Ubique Systems

TRPD-26-04828

Multi-Cloud IAM & Secrets Management Architect (Azure/AWS, CyberArk, Vault)

This role owns assessment and transformation of enterprise secrets management and IAM across Azure, AWS, hybrid/on-prem, Kubernetes and CI/CD. The person will define target-state architecture, standards and governance for secrets storage/rotation/audit, design IAM access models (Entra ID/AWS IAM, federation, workload identity, least privilege), and integrate secrets/IAM with PAM, pipelines, apps, databases, APIs, logging/monitoring and SIEM. Success requires hands-on multi-cloud IAM plus experience with at least two secrets platforms (e.g., Key Vault, AWS Secrets Manager, HashiCorp Vault, CyberArk Conjur) and strong enterprise governance, onboarding and migration support.

Position summary

Location
India
Workplace
Hybrid
Employment
Full Time
Experience
Minimum 5 years and Maximum 10 years
Apply now

Role overview

Why This Role Matters.

This role owns assessment and transformation of enterprise secrets management and IAM across Azure, AWS, hybrid/on-prem, Kubernetes and CI/CD. The person will define target-state architecture, standards and governance for secrets storage/rotation/audit, design IAM access models (Entra ID/AWS IAM, federation, workload identity, least privilege), and integrate secrets/IAM with PAM, pipelines, apps, databases, APIs, logging/monitoring and SIEM. Success requires hands-on multi-cloud IAM plus experience with at least two secrets platforms (e.g., Key Vault, AWS Secrets Manager, HashiCorp Vault, CyberArk Conjur) and strong enterprise governance, onboarding and migration support.

Your Impact

Deliver Enterprise Value

Help organisations solve complex business problems through modern technology, consulting expertise and measurable outcomes.

Collaboration

Work Across Teams

Collaborate with consultants, architects, engineers and client stakeholders throughout the project lifecycle.

Growth

Learn Continuously

Gain exposure to enterprise technologies, certifications, mentoring and real-world project experience.

Career Path

Grow With Ubique

Build a long-term consulting career with opportunities to take on greater responsibility and leadership over time.

Responsibilities

What You'll Be Doing.

Every role at Ubique contributes directly to solving meaningful business challenges for our clients.

01

Assess current secrets management and IAM practices across Azure, AWS, on-premises, Kubernetes, CI/CD, applications,databases, APIs, and service accounts.

02

Create enterprise standards for secrets storage, access, rotation, ownership, naming, tagging, expiry, exception handling,and decommissioning.

03

Define when to use centralized secrets platforms versus cloud-native tools such as Azure Key Vault and AWS SecretsManager.

04

Design IAM access models using Azure Entra ID, AWS IAM, roles, policies, groups, service principals, managed identities,OIDC federation, and least-privilege access.

05

Support onboarding and migration of application teams from insecure or inconsistent secrets and IAM practices.

06

Integrate secrets management with IAM, PAM, CI/CD pipelines, Kubernetes, databases, APIs, legacy applications, logging,monitoring, and SIEM.

07

Help establish operating model components such as ownership, support processes, governance, exception management,control monitoring, and reporting.

08

Produce practical documentation, reference architectures, onboarding playbooks, and implementation patterns forengineering teams

09

Experience with at least two secrets management technologies, such as Azure Key Vault, AWS Secrets Manager, HashiCorpVault, CyberArk Conjur, Akeyless, Thales CipherTrust, External Secrets Operator, or Secrets Store CSI Driver, PAM, CCP

10

Proven enterprise secrets management, Strong IAM knowledge across Azure Entra ID, AWS IAM, workload identity,federation, RBAC/ABAC, least privilege, service principals and managed identities/cyberark

11

Experience with CyberArk PAM, HashiCorp Vault Enterprise, machine identity, certificate lifecycle, or dynamic secrets

12

B.E./ B.Tech. Or M.C.A/ MBA/ M.Tech. in Computer Science from a reputed University with 10-15 years of hands-onexperience on below mentioned skills.

Technology stack

Tools & Technologies.

The platforms and technologies you'll use to build modern, enterprise-grade solutions.

01

Azure Entra ID

02

Azure Managed Identity

03

Service Principal

04

Azure Key Vault

05

AWS IAM

06

AWS STS

07

AWS Secrets Manager

08

OIDC

09

Federation

10

Workload Identity

11

RBAC

12

ABAC

13

Least Privilege

14

CyberArk PAM

15

CyberArk Conjur

16

HashiCorp Vault Enterprise

17

Kubernetes

18

External Secrets Operator

19

Secrets Store CSI Driver

20

CI/CD

Requirements

Skills & Experience.

We value curiosity, collaboration and continuous learning. If you don't meet every requirement but believe you can make an impact, we'd still love to hear from you.

Essential

Required Qualifications

Hands-on Azure IAM: Azure Entra ID, service principals, Azure Managed Identity

Hands-on AWS IAM: roles, policies, STS

OIDC federation / workload identity federation

Least privilege access design; authentication vs authorization concepts

RBAC and ABAC concepts and implementation

Secrets management experience with at least two technologies (e.g., Azure Key Vault, AWS Secrets Manager, HashiCorp Vault, CyberArk Conjur, Akeyless, Thales CipherTrust, External Secrets Operator, Secrets Store CSI Driver)

Enterprise secrets management standards and governance (storage, access, rotation, ownership, naming/tagging, expiry, exceptions, decommissioning)

CyberArk PAM and/or HashiCorp Vault Enterprise experience

Credential/secret rotation and audit controls

Hybrid environment experience (cloud + on-prem workloads)

Integrating secrets/IAM with CI/CD tools (Azure DevOps, GitHub Actions, Jenkins, GitLab)

Kubernetes secrets integration (e.g., External Secrets Operator, Secrets Store CSI Driver)

Documentation and reference architecture creation (playbooks, patterns)

Preferred

Nice to Have

Policy-as-code and guardrails (Terraform, Azure Policy, AWS Organizations/SCPs, OPA, Sentinel)

Security posture/compliance tools (Checkov, Prisma Cloud, Wiz)

Secret scanning tools (GitHub Advanced Security, GitGuardian, Gitleaks, TruffleHog)

Machine identity, certificate lifecycle management, dynamic secrets

Dashboards/metrics for secrets compliance and IAM hygiene

API security and Kubernetes security

SIEM integration and operational monitoring/reporting

Experience in regulated enterprises (financial services, banking, insurance, healthcare or similar)

Stakeholder management across security, cloud, platform, risk and audit teams

What you'll gain

More Than Just A Job.

We're committed to helping every team member grow professionally, personally and technically while working on meaningful projects.

Global Exposure

Collaborate with international clients and multicultural teams on enterprise programmes.

Continuous Learning

Expand your expertise through mentoring, certifications and hands-on project experience.

Career Growth

Take ownership, develop leadership skills and grow your consulting career over time.

Flexible Working

Hybrid and remote collaboration designed around trust and delivering exceptional outcomes.

People First

Join a supportive culture where collaboration, respect and long-term relationships come first.

Enterprise Projects

Work on meaningful technology initiatives for leading organisations across industries.

Apply

Apply for Multi-Cloud IAM & Secrets Management Architect (Azure/AWS, CyberArk, Vault)

One page, about two minutes. We only ask for what we actually need to have a first conversation.

Your CV

Optional. A line or two is plenty.