Back to jobs
New

Security Engineer III (~Senior Identity Security Engineer)

Gurugram, India

At Anaplan, we are a team of innovators focused on optimizing business decision-making through our leading AI-infused scenario planning and analysis platform so our customers can outpace their competition and the market.

What unites Anaplanners across teams and geographies is our collective commitment to our customers’ success and to our Winning Culture.

Our customers rank among the who’s who in the Fortune 50. Coca-Cola, LinkedIn, Adobe, LVMH and Bayer are just a few of the 2,400+ global companies who rely on our best-in-class platform.

Our Winning Culture is the engine that drives our teams of innovators. We champion diversity of thought and ideas, we behave like leaders regardless of title, we are committed to achieving ambitious goals, and we love celebrating our wins – big and small.

Supported by operating principles of being strategy-led, values-based and disciplined in execution, you’ll be inspired, connected, developed and rewarded here. Everything that makes you unique is welcome; join us and let’s build what’s next - together!

What you’ll be doing:

As a Senior Identity Security Engineer, you will be a key hands-on contributor to Anaplan’s identity security function. Working as part of a collaborative security team, you will administer and mature our IGA capability, contribute to the build-out of our Privileged Access Management programme, and help shape the governance of non-human and AI agent identities as part of our broader Zero Trust strategy. Your core responsibilities will be to:

 

  • IGA Platform Administration: Be a key contributor to the day-to-day administration and ongoing development of Anaplan’s Identity Governance and Administration platform (currently SailPoint). This includes supporting the full identity lifecycle (joiner, mover, leaver), configuring and maintaining application connectors, building and refining role models, and running access certification campaigns to ensure least-privilege access across the organisation.
  • PAM Programme Build-Out: Play a key role in the evaluation, selection, and initial implementation of Anaplan’s Privileged Access Management capability. Help define requirements, assess tooling options, and work with cross-functional stakeholders to design and deploy a PAM solution covering privileged account discovery and vaulting, just-in-time (JIT) access, session monitoring, and credential rotation.
  • Non-Human Identity (NHI) Lifecycle Management: Contribute to the development and implementation of governance frameworks for non-human identities across the enterprise, including service accounts, API keys, secrets, certificates, and OAuth tokens. Ensure all NHI are inventoried, governed, and subject to appropriate lifecycle controls, integrating with secrets management solutions where applicable.
  • AI Agent Identity & Security: Be a key technical contributor to identity security for AI agents and automated workflows, ensuring appropriate scoping, lifecycle management, and least-privilege access models are applied. Help develop and enforce policies governing how AI agents authenticate, authorise, and interact with Anaplan’s systems and data.
  • Identity Automation & Engineering: Build and maintain automation to streamline identity processes, including provisioning and de-provisioning workflows, access request fulfilment, and lifecycle rule development. Contribute scripts, integrations, and tooling that reduce manual effort and improve accuracy and consistency across identity operations.
  • Access Governance & Compliance: Support access review and certification processes, SoD (Separation of Duties) policy definition and enforcement, and identity-related audit reporting. Contribute to Anaplan’s compliance programmes (e.g. SOC 2, ISO 27001) by ensuring identity controls are well-documented, consistently applied, and evidenced for audit purposes.
  • Identity Architecture & Strategy: Contribute to the evolution of Anaplan’s identity security architecture, applying Zero Trust principles and advocating for least-privilege and just-in-time access across cloud and on-premises environments. Engage with engineering and platform teams to embed identity security requirements into new and existing systems.
  • Stakeholder Collaboration: Work closely with HR, IT, Engineering, and Security teams to define and maintain access policies, onboarding and offboarding processes, and role-based access models. Communicate identity risks, control gaps, and remediation plans clearly to both technical and non-technical audiences.

What you’ll bring to the role:

We are looking for an experienced identity security practitioner with deep hands-on IGA expertise and a strong foundation across the broader identity and access management discipline. You will bring:

 

  • IGA Platform Expertise: Demonstrated hands-on experience administering an enterprise IGA platform, with strong preference for SailPoint (IdentityNow or IdentityIQ). Experience should include identity lifecycle management, access certifications, connector configuration, role management, and lifecycle rule development. Familiarity with additional IGA platforms (e.g. Saviynt, Omada, One Identity) is highly desirable, given our intent to maintain platform-agnostic capability.
  • PAM Knowledge & Capability Building: Solid understanding of Privileged Access Management concepts and technologies, including privileged account vaulting, session recording, JIT access, and credential rotation. Prior experience evaluating or implementing a PAM solution is a strong advantage; candidates who have contributed to a PAM programme build from the ground up are particularly sought after.
  • Non-Human Identity Management: Experience governing NHI at scale, including service accounts, API keys, OAuth/OIDC tokens, certificates, and secrets. Familiarity with enterprise secrets management platforms (e.g. HashiCorp Vault, AWS Secrets Manager, Azure Key Vault, CyberArk Conjur) and an understanding of the unique risks associated with unmanaged or over-privileged NHI.
  • AI Agent & Agentic Workflow Identity: Understanding of the identity and access challenges posed by AI agents and automated systems, including how to scope, govern, and lifecycle-manage machine identities operating within or on behalf of AI-driven workflows. Experience in this area is emerging and will be valued highly.
  • Identity Protocols & Standards: Strong working knowledge of core identity protocols and standards including SAML 2.0, OAuth 2.0, OIDC, SCIM, LDAP, and Kerberos, and their practical application in hybrid enterprise environments.
  • Cloud IAM: Hands-on experience with cloud IAM platforms, particularly AWS IAM, Microsoft Entra ID (formerly Azure AD), and/or GCP IAM, including policy design, role management, and Privileged Identity Management (PIM) capabilities.
  • Scripting & Automation: Proficiency in one or more scripting or programming languages commonly used in identity automation (e.g. Python, PowerShell, Java/BeanShell for SailPoint rule development). Ability to build integrations and workflows that reduce manual identity operations.
  • Security Frameworks & Compliance: Familiarity with identity-relevant security frameworks and compliance standards (e.g. NIST SP 800-63, NIST CSF, ISO 27001, SOC 2), and an understanding of how IGA and PAM controls map to audit and regulatory requirements.

Communication & Collaboration: Strong ability to translate complex identity security concepts for non-technical stakeholders, and to work cross-functionally across HR, IT, Engineering, and Security to deliver identity outcomes. Clear documentation skills are essential

Our Commitment to Diversity, Equity, Inclusion and Belonging (DEIB)

We believe attracting and retaining the best talent and fostering an inclusive culture strengthens our business. DEIB improves our workforce, enhances trust with our partners and customers, and drives business success. Build your career in a place where diversity, equity, inclusion and belonging aren’t just words on paper – this is what drives our innovation, it’s how we connect, and it contributes to what makes us a market leader. We believe in a hiring and working environment where all people are respected and valued, regardless of gender identity or expression, sexual orientation, religion, ethnicity, age, neurodiversity, disability status, citizenship, or any other aspect which makes people unique. We hire you for who you are, and we want you to bring your authentic self to work every day! 

We will ensure that individuals with disabilities are provided reasonable accommodation to participate in the job application or interview process, perform essential job functions, and receive equitable benefits and all privileges of employment. Please contact us to request accommodation.  

Fraud Recruitment Disclaimer  

It has come to our attention that fraudulent and fictitious job opportunities are being circulated on the Internet. Prospective candidates are being contacted by certain individuals, mainly through telephone calls, emails and correspondence, claiming they are representatives of Anaplan. The main purpose of these correspondences and announcements is to obtain privileged information from individuals.  

Anaplan does not:  

  • Extend offers to candidates without an extensive interview process with a member of our recruitment team and a hiring manager via video or in person.   
  • Send job offers via email. All offers are first extended verbally by a member of our internal recruitment team whenever possible and then followed up via written communication.  

All emails from Anaplan would come from an @anaplan.com email address. Should you have any doubts about the authenticity of an email, letter or telephone communication purportedly from, for, or on behalf of Anaplan, please send an email to people@anaplan.com before taking any further action in relation to the correspondence.   

Candidate data processed during our recruitment activities is handled in accordance with our Candidate Privacy Notice. This may include the use of artificial intelligence or automated tools to assist our team in evaluating qualifications.

 

Apply for this job

*

indicates a required field

Phone
Resume/CV*

Accepted file types: pdf, doc, docx, txt, rtf


Select...
Select...

Voluntary Self-Identification

For government reporting purposes, we ask candidates to respond to the below self-identification survey. Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiring process or thereafter. Any information that you do provide will be recorded and maintained in a confidential file.

As set forth in Anaplan’s Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law.

Select...
Select...
Race & Ethnicity Definitions

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection. As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measure the effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categories is as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability.

A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Select...

Voluntary Self-Identification of Disability

Form CC-305
Page 1 of 1
OMB Control Number 1250-0005
Expires 04/30/2026

Why are you being asked to complete this form?

We are a federal contractor or subcontractor. The law requires us to provide equal employment opportunity to qualified people with disabilities. We have a goal of having at least 7% of our workers as people with disabilities. The law says we must measure our progress towards this goal. To do this, we must ask applicants and employees if they have a disability or have ever had one. People can become disabled, so we need to ask this question at least every five years.

Completing this form is voluntary, and we hope that you will choose to do so. Your answer is confidential. No one who makes hiring decisions will see it. Your decision to complete the form and your answer will not harm you in any way. If you want to learn more about the law or this form, visit the U.S. Department of Labor’s Office of Federal Contract Compliance Programs (OFCCP) website at www.dol.gov/ofccp.

How do you know if you have a disability?

A disability is a condition that substantially limits one or more of your “major life activities.” If you have or have ever had such a condition, you are a person with a disability. Disabilities include, but are not limited to:

  • Alcohol or other substance use disorder (not currently using drugs illegally)
  • Autoimmune disorder, for example, lupus, fibromyalgia, rheumatoid arthritis, HIV/AIDS
  • Blind or low vision
  • Cancer (past or present)
  • Cardiovascular or heart disease
  • Celiac disease
  • Cerebral palsy
  • Deaf or serious difficulty hearing
  • Diabetes
  • Disfigurement, for example, disfigurement caused by burns, wounds, accidents, or congenital disorders
  • Epilepsy or other seizure disorder
  • Gastrointestinal disorders, for example, Crohn's Disease, irritable bowel syndrome
  • Intellectual or developmental disability
  • Mental health conditions, for example, depression, bipolar disorder, anxiety disorder, schizophrenia, PTSD
  • Missing limbs or partially missing limbs
  • Mobility impairment, benefiting from the use of a wheelchair, scooter, walker, leg brace(s) and/or other supports
  • Nervous system condition, for example, migraine headaches, Parkinson’s disease, multiple sclerosis (MS)
  • Neurodivergence, for example, attention-deficit/hyperactivity disorder (ADHD), autism spectrum disorder, dyslexia, dyspraxia, other learning disabilities
  • Partial or complete paralysis (any cause)
  • Pulmonary or respiratory conditions, for example, tuberculosis, asthma, emphysema
  • Short stature (dwarfism)
  • Traumatic brain injury
Select...

PUBLIC BURDEN STATEMENT: According to the Paperwork Reduction Act of 1995 no persons are required to respond to a collection of information unless such collection displays a valid OMB control number. This survey should take about 5 minutes to complete.