Posted on: 20/07/2026
Timings : 3 pm IST - 10/11 pm IST
Notice Period : Immediate Joiner
Consultants will design, build, and operationalize end-to-end automation solutions that cover the full lifecycle of service accounts from self-service request intake through identity provisioning, secrets management integration, and pipeline-driven enforcement. This role sits at the intersection of platform engineering, DevSecOps, InfoSec and identity & access management (IAM).
Key Responsibilities :
1. Automation & Orchestration :
- Design and implement Ansible playbooks and roles for automated SvcAccount provisioning, rotation, and de-provisioning across on-premises and cloud environments.
- Design and implement Ansible playbooks for automated server provisioning and de-provisioning across on-premises environments.
- Build idempotent automation workflows that integrate with Active Directory / LDAP, PAM vaults (e.g., CyberArk), and downstream identity providers.
- Develop reusable Ansible collections and maintain role-based variable structures for multi-environment deployments.
2. Pipeline Integration :
- Integrate SvcAccount provisioning automation into CI/CD pipelines (Azure DevOps) as enforceable pipeline stages.
- Implement pipeline gates that validate account provisioning state, enforce naming conventions, and trigger approval workflows before account activation.
- Build SARIF-compatible output or audit log artifacts from pipeline runs for downstream security tooling ingestion.
3. Frontend / Self-Service GUI :
- Design and develop a self-service portal or operator dashboard for SvcAccount request submission, status tracking, and approval routing.
- .Net, Angular front-end with RESTful API backend.
- Role-based access control (RBAC) aligned to requestor, approver, and admin personas.
- Integration with ticketing systems (Ivanti Neurons) for request traceability.
- Ensure the GUI surfaces real-time provisioning status and surfaced audit trail from the Ansible automation layer.
4. Security & Compliance :
- Enforce least-privilege principles in all provisioned accounts; apply time-bound and scope-constrained credentials where applicable.
- Align automation outputs with compliance frameworks (SOX, PCI-DSS, NIST) and internal InfoSec policies.
- Coordinate with AppSec and IAM teams to ensure secrets are never stored in source control and are retrieved dynamically via vault integration.
5. Documentation & Enablement :
- Produce runbooks, architecture decision records (ADRs), and operator guides for all delivered automation.
- Conduct knowledge-transfer sessions with client platform and security teams at engagement close-out.
Required Qualifications :
1. Experience :
- 5 - 7 years of hands-on systems engineering experience in enterprise environments.
- Demonstrated history delivering automation at scale in hybrid (on-prem + cloud) environments.
2. Ansible & Infrastructure Automation :
- Proficiency in Ansible (playbooks, roles, collections, Ansible Vault, dynamic inventory).
- Experience with Ansible Automation Platform (AAP) for enterprise scheduling and RBAC-governed execution.
- Experience with Powershell Automation.
- Familiarity with infrastructure-as-code (IaC) principles; Terraform experience a plus.
3. Pipeline & DevSecOps :
- Experience building and maintaining CI/CD pipelines in Azure DevOps, GitHub Actions.
- Understanding of pipeline-as-code patterns; ability to write YAML-based pipeline definitions.
4. Frontend / GUI Development :
- Working proficiency in at least one modern JavaScript framework (Angular).
- Ability to build and consume RESTful APIs (.NET).
- Basic UX sensibility - able to design functional, operator-friendly interfaces without dedicated UX resources.
5. Identity & Access Management :
- Solid understanding of service account lifecycle management concepts.
- Familiarity with Active Directory, LDAP/SAML, and group policy as they relate to service identities.
- Exposure to PAM tooling (CyberArk or similar) is strongly preferred.
Preferred Experience :
- Experience with OpenShift or Kubernetes for containerized automation workloads.
- Familiarity with CyberArk Central Credential Provider (CCP) or Conjur for secrets injection in pipelines.
- Red Hat Certified Engineer (RHCE) or Ansible Automation certification.
- Exposure to ITSM platforms and REST API integration patterns.
- Experience with Backstage or similar Internal Developer Portals (IDPs) for self-service tooling.
Did you find something suspicious?
Posted by
Posted in
CyberSecurity
Functional Area
IT Security
Job Code
1655682