Iam Team Leader
Indexed description
Our secret?
A team that blends talent, creativity, and experience to deliver robust, scalable, and tailored solutions.We're not just tech experts — we're partners who support our clients' transformation, anticipate trends, and drive their evolution.
Flexibility, innovation, and a forward-thinking mindset are part of our DNA.We're hiring:IAM Team Leader – Hybrid - (Lisbon 3x) M/FResponsibilities:- Lead and manage the Identity and Access Management (IAM) team, including shift planning for 24x7 IAM engineers, workload distribution, performance reviews, coaching, and career development.
- Design and govern the end-to-end IAM architecture, including Active Directory Domain Services (AD DS) domain structure, FSMO roles, replication topology, Group Policy, DNS/DHCP integration, and forest trust relationships.
- Architect and oversee Active Directory Federation Services (AD FS), Single Sign-On (SSO) configurations, and trust relationships with external identity providers.
- Design and maintain the Active Directory Certificate Services (AD CS/PKI) architecture, including Certification Authority (CA) hierarchy, certificate templates, and auto-enrollment policies.
- Govern the Microsoft Entra ID architecture, including identity lifecycle management, Conditional Access policies, MFA and passwordless authentication strategies, SSO integrations, external identities (B2B/B2C), and SCIM automation.
- Define Identity Governance frameworks, including Privileged Identity Management (PIM) role lifecycle, Access Review schedules, access assignment policies, and privileged identity protection standards.
- Oversee the Privileged Access Management (PAM) architecture and integrations with CyberArk and SailPoint, ensuring least-privilege enforcement and privileged session monitoring.
- Lead identity security initiatives, including Identity Protection signals, risk-based access policies, threat correlation with the Security Operations Center (SOC), and audit evidence preparation.
- Conduct architecture reviews, capacity planning, and lifecycle governance across the entire IAM infrastructure.
- Act as the highest technical escalation point for complex identity-related incidents that cannot be resolved by IAM or PAM teams.
- Define and maintain automation frameworks using PowerShell and Python for identity lifecycle operations, compliance validation, and drift detection.
- Coordinate IAM workflow orchestration through ServiceNow, ensuring that Change, Request, Incident, and lifecycle processes are automated, auditable, and compliant.
- Produce architecture documentation, technical design decisions, compliance reports, and governance documentation for internal teams and customers.
- Support recruitment, onboarding, and training of new IAM team members.Mandatory Requirements:- Minimum of 7 years of hands-on experience in Identity and Access Management, including at least 2 years in a team leadership, architecture, or supervisory role.
- Microsoft Certified: Identity and Access Administrator Associate certification (or equivalent).
- Expert knowledge of Active Directory (AD DS, AD FS, and AD CS), Kerberos, LDAP, and Group Policy.
- Extensive experience with Microsoft Entra ID (Azure AD), Conditional Access, Privileged Identity Management (PIM), MFA/Passwordless, Single Sign-On (SSO), and identity governance.
- Strong understanding of authentication protocols, including SAML, OAuth 2.0, OpenID Connect (OIDC), and RADIUS.
- Experience with CyberArk Privileged Access Management and SailPoint identity governance platforms.
- Proven experience designing and governing Public Key Infrastructure (PKI) architectures and digital certificate services.
- Strong scripting and automation skills using PowerShell and Python.
- Familiarity with ServiceNow, including Incident, Change, Request, and CMDB modules.
- Excellent analytical and structured problem-solving skills.
- Strong written and verbal communication skills in English (B2 level or above), with the ability to interact with customers and produce governance reports.
- Proven experience managing shift-based teams and coordinating distributed teams across multiple time zones.Nice to Have:- Microsoft Certified: Security, Compliance, and Identity Fundamentals or Microsoft Cybersecurity Architect Expert certification.
- Previous experience in Managed Service Provider (MSP) environments or the financial services sector.Experience automating identity lifecycle processes using SCIM and API integrations.
- Knowledge of regulatory frameworks such as DORA, FCA, or PRA.
- Experience designing and implementing Zero Trust architectures.
- Familiarity with BeyondTrust or other Privileged Access Management (PAM) platforms in addition to CyberArk.
- Knowledge of Active Directory Domain Services (AD DS) decommissioning strategies and cloud identity migration.What we offer:- A personalized onboarding experience that welcomes and supports you throughout your journey.
- Regular and constructive feedback to boost your growth and development.
- A dynamic project with a prestigious client.
- A competitive salary package, aligned with your experience and skills.
- Career development opportunities through ambitious and innovative tech projects.
- A collaborative culture that values creativity and individual progress.
- Access to exclusive discounts in a wide network of partners, including health, wellness, travel, culture, gastronomy, leisure and much more.
- Team-building events and initiatives that create memorable shared experiences.Salary Range: ******€ - ******€ Gross Annual + BenefitsTo apply, just send your updated CV with the reference RS/IAM/C to: ******#J-*****-Ljbffr
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search