Security Track Consultant

HEXAWARE
Onsite

About The Position

Hexaware is a dynamic and innovative IT organization committed to delivering cutting-edge solutions to our clients worldwide. We pride ourselves on fostering a collaborative and inclusive work environment where every team member is valued and empowered to succeed. Hexaware provides access to a vast array of tools that enhance, revolutionize, and advance professional profile. We complete the circle with excellent growth opportunities, chances to collaborate with highly visible customers, chances to work alongside bright brains, and the perfect work-life balance. With an ever-expanding portfolio of capabilities, we delve deep into and identify the source of our motivation. Although technology is at the core of our solutions, it is still the people and their passion that fuel Hexaware’s commitment towards creating smiles. At Hexaware we encourage to challenge oneself to achieve full potential and propel growth. We trust and empower to disrupt the status quo and innovate for a better future. We encourage an open and inspiring culture that fosters learning and brings talented, passionate, and caring people together. We are always interested in, and want to support, the professional and personal you. We offer a wide array of programs to help expand skills and supercharge careers. We help discover passion—the driving force that makes one smile and innovate, create, and make a difference every day.

Requirements

  • 10+ years of experience
  • Own and lead day-to-day operations for enterprise key and certificate lifecycle management, ensuring secure, reliable, and compliant handling of cryptographic keys, certificates, secrets, and related IAM integrations.
  • Drive operational excellence, incident/problem management, automation, and continuous improvement across keychain services supporting critical business applications.
  • Administer PingFederate, PingAccess, PingDirectory, and PingID/PingOne (as applicable).
  • Onboard and maintain OIDC/SAML integrations: configure IdP/SP connections, manage metadata, certificates, and key rotation.
  • Operate SailPoint platforms: IdentityIQ and/or IdentityNow (Identity Security Cloud), including task scheduling, health checks, and upgrades.
  • Application onboarding and connector operations (e.g., AD/Entra ID, LDAP, Azure, Workday/SuccessFactors, ServiceNow, SAP, Oracle, databases, SaaS apps).
  • Maintain and tune provisioning policies, entitlements, SoD policies/violations, and exception handling.
  • Develop and support SailPoint rules/workflows and automation: IdentityIQ: BeanShell/Java rules, lifecycle manager workflows, task definitions, plugin/config promotion. IdentityNow: sources, transforms, rules, lifecycle events, connectors, sp-config export/import, REST APIs.
  • Enforce least privilege, SoD, and Zero Trust-aligned controls across SSO and IGA.
  • Manage certificate, key, and secret lifecycles and ensure secure configuration baselines.
  • Automate routine tasks (app onboarding, cert renewals, config backups, campaign setups, rotation checks) using platform APIs and scripts.
  • Implement configuration-as-code and environment promotion where supported (Ping and SailPoint).

Responsibilities

  • Lead the IAM Keychain Operations team, providing direction, coaching, performance management, and workload prioritization.
  • Own operational KPIs/SLAs/SLOs for key and certificate services (availability, turnaround time, renewal success rate, incident reduction).
  • Establish and maintain runbooks, SOPs, on-call rotations, and escalation paths.
  • Own day-to-day operations for Ping Identity and SailPoint platforms, ensuring availability, performance, and security SLAs.
  • Proactively monitor platform health, perform routine checks, capacity planning, backups, and schedule/execute maintenance, patching, and upgrades.
  • Triage and resolve incidents, service requests, and problems; lead root cause analysis and implement permanent fixes.
  • Administer PingFederate, PingAccess, PingDirectory, and PingID/PingOne (as applicable).
  • Onboard and maintain OIDC/SAML integrations: configure IdP/SP connections, manage metadata, certificates, and key rotation.
  • Operate SailPoint platforms: IdentityIQ and/or IdentityNow (Identity Security Cloud), including task scheduling, health checks, and upgrades.
  • Application onboarding and connector operations (e.g., AD/Entra ID, LDAP, Azure, Workday/SuccessFactors, ServiceNow, SAP, Oracle, databases, SaaS apps).
  • Maintain and tune provisioning policies, entitlements, SoD policies/violations, and exception handling.
  • Develop and support SailPoint rules/workflows and automation: IdentityIQ: BeanShell/Java rules, lifecycle manager workflows, task definitions, plugin/config promotion. IdentityNow: sources, transforms, rules, lifecycle events, connectors, sp-config export/import, REST APIs.
  • Enforce least privilege, SoD, and Zero Trust-aligned controls across SSO and IGA.
  • Manage certificate, key, and secret lifecycles and ensure secure configuration baselines.
  • Automate routine tasks (app onboarding, cert renewals, config backups, campaign setups, rotation checks) using platform APIs and scripts.
  • Implement configuration-as-code and environment promotion where supported (Ping and SailPoint).
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service