
Senior Analyst, Identity Governance & Priviliged Access Management
Connor, Clark & Lunn Financial Group (CCLFG), one of Canada’s leading asset managers, is seeking a Senior Analyst, Identity Governance & Privileged Access Management (IGA/PAM) to join our Center of Excellence (CoE) – Information Security in Gurugram.
The Information Security team is responsible for securing and governing access to critical systems and data across the organization. This role will lead key initiatives related to Identity Governance and Administration (IGA), Privileged Access Management (PAM), user lifecycle management, access governance, and identity security modernization. If you are passionate about reducing identity-related risk, implementing scalable access controls, and driving improvements to identity security processes, this may be the right opportunity for you. The successful candidate will collaborate with teams across Canada and India and play a key role in the ongoing implementation and operation of the organization's IAM program and reporting to the Information Security Manager based in Gurugram.
What You Will Do
Identity Governance and Administration
- Lead the implementation, administration, operation, and continuous improvement of the Saviynt Identity Cloud platform, including application onboarding, connector integration, configuration, and platform health monitoring.
- Design, implement, and maintain role-based and attribute-based access control models (RBAC and ABAC), access governance standards, and entitlement structures.
- Develop and maintain automated Joiner, Mover, and Leaver (JML) workflows that provision, modify, and deprovision access based on HR, directory, and other authoritative system events.
- Transition manual User Access Review (UAR) and certification campaigns to automated, periodic, and event-driven processes.
- Coordinate access reviews, entitlement certifications, and remediation activities, ensuring findings are tracked to closure and supported by audit-ready evidence.
- Build and optimize access request workflows, approval routing, and rules-based provisioning processes to reduce manual effort, prevent access creep, and improve the user experience.
- Identify and support the remediation of excessive privileges, orphaned accounts, inappropriate entitlements, Segregation of Duties (SoD) conflicts, and other identity-related risks.
- Integrate the IGA platform with HR systems, directories, cloud platforms, SaaS applications, and adjacent identity controls, including Privileged Access Management (PAM), Single Sign-On (SSO), and multifactor authentication (MFA).
- Troubleshoot identity workflows, provisioning processes, connector integrations, and platform configuration issues.
- Identify opportunities to improve IAM processes through automation, workflow optimization, analytics, and responsible use of AI.
Privileged Access Management
- Administer, operate, and expand CyberArk/Idira Privileged Access Management capabilities, including privileged account discovery, onboarding, credential management, access workflows, and policy enforcement.
- Collaborate with infrastructure, application, cloud, and security teams to onboard privileged accounts, applications, and technology platforms into CyberArk.
- Monitor privileged access activity and investigate access-related security events, anomalous behaviour, and policy violations.
- Support the implementation and ongoing improvement of privileged access controls aligned with least privilege, Zero Trust, and regulatory requirements.
- Identify unmanaged, shared, dormant, or high-risk privileged accounts and coordinate their remediation.
- Support the integration of CyberArk with identity governance, directory, cloud, and security-monitoring platforms.
Governance, Reporting, and Advisory
- Develop metrics, dashboards, and reports covering identity governance, access certifications, JML performance, privileged account coverage, policy compliance, and remediation status.
- Produce documentation and evidence to support internal audits, external audits, risk assessments, and regulatory reviews.
- Act as a subject-matter expert and provide guidance to technical and business teams on identity security, access governance, and privileged access management best practices.
- Partner with business stakeholders, application owners, technology teams, Risk, Compliance, and Internal Audit to implement sustainable identity controls.
- Lead identity security initiatives, drive process improvements, and contribute to the evolution of the organization’s IAM governance framework.
What You Bring
- Five or more years of relevant experience in Identity and Governance Administration, cybersecurity, or information security.
- Hands-on experience implementing or administering an IGA platform, preferably Saviynt Identity Cloud.
- Demonstrated experience designing and automating Joiner, Mover, and Leaver processes and managing User Access Review and certification campaigns in a production environment.
- Strong understanding of Identity Governance and Administration, Privileged Access Management, RBAC, ABAC, Segregation of Duties, least privilege, and Zero Trust principles.
- Experience with user provisioning and deprovisioning, entitlement management, access requests, access certifications, role engineering, and application onboarding.
- Experience administering or supporting CyberArk PAM.
- Experience integrating IGA platforms with HR systems, directories such as Microsoft Entra ID, Active Directory, and LDAP, and cloud and SaaS applications through connectors and APIs.
- Experience with identity technologies such as Saviynt, CyberArk, Microsoft Entra ID, Active Directory, AWS IAM, SSO, and MFA.
- Working knowledge of REST and SOAP APIs and experience using scripting or automation tools. PowerShell experience is considered an asset.
- Familiarity with security and compliance frameworks relevant to a regulated financial-services environment, including NIST, ISO 27001, CIS Controls, SOC 1, and Zero Trust architectures.
- Strong analytical and problem-solving skills, with the ability to investigate complex identity, entitlement, workflow, and integration issues.
- Strong written and verbal communication skills, with the ability to work effectively with technical teams, business stakeholders, application owners, auditors, and senior leaders.
- Demonstrated ability to lead initiatives, manage competing priorities, drive process improvements, and work independently in a fast-paced environment.
- Relevant Saviynt, CyberArk, Microsoft, cloud, or identity security certifications are considered strong assets.
Our offices currently operate on a hybrid model with a combination of in office and remote working days throughout the week – this role requires 3 days/week working in our Gurugram office.
#LI-HYBRID #LI-MP1
For a closer look at how you can build your career with us, we invite you to explore cclgroup.com.
CC&L Financial Group is committed to creating a diverse and inclusive environment and is proud to be an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to gender, ethnicity, religion, sexual orientation or expression, disability, or age.
Your application will be reviewed by a member of the hiring team - AI is not used in the screening, assessment or selection of applications at this time.
Apply for this job
*
indicates a required field