Back to search
Dellent Linkedin · Posted 12d ago

Iam Team Leader

Portugal

Linkedin
Continue to application Add your email once, then Caio opens the original posting.

Indexed description

### IAM Team Leader – Hybrid (Lisbon) M/FWho we are:With over 25 years of experience, Sysmatch is a well-established name in IT Consultancy and Outsourcing, involved in both national and international projects that promote excellence in technology and services.

Our secret?

A team that blends talent, creativity, and experience to deliver robust, scalable, and tailored solutions.We're not just tech experts — we're partners who support our clients' transformation, anticipate trends, and drive their evolution.

Flexibility, innovation, and a forward-thinking mindset are part of our DNA.We're hiring:IAM Team Leader – Hybrid - (Lisbon 3x) M/FResponsibilities:- Lead and manage the Identity and Access Management (IAM) team, including shift planning for 24x7 IAM engineers, workload distribution, performance reviews, coaching, and career development.

  • Design and govern the end-to-end IAM architecture, including Active Directory Domain Services (AD DS) domain structure, FSMO roles, replication topology, Group Policy, DNS/DHCP integration, and forest trust relationships.
  • Architect and oversee Active Directory Federation Services (AD FS), Single Sign-On (SSO) configurations, and trust relationships with external identity providers.
  • Design and maintain the Active Directory Certificate Services (AD CS/PKI) architecture, including Certification Authority (CA) hierarchy, certificate templates, and auto-enrollment policies.
  • Govern the Microsoft Entra ID architecture, including identity lifecycle management, Conditional Access policies, MFA and passwordless authentication strategies, SSO integrations, external identities (B2B/B2C), and SCIM automation.
  • Define Identity Governance frameworks, including Privileged Identity Management (PIM) role lifecycle, Access Review schedules, access assignment policies, and privileged identity protection standards.
  • Oversee the Privileged Access Management (PAM) architecture and integrations with CyberArk and SailPoint, ensuring least-privilege enforcement and privileged session monitoring.
  • Lead identity security initiatives, including Identity Protection signals, risk-based access policies, threat correlation with the Security Operations Center (SOC), and audit evidence preparation.
  • Conduct architecture reviews, capacity planning, and lifecycle governance across the entire IAM infrastructure.
  • Act as the highest technical escalation point for complex identity-related incidents that cannot be resolved by IAM or PAM teams.
  • Define and maintain automation frameworks using PowerShell and Python for identity lifecycle operations, compliance validation, and drift detection.
  • Coordinate IAM workflow orchestration through ServiceNow, ensuring that Change, Request, Incident, and lifecycle processes are automated, auditable, and compliant.
  • Produce architecture documentation, technical design decisions, compliance reports, and governance documentation for internal teams and customers.
  • Support recruitment, onboarding, and training of new IAM team members.Mandatory Requirements:- Minimum of 7 years of hands-on experience in Identity and Access Management, including at least 2 years in a team leadership, architecture, or supervisory role.
  • Microsoft Certified: Identity and Access Administrator Associate certification (or equivalent).
  • Expert knowledge of Active Directory (AD DS, AD FS, and AD CS), Kerberos, LDAP, and Group Policy.
  • Extensive experience with Microsoft Entra ID (Azure AD), Conditional Access, Privileged Identity Management (PIM), MFA/Passwordless, Single Sign-On (SSO), and identity governance.
  • Strong understanding of authentication protocols, including SAML, OAuth 2.0, OpenID Connect (OIDC), and RADIUS.
  • Experience with CyberArk Privileged Access Management and SailPoint identity governance platforms.
  • Proven experience designing and governing Public Key Infrastructure (PKI) architectures and digital certificate services.
  • Strong scripting and automation skills using PowerShell and Python.
  • Familiarity with ServiceNow, including Incident, Change, Request, and CMDB modules.
  • Excellent analytical and structured problem-solving skills.
  • Strong written and verbal communication skills in English (B2 level or above), with the ability to interact with customers and produce governance reports.
  • Proven experience managing shift-based teams and coordinating distributed teams across multiple time zones.Nice to Have:- Microsoft Certified: Security, Compliance, and Identity Fundamentals or Microsoft Cybersecurity Architect Expert certification.
  • Previous experience in Managed Service Provider (MSP) environments or the financial services sector.Experience automating identity lifecycle processes using SCIM and API integrations.
  • Knowledge of regulatory frameworks such as DORA, FCA, or PRA.
  • Experience designing and implementing Zero Trust architectures.
  • Familiarity with BeyondTrust or other Privileged Access Management (PAM) platforms in addition to CyberArk.
  • Knowledge of Active Directory Domain Services (AD DS) decommissioning strategies and cloud identity migration.What we offer:- A personalized onboarding experience that welcomes and supports you throughout your journey.
  • Regular and constructive feedback to boost your growth and development.
  • A dynamic project with a prestigious client.
  • A competitive salary package, aligned with your experience and skills.
  • Career development opportunities through ambitious and innovative tech projects.
  • A collaborative culture that values creativity and individual progress.
  • Access to exclusive discounts in a wide network of partners, including health, wellness, travel, culture, gastronomy, leisure and much more.
  • Team-building events and initiatives that create memorable shared experiences.Salary Range: ******€ - ******€ Gross Annual + BenefitsTo apply, just send your updated CV with the reference RS/IAM/C to: ******#J-*****-Ljbffr
Free. 20 seconds. No password. See every match in this search.

Create a free Caio profile to unlock more results and save your role and location preferences.

Unlock free search
Want help applying to roles like this? Search Caio for free. If repetitive applications get heavy, Managed Job Search adds supervised execution for $99/month.
View Managed Job Search