ABOUT THE PRACTICE
Olive Intelligence (OI) is building an independent, advisory-first cybersecurity, privacy, and responsible AI practice serving CISOs and senior executives across Indian enterprises — anchored to live regulatory mandates including the DPDP Act & Rules, SEBI CSCRF, RBI IT Governance and outsourcing directions, and CERT-In norms. We are product-independent by design: we assess, design, and advise — with recommendations anchored to risk and regulation.
ROLE OVERVIEW
You will lead identity governance and access management engagements — from IAM maturity assessment and roadmap through IGA/SSO implementation — for clients facing RBI, SEBI CSCRF, and DPDP-driven identity mandates. Identity is the control plane of Zero Trust; this role anchors that pillar of our practice.
KEY RESPONSIBILITIES
▪ IAM strategy & assessment — Assess client identity landscapes (workforce, privileged, machine/workload identities); define target-state architecture, roadmap, and business case.
▪ IGA delivery — Implement identity governance — joiner/mover/leaver lifecycle, access certification campaigns, SoD policy, role mining and RBAC design, and application onboarding.
▪ Access management — Deploy SSO, adaptive MFA, and conditional access; federate across SaaS and on-prem estates; design passwordless and phishing-resistant authentication journeys.
▪ Regulatory alignment — Map IAM controls to RBI IT Governance, SEBI CSCRF identity requirements, DPDP access-control safeguards, and supervisory expectations; deliver assessment-ready evidence.
▪ Client advisory — Advise CISOs on IAM tooling strategy, PAM adjacency, and Zero Trust sequencing — product-independent and regulator-anchored.
MUST-HAVE: TOOLS & PLATFORMS
▪ SailPoint (IdentityIQ or Identity Security Cloud/IdentityNow) — connector configuration, lifecycle workflows, certifications, and role modelling; or
▪ Okta — Universal Directory, SSO/OIDC/SAML federation, adaptive MFA, Workflows, and Okta Identity Governance; or
▪ Ping Identity (PingFederate, PingOne, PingAccess) — federation architecture, policy design, and API access management.
▪ Depth in at least one of the above is mandatory; working familiarity with a second platform is a strong advantage.
MUST-HAVE: EXPERIENCE & KNOWLEDGE
▪ 5+ years in IAM consulting or engineering, with at least two end-to-end IGA or access management implementations.
▪ Strong grasp of identity protocols and patterns — SAML, OIDC/OAuth 2.0, SCIM, LDAP/AD, and RBAC/ABAC design.
▪ Understanding of privileged access management concepts and how PAM (CyberArk, BeyondTrust, Delinea) integrates with IGA.
GOOD TO HAVE
▪ Platform certifications (SailPoint Certified Professional, Okta Certified Consultant/Administrator, Ping certifications).
▪ Exposure to workload identity and Zero Trust architectures — service accounts, secrets management, and machine identity at data-center/cloud scale.
▪ BFSI delivery experience and familiarity with RBI/SEBI supervisory interactions.
Pay: ₹600,000.00 - ₹2,000,000.00 per year
Experience:
- Identity & access management: 4 years (Preferred)
Work Location: Hybrid remote in Hyderabad, Telangana (Hyderabad, Hyderabad District)