessary
- Ensure logical accesses leaver and mover accesses are timely deleted.
- Active Directory (AD) for leavers is deactivated on the date of leave (EoD)
- Ensure Letter of undertaking (LOU) is signed by users who can access local data of another territory
- Identify users having access to critical payment systems such as Swift, Olympicm StorQM and ensure they do not have internet access
- Ensure VIPs are identified and their delegations are in place with appropriate expiry dates
- Ensure multiple accounts, inactive accounts, etc. are identified and mitigated within critical applications
- Provide support during audit campaigns by providing necessary evidences as part of RFIs and recommendation closures
Technical & Behavioral Competencies
- Strong understanding of Identity and Access Management (IAM) control framework
- Exposure to stakeholder management
- Proficiency in speaking and writing in English. French would be an added advantage.
- Have outstanding interpersonal skills and are comfortable engaging with senior stakeholders
- Confident and able to influence others
- Is able to lead a group to consensus while handling situations of conflict
- Have excellent time management and are able to multi-task and manage priorities
- Can translate analytical thinking into solutions and present them to management
- Experienced in managing and processing data in with advanced Excel functions
- Able to produce clear reports (KPIs, KRIs, dashboards, charts, data visualization in general)
- Familiar with process analysis and improvement, drafting of workflows and procedures
If anyone is interested , please share me your resumes to ashwini.shetty@kiya.ai