Work Location: Pune or Chennai
Shift: 24x7 Rotation Shifts
Position Summary
This is a technical role requiring prior experience in Identity and Access Management (IAM), cybersecurity operations, and enterprise security practices. The Security Analyst II is responsible for supporting and troubleshooting identity platforms, monitoring and investigating security events, enforcing security controls, and assisting with operational and compliance activities across the enterprise.
The successful candidate will demonstrate strong analytical and troubleshooting skills while working independently and collaboratively within a global cybersecurity team.
Key Responsibilities
- Respond to and resolve IAM incidents and service tickets within defined SLAs while following established operational procedures.
- Perform administration, troubleshooting, and operational support across IAM platforms including Active Directory, Microsoft Entra ID (Azure AD), Single Sign-On (SSO), Multi-Factor Authentication (MFA), and identity lifecycle management processes.
- Process and troubleshoot user onboarding, offboarding, provisioning, de-provisioning, and access modification requests across enterprise systems.
- Support role-based access control (RBAC), least-privilege enforcement, and privileged access management processes.
- Work closely with IT support teams, application owners, and business stakeholders to investigate and resolve access-related issues.
- Monitor, triage, and investigate alerts generated by SIEM, EDR, IAM, cloud, and infrastructure security platforms.
- Correlate events across multiple security tools to establish incident context and identify potential security concerns.
- Perform analysis using logs, IP addresses, domains, URLs, hashes, user activity, and threat intelligence sources.
- Investigate security events including suspicious login activity, MFA issues, phishing attempts, unauthorized access attempts, privilege escalation activity, malware alerts, and endpoint security events.
- Identify false positives and distinguish them from legitimate security incidents.
- Escalate complex incidents and technical issues to senior engineers and subject matter experts as appropriate.
- Participate in access reviews, certification campaigns, audits, and compliance evidence collection activities.
- Assist with implementation and support of IAM security controls and automation initiatives.
- Contribute to the creation and maintenance of operational runbooks, knowledge articles, and process documentation.
- Identify recurring issues and recommend process improvements and automation opportunities.
- Participate in shift handovers and maintain clear operational communication.
- Mentor junior analysts on operational procedures, troubleshooting techniques, and security best practices.
- Maintain accurate ticket documentation and timely updates throughout the lifecycle of incidents and service requests.
Required Qualifications
- Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field.
- 4-6 years of hands-on experience in cybersecurity, Identity and Access Management, security operations, or related IT disciplines.
- Experience supporting enterprise IAM platforms and identity lifecycle management processes.
- Experience with Microsoft Entra ID (Azure AD), Active Directory, authentication services, and MFA technologies.
- Understanding of user lifecycle management, access control models, RBAC, and identity governance concepts.
- Experience investigating security events and performing analysis across multiple security technologies.
- Working knowledge of SIEM platforms and security event monitoring.
- Familiarity with EDR/XDR platforms such as Microsoft Defender, CrowdStrike, or similar technologies.
- Experience supporting cloud environments, particularly Microsoft Azure.
- Experience with ServiceNow or similar IT Service Management platforms.
- Basic scripting or automation experience using PowerShell, Python, or similar technologies.
- Strong analytical, troubleshooting, and problem-solving skills.
- Strong written and verbal communication skills.
- Ability to independently prioritize and manage multiple operational activities in a fast-paced environment.
Preferred Qualifications
- Experience with Microsoft Sentinel.
- Experience supporting Conditional Access and Identity Governance solutions.
- Experience participating in access certification activities and audit support engagements.
- Experience with security automation initiatives.
- Exposure to AWS identity and access management concepts.
- Industry certifications such as Security+, SC-900, SC-300, AZ-500, CISSP, or equivalent cybersecurity certifications.
Success Factors
The ideal candidate will be capable of independently supporting routine IAM and security operations activities, conducting meaningful investigations, contributing to compliance and audit efforts, assisting with operational improvements, and supporting the organization's cybersecurity and access governance objectives while working within a global 24x7 operational environment.
Our Interview Practices
To maintain a fair and genuine hiring process, we kindly ask that all candidates participate in interviews without the assistance of AI tools or external prompts. Our interview process is designed to assess your individual skills, experiences, and communication style. We value authenticity and want to ensure we’re getting to know you—not a digital assistant. To help maintain this integrity, we ask to remove virtual backgrounds and include in-person interviews in our hiring process. Please note that use of AI-generated responses or third-party support during interviews will be grounds for disqualification from the recruitment process.
Applicants may be required to appear onsite at a Wolters Kluwer office as part of the recruitment process.