HamburgerMenu
hirist

TelioLabs - Systems Engineer - Service Account Provisioning Automation

Teliolabs
5 - 8 Years
Multiple Locations

Posted on: 20/07/2026

Job Description

Timings : 3 pm IST - 10/11 pm IST

Notice Period : Immediate Joiner

Consultants will design, build, and operationalize end-to-end automation solutions that cover the full lifecycle of service accounts from self-service request intake through identity provisioning, secrets management integration, and pipeline-driven enforcement. This role sits at the intersection of platform engineering, DevSecOps, InfoSec and identity & access management (IAM).

Key Responsibilities :

1. Automation & Orchestration :

- Design and implement Ansible playbooks and roles for automated SvcAccount provisioning, rotation, and de-provisioning across on-premises and cloud environments.

- Design and implement Ansible playbooks for automated server provisioning and de-provisioning across on-premises environments.

- Build idempotent automation workflows that integrate with Active Directory / LDAP, PAM vaults (e.g., CyberArk), and downstream identity providers.

- Develop reusable Ansible collections and maintain role-based variable structures for multi-environment deployments.

2. Pipeline Integration :

- Integrate SvcAccount provisioning automation into CI/CD pipelines (Azure DevOps) as enforceable pipeline stages.

- Implement pipeline gates that validate account provisioning state, enforce naming conventions, and trigger approval workflows before account activation.

- Build SARIF-compatible output or audit log artifacts from pipeline runs for downstream security tooling ingestion.

3. Frontend / Self-Service GUI :

- Design and develop a self-service portal or operator dashboard for SvcAccount request submission, status tracking, and approval routing.

- .Net, Angular front-end with RESTful API backend.

- Role-based access control (RBAC) aligned to requestor, approver, and admin personas.

- Integration with ticketing systems (Ivanti Neurons) for request traceability.

- Ensure the GUI surfaces real-time provisioning status and surfaced audit trail from the Ansible automation layer.

4. Security & Compliance :

- Enforce least-privilege principles in all provisioned accounts; apply time-bound and scope-constrained credentials where applicable.

- Align automation outputs with compliance frameworks (SOX, PCI-DSS, NIST) and internal InfoSec policies.

- Coordinate with AppSec and IAM teams to ensure secrets are never stored in source control and are retrieved dynamically via vault integration.

5. Documentation & Enablement :

- Produce runbooks, architecture decision records (ADRs), and operator guides for all delivered automation.

- Conduct knowledge-transfer sessions with client platform and security teams at engagement close-out.

Required Qualifications :

1. Experience :

- 5 - 7 years of hands-on systems engineering experience in enterprise environments.

- Demonstrated history delivering automation at scale in hybrid (on-prem + cloud) environments.

2. Ansible & Infrastructure Automation :

- Proficiency in Ansible (playbooks, roles, collections, Ansible Vault, dynamic inventory).

- Experience with Ansible Automation Platform (AAP) for enterprise scheduling and RBAC-governed execution.

- Experience with Powershell Automation.

- Familiarity with infrastructure-as-code (IaC) principles; Terraform experience a plus.

3. Pipeline & DevSecOps :

- Experience building and maintaining CI/CD pipelines in Azure DevOps, GitHub Actions.

- Understanding of pipeline-as-code patterns; ability to write YAML-based pipeline definitions.

4. Frontend / GUI Development :

- Working proficiency in at least one modern JavaScript framework (Angular).

- Ability to build and consume RESTful APIs (.NET).

- Basic UX sensibility - able to design functional, operator-friendly interfaces without dedicated UX resources.

5. Identity & Access Management :

- Solid understanding of service account lifecycle management concepts.

- Familiarity with Active Directory, LDAP/SAML, and group policy as they relate to service identities.

- Exposure to PAM tooling (CyberArk or similar) is strongly preferred.

Preferred Experience :

- Experience with OpenShift or Kubernetes for containerized automation workloads.

- Familiarity with CyberArk Central Credential Provider (CCP) or Conjur for secrets injection in pipelines.

- Red Hat Certified Engineer (RHCE) or Ansible Automation certification.

- Exposure to ITSM platforms and REST API integration patterns.

- Experience with Backstage or similar Internal Developer Portals (IDPs) for self-service tooling.

info-icon

Did you find something suspicious?

Similar jobs that you might be interested in

Loading chat...