
IND IT Support Specialist II
- 🇮🇳 India
- On-site
- 1 day ago
- IAM
- Azure
- Ping
- Okta
- HTML
- CSS
- JavaScript
- Ping Identity
- Java
- Disaster Recovery
- Load Balancing
- Excel
- PowerPoint
- MS Project
- Git
- Visio
- Azure AD
- Conditional Access
- SAML
- OAuth
- OpenID Connect
- SCIM
- SSL/TLS
- LDAP
- Active Directory
- XML
- JSON
- ASP.NET
- J2EE
- Regulatory Compliance
- GDPR
- HIPAA
- SOC2
- Devops
- GitHub
- CI/CD
- Python
- PowerShell
- ISE
- AWS
- Graph API
Our Story
At Alight, we believe a company’s success starts with its people. Alight embraces values that come directly from our people – purposeful, human, united and growth-minded – reflecting our inclusive culture and promise that our clients expect. We are passionate about connecting purpose with impact. Alight empowers clients to build a healthier and more financially secure workforce by unifying the benefits ecosystem across health, wealth, wellbeing, navigation, and absence management.
Our Benefits
With a comprehensive total rewards package, Alight offers programs and plans that support your mind, body, wallet, and life. Benefits include health, starting Day One. Additionally, Alight colleagues enjoy wellbeing programs, retirement plans, and career growth opportunities – all within a thriving global organization.
Great Place to Work
Thanks to the work of every colleague, Alight has received multiple awards of recognition including “Great Place to Work” for the past 7 years and Fortune’s “Best Companies to Work For.” To learn more about our company culture and awardsClick Here.
We invite you to join our team! Learn more atcareers.alight.com.
Job Description
WD Grade: 110 Job Title: Senior Analyst Location: Chennai/Hyderabad / IND
ROLE DESCRIPTION
Delivery of exceptional Technical Services. Responsible for analyzing, resolving, and maintaining different layers of IDAM applications, including but not limited to SSO/Authentication, Authorization, Identity Governance.
IDAM is a tightknit group, with many overlapping areas of responsibility.
PRINCIPAL DUTIES AND RESPONSIBILITIES:
· Design and implement cutting-edge identity and access management (IAM) solutions.
· Develop and deploy access management and federation products, including but not limited to Microsoft Azure Entra ID, Ping Federate, Okta and B2C, or equivalent solutions.
· Demonstrate comprehensive knowledge of Single Sign-On (SSO), authentication, and authorization workflows. Develop custom Authentication Modules, Authentication Tree Nodes, Account Mappers, and Adapters based on customer requirements and use cases.
· Enhance user experience by designing and modifying UI elements (HTML, CSS, JavaScript), updating MFA requirements, modifying token claims, and configuring session settings.
· Facilitate the onboarding of new customers (inbound and outbound SSO), ensuring adherence to defined processes and timelines.
· Manage the complete lifecycle of Ping Identity solution deployments, including requirements analysis, solution design, architecture, configuration, customization (using Java/JavaScript), and testing (unit, system integration, performance, and UAT testing).
· Contribute to IAM security service delivery through monitoring, controlling, and supporting the execution of security services.
· Collaborate and liaise with internal teams and customer stakeholders throughout the SSO implementation lifecycle.
· Conduct technology assessments to support automation and migration initiatives.
· Partner with external client technical and business contacts to showcase Alight IAM capabilities and best practices while documenting proposed solutions.
· Working with External Client Technical and Business contacts to demonstrate Alight IAM capabilities and best practices while documenting the solution to be implemented.
· Create and maintain comprehensive support documentation and processes.
· Diagnose and resolve software application issues using established procedures and methodologies.
· Analyze complex problems and provide actionable resolution paths.
· Provide on-call technical support as required.
· Lead escalation handling for complex IAM-related issues, ensuring timely resolution and minimizing operational disruptions. Serve as the primary point of contact for escalated technical issues and coordinate cross-functional teams for rapid response.
· Act as a key liaison to provide stakeholders with timely escalation updates, ensuring transparency and alignment throughout the process. Perform root cause analyses for recurring issues or major incidents and propose actionable process improvements to prevent future occurrences. Address problem statements and deliver the required information within the specified deadline.
· Actively participate in Disaster Recovery Exercises (DRE) to ensure process documents are up-to-date and seamless execution of the exercise.
· Ability to create training materials and conduct workshops for end-users and internal teams on SSO workflows and best practices.
EDUCATION AND PROFESSIONAL CERTIFICATIONS:
· Bachelor's degree Graduation (Mandatory)
· At least 7 years job experience in the IT industry with minimum 5 year in IAM technology.
· Professional Certifications such as SC 900, SC 300, AZ 500, AZ 900, SSCP, etc. are a plus but not mandatory.
CANDIDATE PROFILE:
· Solid oral and written communication skills in English.
· Clear understanding of Team’s role in meeting Organizational objectives.
· Average Business knowledge.
· Ability to organize work and priorities to meet deadlines with limited supervision.
· Strong problem solving and analytical skills.
· Be proactive, dynamic, and flexible.
· Incumbents at this level should be familiar with all aspects of Information Technologies including Hardware, Operating Systems, Network protocols, Clustering, Load-balancing, High Availability, Cloud Computing, IAM, SSO, DB etc.
Position
Description
Describe in as much detail as possible any expectations of this position not described above that are unique to your area. Do not include client specific tasks.
COMPETENCIES:
o Cybersecurity Expertise: Demonstrated ability to assist across all aspects of Cybersecurity, including proactive risk identification and resolution.
o Advanced Cloud Computing Knowledge: In-depth understanding of cloud computing platforms and services, especially in relation to IAM and SSO solutions.
o Exceptional Presentation and Communication Skills: Strong presentation abilities and proficiency in office productivity tools such as MS365, Word, Excel, PowerPoint, with advanced knowledge of MS Project, Visual Source Code, Git, and Visio.
o Continuous Learning and Adaptability: Proven capability to quickly gain proficiency in new technologies and work autonomously toward strategic goals.
· Required Skills:
o Strong understanding of Microsoft Entra ID (Azure AD) features, including Conditional Access, Multi-Factor Authentication (MFA), and Identity Protection.
o Configure and manage Microsoft Entra ID environments, including user accounts, groups, roles, and policies.
o Expertise in identity federation protocols such as SAML, OAuth, OpenID Connect, and WS-Federation.
o Proficiency in Single Sign-On (SSO) configurations for diverse applications, including web, mobile, and enterprise systems.
o Plan and implement Single Sign-On (SSO) solutions to enable seamless access across applications and resources.
o Configure and maintain SCIM-based automatic provisioning for enterprise applications.
o Oversee user provisioning, de-provisioning, and access reviews to ensure secure identity lifecycle management.
o Experience in designing access control policies to ensure appropriate authorization levels.
o Configure and support integrations with Enterprise applications, cloud services, and third-party identity providers using protocols like SAML, OAuth, and WS-FED.
o Ensure compliance with organizational security policies and regulatory requirements related to identity and access management.
o Diagnose and resolve authentication issues, login failures, and access permissions related to Entra ID, SSO and MFA.
o Hands-on experience managing both an Identity Provider (IdP) and Service Provider (SP), along with external federation setups (e.g., IDP-initiated and SP-initiated SSO).
o Competence in configuring user attribute mapping and claims transformation for effective data communication between IdPs and SPs.
o Comprehensive knowledge of IdP Adapters, context-based authentication policies, and device, location, or network-based protocols.
o Expertise in securing communications (e.g., SSL/TLS), token signing, and encryption for SAML assertions and OAuth tokens.
o Integration proficiency with LDAP directories, Active Directory (AD), and other identity stores for authentication and user information retrieval.
o Practical knowledge in identity synchronization across federated systems to maintain accurate user identities.
o Configure and maintain HYPR Authenticate, ensuring smooth integration with enterprise systems.
o Oversee FIDO-based authentication, eliminating passwords while enhancing security.
o Work with HYPR APIs to enable secure authentication across applications.
o Proficiency with XML, JSON, Java, JavaScript, ASP.net, and J2EE.
o Expertise in migrating legacy identity and access management systems to modern SSO solutions while ensuring minimal disruption and seamless integration.
o Knowledge of regulatory compliance standards like GDPR, HIPAA, and SOC2, as well as securing SSO systems against vulnerabilities and threats.
o Ability to implement monitoring tools and dashboards for tracking SSO system performance, usage metrics, and error trends.
o Maintain up-to-date documentation on Entra ID configurations, processes, and best practices.
o Maintain technical documentation and provide guidance on passwordless authentication best practices.
· Supplemental Skill’s:
o Familiarity with DevOps tools like GitHub and Continuous Integration/Deployment practices.
o Proficiency in Python scripting and PowerShell, including workflows and troubleshooting in ISE or AWS CLI.
o Advanced knowledge of API integrations, including GraphAPI, REST, and cloud-based interfaces.
o Strong understanding of Disaster Recovery Exercises (DRE) protocols and escalation handling for SSO issues.
o Familiarity with tools and scripting for automating IAM processes, such as onboarding, deprovisioning, and system updates.
Application and Interview
By applying for a position with Alight, you understand that, should you be made an offer, it will be contingent on your undergoing and successfully completing a background check consistent with Alight’s employment policies. Background checks may include some or all the following based on the nature of the position: Government ID validation, education verification, employment verification, and criminal check, search against global sanctions and government watch lists, credit check, and/or drug test. You will be notified during the hiring process which checks are required by the position.
Alight requires all virtual interviews to be conducted on video. Please be aware that Alight is a camera-on culture and may require occasional travel to one of our physical office locations.
Our commitment to Inclusion
We celebrate differences and believe in fostering an environment where everyone feels valued, respected, and supported. We know that diverse teams are stronger, more innovative, and more successful.
At Alight, we welcome and embrace all individuals, regardless of their background, and are dedicated to creating a culture that enables every employee to thrive. Join us in building a brighter, more inclusive future.
As part of this commitment, Alight will ensure that persons with disabilities are provided with reasonable accommodation for the hiring process. If reasonable accommodation is needed, please contactalightcareers@alight.com.
Equal Opportunity Policy Statement
Alight is an Equal Employment Opportunity employer and does not discriminate against anyone based on sex, race, color, religion, creed, national origin, ancestry, age, physical or mental disability, medical condition, pregnancy, marital or domestic partner status, citizenship, military or veteran status, sexual orientation, gender, gender identity or expression, genetic information, or any other legally protected characteristics or conduct covered by federal, state, or local law. In addition, we take affirmative action to employ disabled persons, disabled veterans, and other covered veterans.
Alight provides reasonable accommodation to the known limitations of otherwise qualified employees and applicants for employment with disabilities and sincerely held religious beliefs, practices and observances, unless doing so would result in undue hardship. Applicants for employment may request reasonable accommodations/modifications by contacting their recruiter.
Authorization to work in the Employing Country
Applicants for employment in the country in which they are applying (Employing Country) must have work authorization that does not, now or in the future, require sponsorship of a visa for employment authorization in the Employing Country and with Alight.
Note, this job description does not restrict management's right to assign or reassign duties and responsibilities of this job to other entities; including but not limited to subsidiaries, partners, or purchasers of Alight business units.
to be replaced with Government ID to get aligned with India context Agree.
We offer you a competitive total rewards package, continuing education & training, and tremendous potential with a growing worldwide organization.
DISCLAIMER:
Nothing in this job description restricts management's right to assign or reassign duties and responsibilities of this job to other entities; including but not limited to subsidiaries, partners, or purchasers of Alight business units.
IND IT Support Specialist II · Axiom U.S. Payroll, LLC