JobHabor

Identity Access Management Operations and Engineering Manager

StoneX Group
Location
Bangalore, India
Workplace
Employment
Full Time
Salary
Apply on the employer’s site

Posted 2y ago

Overview

Connecting clients to markets – and talent to opportunity.With 5,400+ employees and over 80,000 institutional, commercial, and payments clients, we operate from more than 80 offices spread across six continents. As a Fortune 100, Nasdaq-listed provider, we connect clients to the global markets – focusing on innovation, human connection, and providing world-class products and services to all types of investors.Whether you want to forge a career connecting our retail clients to potential trading opportunities, or ingrain yourself in the world of institutional investing, StoneX Group is made up of four business segments that offer endless potential for progression and growth.

Business Segment Overview

Corporate

Engage in a deep variety of business-critical activities that keep our company running efficiently. From strategic marketing and financial management to human resources and operational oversight, you’ll have the opportunity to optimize processes and implement game-changing policies.

Position Purpose

As Identity Access Management Operations and Engineering Manager for IT Risk and Security, you will lead an IAM Operations and Identity Engineering function within StoneX, owning both the day-to-day identity service the firm depends on and the engineering of the platforms that deliver it. The estate runs core identity platforms such as Microsoft Entra ID with Active Directory, and Okta. Around them sit enterprise PKI, privileged access management, modern authentication and identity governance tooling, alongside legacy platforms now being retired. The ideal candidate will have experience working in a regulated financial environment and is a highly skilled, experienced and motivated leader willing to drive and grow our identity function across a globally distributed team.

Responsibilities

Primary duties will include

  • Own the identity service catalogue end to end - joiner, mover and leaver processing, access request, entitlement and group administration, privileged account issuance, certificate services and application onboarding and the service levels each commitment carries.
  • Set the engineering and operations roadmap and act as technical design authority across both core identity platforms; Entra ID with hybrid directory services and Okta as well as identity governance and administration, privileged access management, PKI and certificate lifecycle, federation and single sign-on, and modern authentication.
  • Run the operational disciplines behind the service: incident and problem management for identity outages, change control, capacity and availability planning, and a documented escalation and on-call model that holds across time zones.
  • Design, implement and maintain IAM policies, procedures and standards to ensure the confidentiality, integrity and availability of sensitive data and resources.
  • Manage and lead a team (1-3) of identity engineers and analysts and building coverage so that every platform has more than one engineer, in more than one region, who can safely operate it.
  • Drive standing privilege down across the estate: run the access certification and recertification cycle, enforce segregation of duties and least privilege, eliminate orphaned and dormant accounts, and bring service, workload and other non-human identities under the same lifecycle discipline as people.
  • Act as identity manager you will be working with the team and supporting internal audit, external audit and client or scheme assessments including SWIFT CSP, inc. producing evidence on request, owning remediation actions and closing findings to agreed dates.
  • Automate the routine work out of the service: provisioning and deprovisioning driven from authoritative HR sources, policy and role-based entitlement in place of ticket-by-ticket approval and reporting instrumented so identity risk is visible without a manual data pull.
  • Own identity data quality and metrics, account ownership, lifecycle state, entitlement mapping and application registration as the foundation every downstream control, report and detection depends on.
  • Lead directory and tenant consolidation and legacy platform decommissioning, including the absorption of acquired identity estates onto the strategic Entra ID and Okta platforms, working directly with the application teams that depend on those platforms rather than routing every migration through the identity team.
  • Collaborate with cross-functional teams - security architecture, security operations, enterprise IT, HR, compliance and the business to assess IAM requirements and develop solutions that meet business needs.
  • Manage external partners and vendors against their commitments, and contribute to forecasting and planning for identity licensing, tooling and headcount.
  • Maintain IAM process documentation, including end-user guidance, runbooks and team processes and procedures, to a standard that allows work to move between regions without loss.

Qualifications

To land this role you will need

  • This individual must be capable of working with internal and customer-facing teams to facilitate process improvement and customer support resulting in an enhanced security posture, reduction in risk and improvement in end-user experience. Excellent communication, strong organizational skills and attention to detail are essential.
  • 10+ years of overall professional experience, including at least 6 years in identity and access management and 3+ years leading and directly managing an IAM team, with accountability for both a production service and an engineering backlog; experience in financial services a plus.
  • Proven experience designing, implementing and managing complex IAM processes and solutions within large organizations.
  • Deep, current, hands-on knowledge of both core platforms. Microsoft Entra ID and Active Directory in a hybrid estate — tenant and forest design, synchronisation, conditional access, privileged role management and entitlement models. Okta — policy architecture, authentication journeys, application integration, lifecycle management and federation at scale.
  • Production delivery experience across at least three of: identity governance and administration tooling, privileged access management such as CyberArk, PKI and certificate lifecycle management, federation and single sign-on, and multi-factor or passwordless authentication.
  • Knowledge and implementation of key security concepts such as RBAC, zero trust, identity lifecycle automation, least privilege and identity governance, together with command of the underlying protocols SAML 2.0, OIDC, OAuth 2.0, SCIM, Kerberos and LDAP.
  • Automation and scripting ability sufficient to lead engineers credibly e.g. PowerShell, Microsoft Graph and the Okta management APIs with practical use of source control, pipelines and configuration-as-code applied to identity change.
  • Demonstrated operational management discipline: service level definition and reporting, incident, problem and change management, and oversight of vendors or managed service providers.
  • Direct experience owning identity controls through audit - preparing evidence, defending design decisions to auditors or regulators, and closing findings.
  • Understanding of a broad range of general information security domains, including networking, cybersecurity, governance and risk, and cloud.
  • Strong leadership skills with a track record of successfully leading distributed and cross-functional teams across time zones, including offshore or GCC-based staff.
  • Excellent communication and interpersonal skills to effectively collaborate with technical and non-technical stakeholders.

What makes you stand out

  • You have an operations mindset and an engineer's instinct; you see an inefficient process and immediately think of how to automate it away rather than staff it.
  • You thrive in a fast-paced, collaborative environment and are comfortable juggling a live service and a delivery roadmap at the same time.
  • You are equally comfortable in both platforms and can reason about where a capability belongs — Entra ID or Okta — rather than defaulting to the one you know best.
  • You build people as deliberately as you build platforms, and you measure your team by the cover and capability it has, not by the hours it works.
  • You have experience in a Zero Trust program, or with securing non-human identities including service accounts, workload identities and emerging agentic and AI workloads.

Education / Certification Requirements

  • Bachelor's or master's degree in computer science, information security or a related field (or equivalent experience).
  • Microsoft Certified: Identity and Access Administrator Associate (SC-300) preferred.
  • Okta Certified Professional or Okta Certified Administrator preferred.
  • CISSP, CISM, CyberArk Defender or Sentry, or an equivalent identity governance credential preferred; ITIL foundation or equivalent service management training is a plus.

Working environment

  • 4 days' work from office
  • Working hours aligned to India business hours, with overlap into CET / BST.
  • Team distributed across UK, US and Latam locations; participation in an escalation and on-call rotation should be expected.
  • Travel requirements, for leadership meetings and conferences.

Skills

  • Segment
  • IAM
  • Microsoft Entra ID
  • Active Directory
  • Okta
  • PKI
  • Swift
  • RBAC
  • Zero Trust
  • SAML
  • OpenID Connect
  • OAuth 2.0
  • SCIM
  • Kerberos
  • LDAP
  • PowerShell
  • CISSP
  • Sentry

More jobs at StoneX Group

All 52

Similar roles