UST logo
UST

1,202 open roles

Analyst II - Information Security

Trivandrum, IndiaFull-timePosted Oct 10, 2026

Job description

Identity Security Engineer Function: Security Architecture & Engineering Reports to: Identity Security Architect & IGA Service Owner Location: India (Trivandrum, Bangalore or Hyderabad) Role Overview UST is looking for an Identity Security Engineer to own the engineering and operational delivery of identity security controls across the enterprise.

Identity is UST's primary security control plane -this role exists to make it robust, resilient, and difficult to abuse. This is not just an IGA administration role. The focus is security: closing identity-based attack paths, enforcing least privilege, eliminating orphaned and over-privileged accounts, securing non-human and AI-driven identities, and ensuring that identity signals are feeding detection and response.

The platforms

  • IGA, IAM, NHI controls are the means to that end. The engineer works directly under the Identity Security Architect & IGA Service Owner and is the primary technical resource responsible for building, automating, and operating identity security controls across the full identity lifecycle. This is a build-and-operate role - ownership includes both engineering delivery and the ongoing security integrity of what is built. The expectation is engineering-led operations: automation-first, security-outcome-focused, with continuous improvement built in.

Key Responsibilities

  1. IGA
  • Identity Lifecycle Security Engineer the IGA platform to enforce secure identity lifecycle controls. The goal is not a functioning workflow engine - it is zero orphaned accounts, enforced least privilege, and audit-ready access governance:
  1. Build and automate Joiner-Mover-Leaver controls ensuring access is granted only when it should be, scoped correctly, and revoked without delay
  2. Engineer SoD rule enforcement and automated violation detection- reducing the window between a violation occurring and being closed
  3. Implement access certification campaigns that are meaningful, not ceremonial - right reviewers, right scope, automated remediation of uncertified access
  4. Build provisioning connectors with security controls embedded - least privilege defaults, approval gates, and deprovisioning automation
  5. Engineer repeatable evidence collection for audit and compliance - access reviews, provisioning logs, and certification completion rates
  6. Own platform change and release engineering - ensuring changes are tested, controlled, and do not introduce access regressions
  7. IAM
  • Authentication & Access Security
  1. Engineer and harden IAM integrations across Entra ID and other identity providers -with a focus on reducing authentication attack surface, not just enabling access
  2. Implement and validate federation and SSO configurations (SAML, OAuth 2.0, OIDC) - including token security, claim scoping, and session controls
  3. Build and maintain SCIM provisioning integrations - ensuring over-provisioning is structurally prevented, not just periodically reviewed
  4. Engineer Conditional Access and identity protection policies - risk-based controls, not blanket policies
  5. Build automation for directory hygiene - stale account detection, group membership enforcement, and privilege creep remediation
  6. Non-Human Identity (NHI) Security
  7. Engineer controls to reduce the NHI attack surface - service accounts, API keys, workload identities, bots, and automation credentials are a primary lateral movement vector and must be treated accordingly
  8. Build lifecycle governance for NHIs: ownership enforcement, automated rotation, and decommissioning -eliminating the long-lived, unowned credential as a risk class
  9. Integrate secrets vaults into application and workload pipelines - replacing static credentials with dynamic, short-lived secrets
  10. Implement workload identity federation for cloud-native workloads - removing the need for stored credentials entirely where possible
  11. Engineer detection for NHI abuse - identifying stale, over-privileged, or anomalously behaving machine identities before they are exploited
  12. AI & Agentic Identity Security
  13. Implement security controls for AI agent and copilot identities - scoped credentials, token lifecycle management, and enforced least privilege
  14. Build data access governance controls for AI pipelines - ensuring AI systems access only what they need, with full auditability
  15. Engineer controls to prevent and detect API key sprawl, over-permissioned AI service accounts, and credential misuse by AI systems
  16. Identity Threat Detection & Response
  17. Engineer identity signal feeds into SIEM, UEBA, and EDR/XDR platforms - ensuring identity events are visible and actionable in detection workflows
  18. Build and tune detection logic for identity-based attack patterns: credential abuse, privilege escalation, service account misuse, and impossible travel
  19. Investigate identity-related security events and support incident response - tracing access paths, containing compromised identities, and remediating the root cause
  20. Proactively hunt for identity risk: over-privileged accounts, dormant credentials, shadow access, and SoD violations
  21. Security Compliance & Access Risk
  22. Engineer evidence collection and access review processes to support ISO 27001, SOC 2, and applicable regulatory requirements - automated and repeatable, not manual and point-in-time
  23. Identify and close access risk gaps: orphaned accounts, excessive entitlements, SoD violations, and uncertified access
  24. Contribute to risk reporting by surfacing identity risk metrics - not just activity logs
  25. Documentation & Engineering Standards
  26. Maintain build documentation, runbooks, and operational procedures for all identity security controls owned
  27. Document integration patterns and security configuration standards to ensure consistency across the identity ecosystem
  28. Feed operational insight back to the Identity Security Architect - surfacing gaps, emerging risks, and improvement opportunities from the engineering layer Required Experience 1. 5+ years in IT/security, with at least 3 years in hands-on identity security engineering -not IAM administration
  29. Proven experience implementing enterprise IGA platforms
  • Sail. Point Or Savyint strongly preferred
  1. Practical experience with Entra ID, Okta, or equivalent IAM platforms - security configuration, not helpdesk-level administration
  2. Working knowledge of SAML, OAuth 2.0, OIDC, and SCIM - able to implement and troubleshoot, not just describe
  3. Experience securing non-human identities - service accounts, API keys, secrets vaults, workload identity
  4. Scripting or automation capability (Power. Shell, Python, or equivalent) - used to eliminate manual identity operations, not just run reports
  5. Understanding of identity-based attack techniques: credential abuse, privilege escalation, lateral movement via service accounts
  6. Familiarity with Cloud IAM across at least one of AWS, Azure, or GCP
  7. Experience producing compliance evidence and supporting security audits What Good Looks Like The right person thinks like a security engineer who specialises in identity - not an IAM engineer who handles security on the side. They understand how identity gets abused: credential theft, privilege escalation, lateral movement through service accounts, SoD bypass. They build controls with that threat model in mind, automate away the manual work, and feed signal back into detection. They are not waiting for the architect to tell them something is a risk they are finding it, flagging it, and fixing it.

Preferred Qualifications

  1. Sail. Point Or Savyint certifications
  2. Experience with PAM platforms (e.g., Cyber. Ark, Beyondtrust) and privileged access security controls
  3. Hands-on experience with SIEM or UEBA platforms from an identity threat detection perspective
  4. Understanding of identity attack techniques
  • MITRE ATT&CK coverage across credential access, privilege escalation, and lateral movement
  1. Exposure to Zero Trust architecture and how identity security controls underpin it

Description copied from UST's careers page. Read the full posting before you apply.

More jobs at UST

See all openings at UST