As an RSA Administrator, responsible
for demonstrating the capabilities of RSA features & products. Integrating
the on-prem AD & secure the user accounts. Implementation of security
policies to strengthen users & application access for diverged user base. Monitoring
& troubleshooting the infrastructure and handling the authentication
requests to improve overall security posture.
1. Installing, configuring, and upgrading RSA
Authentication Manager servers, replicas, and web tiers across on-premises and
cloud environments.
2. Connecting RSA systems with directories (Active
Directory, OpenLDAP) and enterprise applications via RADIUS, SAML, OIDC, and
REST APIs.
3. Enforce Multi-Factor Authentication (MFA) across privileged and
non-privileged identities.
4. Provisioning, rotating, assigning, and revoking software tokens,
hardware key fobs, and mobile authenticators for end-users.
5. Designing and executing emergency access procedures (e.g.,
temporary fixed passcodes) for users with lost or broken tokens.
6. Utilizing the RSA administrative console to execute bulk user
imports, profile creations, and security group synchronization.
7. Planning and scheduling the deployment of critical security
patches, cumulative hotfixes, and major version upgrades on RSA appliances.
8. Creating and managing risk-based authentication (RBA) policies,
conditional access rules, and geographic fencing parameters.
9. Audit and adjust user Role-Based Access Control (RBAC) to
eliminate unnecessary excessive privileges across both cloud and hybrid setups.
10. Monitoring server CPU, memory, and token license counts to
proactively recommend system expansions or renewals before resource depletion.
11. Authoring, maintaining, and testing disaster recovery (DR)
runbooks specific to recovering the RSA authentication infrastructure from
bare-metal backups.
12. Creating clear standard operating procedures (SOPs) for Tier 1 and
Tier 2 helpdesk admins regarding day-to-day token troubleshooting.
13. Manage the daily operation, health monitoring, and system upgrades
of the RSA ID Plus & SecurID components
Requirements1.1. Must have skills:
1. Understanding basic authentication
flow mechanics and troubleshooting common clock-skew time sync errors.
2. Creating and updating A, AAAA, CNAME,
PTR, and SRV locator records manually.
3. Monitoring policy replication health
across DCs using Distributed File System Replication (DFSR) commands.
4. Configuring Domain Name System (DNS)
zones, Dynamic Host Configuration Protocol (DHCP) scopes, and IP Address
Management (IPAM) structures.
5. Creating, managing, and rotating
passwords for standard and Managed Service Accounts (MSAs).
6. Implementing different password
complexity rules for specific high-risk user groups via password policies.
7. Configuring standard security and
sharing tabs using inheritance and AGDLP (Account, Global, Universal, Domain
Local, Permissions) best practices.
8. Knowing the five Flexible Single
Master Operation roles and their placements across domain controllers.
9. Enabling
security audit logs on OUs to trace which admin modified or moved a specific
object.
10. Applying Group Policy Objects
conditionally based on hardware traits like operating system version or laptop
vs. desktop.
11. Mapping network printers, deploying
registry changes, and configuring local shortcut files natively
12. Understanding about networking
concepts LAN, MAN & WAN.
13. Knowledge of IP addressing and
subnetting.
1. Strong analytical mindset with an ability to troubleshoot basic
issues.
2. High willingness to learn, adapt, and grasp new technologies
quickly.
3. Excellent verbal and written communication skills in English.
4. Understanding of networking & diagnosing system / vm related
issues.
5. Understanding of cloud network architecture & administration
techniques.
6. Exposure on AWS, Azure & GCP cloud platforms.
1. Bachelors in engineering in
departments such as IT/EEE are preferred.
Skills Required
- Understanding authentication flow mechanics and troubleshooting clock-skew and time synchronization errors
- Creating and updating A, AAAA, CNAME, PTR, and SRV DNS records
- Monitoring Active Directory policy replication health using DFSR commands
- Configuring DNS zones, DHCP scopes, and IPAM structures
- Creating, managing, and rotating passwords for standard and Managed Service Accounts
- Implementing password complexity policies for high-risk user groups
- Configuring security and sharing permissions using inheritance and AGDLP best practices
- Knowledge of the five Flexible Single Master Operation roles and their domain controller placements
- Enabling OU security audit logs to track administrative object changes
- Applying conditional Group Policy based on operating system and hardware characteristics
- Mapping network printers, deploying registry changes, and configuring local shortcuts natively
- Understanding LAN, MAN, and WAN networking concepts
- Knowledge of IP addressing and subnetting
- Analytical mindset and basic troubleshooting ability
- Willingness to learn and adapt to new technologies
- Excellent verbal and written English communication skills
- Understanding of networking and system or virtual machine troubleshooting
- Understanding of cloud network architecture and administration
- Exposure to AWS, Azure, and GCP
- Bachelor's degree in engineering, preferably IT or EEE
What We Do
ENH iSecure is a cybersecurity consulting and solution-deployment company established by information-security experts. It focuses on identity-based security and human identity risks, delivering solutions across BFSI, telecom, healthcare, utilities, and other sectors. Its expertise includes identity security, privileged identity management, access management, email and cloud security, endpoint privilege security, and GRC/SIEM services for enterprise clients, from risk assessment through implementation.








