TRPD-26-04828
Multi-Cloud IAM & Secrets Management Architect (Azure/AWS, CyberArk, Vault)
This role owns assessment and transformation of enterprise secrets management and IAM across Azure, AWS, hybrid/on-prem, Kubernetes and CI/CD. The person will define target-state architecture, standards and governance for secrets storage/rotation/audit, design IAM access models (Entra ID/AWS IAM, federation, workload identity, least privilege), and integrate secrets/IAM with PAM, pipelines, apps, databases, APIs, logging/monitoring and SIEM. Success requires hands-on multi-cloud IAM plus experience with at least two secrets platforms (e.g., Key Vault, AWS Secrets Manager, HashiCorp Vault, CyberArk Conjur) and strong enterprise governance, onboarding and migration support.
Position summary
- Location
- India
- Workplace
- Hybrid
- Employment
- Full Time
- Experience
- Minimum 5 years and Maximum 10 years
Role overview
Why This Role Matters.
This role owns assessment and transformation of enterprise secrets management and IAM across Azure, AWS, hybrid/on-prem, Kubernetes and CI/CD. The person will define target-state architecture, standards and governance for secrets storage/rotation/audit, design IAM access models (Entra ID/AWS IAM, federation, workload identity, least privilege), and integrate secrets/IAM with PAM, pipelines, apps, databases, APIs, logging/monitoring and SIEM. Success requires hands-on multi-cloud IAM plus experience with at least two secrets platforms (e.g., Key Vault, AWS Secrets Manager, HashiCorp Vault, CyberArk Conjur) and strong enterprise governance, onboarding and migration support.
Your Impact
Deliver Enterprise Value
Help organisations solve complex business problems through modern technology, consulting expertise and measurable outcomes.
Collaboration
Work Across Teams
Collaborate with consultants, architects, engineers and client stakeholders throughout the project lifecycle.
Growth
Learn Continuously
Gain exposure to enterprise technologies, certifications, mentoring and real-world project experience.
Career Path
Grow With Ubique
Build a long-term consulting career with opportunities to take on greater responsibility and leadership over time.
Responsibilities
What You'll Be Doing.
Every role at Ubique contributes directly to solving meaningful business challenges for our clients.
Create enterprise standards for secrets storage, access, rotation, ownership, naming, tagging, expiry, exception handling,and decommissioning.
Define when to use centralized secrets platforms versus cloud-native tools such as Azure Key Vault and AWS SecretsManager.
Design IAM access models using Azure Entra ID, AWS IAM, roles, policies, groups, service principals, managed identities,OIDC federation, and least-privilege access.
Support onboarding and migration of application teams from insecure or inconsistent secrets and IAM practices.
Integrate secrets management with IAM, PAM, CI/CD pipelines, Kubernetes, databases, APIs, legacy applications, logging,monitoring, and SIEM.
Help establish operating model components such as ownership, support processes, governance, exception management,control monitoring, and reporting.
Produce practical documentation, reference architectures, onboarding playbooks, and implementation patterns forengineering teams
Experience with at least two secrets management technologies, such as Azure Key Vault, AWS Secrets Manager, HashiCorpVault, CyberArk Conjur, Akeyless, Thales CipherTrust, External Secrets Operator, or Secrets Store CSI Driver, PAM, CCP
Proven enterprise secrets management, Strong IAM knowledge across Azure Entra ID, AWS IAM, workload identity,federation, RBAC/ABAC, least privilege, service principals and managed identities/cyberark
Experience with CyberArk PAM, HashiCorp Vault Enterprise, machine identity, certificate lifecycle, or dynamic secrets
B.E./ B.Tech. Or M.C.A/ MBA/ M.Tech. in Computer Science from a reputed University with 10-15 years of hands-onexperience on below mentioned skills.
Technology stack
Tools & Technologies.
The platforms and technologies you'll use to build modern, enterprise-grade solutions.
Azure Entra ID
Azure Managed Identity
Service Principal
Azure Key Vault
AWS IAM
AWS STS
AWS Secrets Manager
OIDC
Federation
Workload Identity
RBAC
ABAC
Least Privilege
CyberArk PAM
CyberArk Conjur
HashiCorp Vault Enterprise
Kubernetes
External Secrets Operator
Secrets Store CSI Driver
CI/CD
Requirements
Skills & Experience.
We value curiosity, collaboration and continuous learning. If you don't meet every requirement but believe you can make an impact, we'd still love to hear from you.
Essential
Required Qualifications
Hands-on Azure IAM: Azure Entra ID, service principals, Azure Managed Identity
Hands-on AWS IAM: roles, policies, STS
OIDC federation / workload identity federation
Least privilege access design; authentication vs authorization concepts
RBAC and ABAC concepts and implementation
Secrets management experience with at least two technologies (e.g., Azure Key Vault, AWS Secrets Manager, HashiCorp Vault, CyberArk Conjur, Akeyless, Thales CipherTrust, External Secrets Operator, Secrets Store CSI Driver)
Enterprise secrets management standards and governance (storage, access, rotation, ownership, naming/tagging, expiry, exceptions, decommissioning)
CyberArk PAM and/or HashiCorp Vault Enterprise experience
Credential/secret rotation and audit controls
Hybrid environment experience (cloud + on-prem workloads)
Integrating secrets/IAM with CI/CD tools (Azure DevOps, GitHub Actions, Jenkins, GitLab)
Kubernetes secrets integration (e.g., External Secrets Operator, Secrets Store CSI Driver)
Documentation and reference architecture creation (playbooks, patterns)
Preferred
Nice to Have
Policy-as-code and guardrails (Terraform, Azure Policy, AWS Organizations/SCPs, OPA, Sentinel)
Security posture/compliance tools (Checkov, Prisma Cloud, Wiz)
Secret scanning tools (GitHub Advanced Security, GitGuardian, Gitleaks, TruffleHog)
Machine identity, certificate lifecycle management, dynamic secrets
Dashboards/metrics for secrets compliance and IAM hygiene
API security and Kubernetes security
SIEM integration and operational monitoring/reporting
Experience in regulated enterprises (financial services, banking, insurance, healthcare or similar)
Stakeholder management across security, cloud, platform, risk and audit teams
What you'll gain
More Than Just A Job.
We're committed to helping every team member grow professionally, personally and technically while working on meaningful projects.
Global Exposure
Collaborate with international clients and multicultural teams on enterprise programmes.
Continuous Learning
Expand your expertise through mentoring, certifications and hands-on project experience.
Career Growth
Take ownership, develop leadership skills and grow your consulting career over time.
Flexible Working
Hybrid and remote collaboration designed around trust and delivering exceptional outcomes.
People First
Join a supportive culture where collaboration, respect and long-term relationships come first.
Enterprise Projects
Work on meaningful technology initiatives for leading organisations across industries.
Apply
Apply for Multi-Cloud IAM & Secrets Management Architect (Azure/AWS, CyberArk, Vault)
One page, about two minutes. We only ask for what we actually need to have a first conversation.