IAM Engineer - Silverfort

Posted 5 Days Ago
Be an Early Applicant
Hyderabad, Telangana, IND
In-Office
Entry level
Information Technology • Consulting • Cybersecurity
The Role
Deploys and administers Silverfort infrastructure, integrating Active Directory, Entra ID, Okta, MFA providers, and SIEM platforms. Implements risk-based access, machine-to-machine protection, RBAC, and attack-detection policies. Monitors authentication traffic, node health, replication, logs, and system performance while troubleshooting issues and managing upgrades. Configures DNS, DHCP, IPAM, Group Policy, auditing, service accounts, password policies, and network access. Documents deployments, runbooks, and exception-handling procedures.
Summary Generated by Built In

As a Silverfort Administrator, responsible for demonstrating the capabilities of Silverfort features & products. Integrating the on-prem AD & secure the privileged access user accounts. Implementation of security policies to strengthen server access for diverged user base. Monitoring & troubleshooting the infrastructure and handling the authentication requests to improve security and reduce the blast radius.

1       Roles & Responsibilities:

1.       Deploy the Silverfort infrastructure with Admin & nodes in load balancing and failover architecture.

2.       Configure and maintain direct connections with Identity Providers (IdPs), including Microsoft Active Directory, Entra ID, & Okta.

3.       Enforce Multi-Factor Authentication (MFA) across non-standard interfaces such as Remote Desktop Protocol (RDP), Command-Line interfaces (PowerShell, SSH), and SMB file shares.

4.       Integrate 3rd part MFA solutions like MS authenticator, Okta, Google Authenticator & Duo with Silverfort environment to extend the Silverfort capabilities with existing MFA solutions.

5.       Oversee traffic interception parameters, ensure optimal performance of Silverfort nodes, and troubleshoot authentications.

6.       Create, tune, and optimize risk-based access policies utilizing Silverfort’s AI-driven threat engine.

7.       Discover, map, and secure machine-to-machine communications by creating behavioral baselines and automated protection policies.

8.       Audit and adjust user Role-Based Access Control (RBAC) to eliminate unnecessary excessive privileges across both cloud and hybrid setups.

9.       Set up and configure triggers to detect modern lateral movement attacks, brute-force strategies, and credential-dumping attempts.

10.   Evaluate Silverfort traffic logs to trace anomalies and generate operational risk metrics.

11.   Ingesting Silverfort logs to SIEM solutions like Splunk, LogRhythm & Sentinel.

12.   Document Silverfort platform deployments, runbooks, and exception-handling frameworks to maintain clean IT operational continuity.

13.   Manage the daily operation, health monitoring, and system upgrades of the Silverfort admin console, nodes, and dependent services.


 



Requirements1.1.              Must have skills:

1.       Understanding basic authentication flow mechanics and troubleshooting common clock-skew time sync errors.

2.       Creating and updating A, AAAA, CNAME, PTR, and SRV locator records manually.

3.       Monitoring policy replication health across DCs using Distributed File System Replication (DFSR) commands.

4.       Configuring Domain Name System (DNS) zones, Dynamic Host Configuration Protocol (DHCP) scopes, and IP Address Management (IPAM) structures.

5.       Creating, managing, and rotating passwords for standard and Managed Service Accounts (MSAs).

6.       Implementing different password complexity rules for specific high-risk user groups via password policies.

7.       Configuring standard security and sharing tabs using inheritance and AGDLP (Account, Global, Universal, Domain Local, Permissions) best practices.

8.       Knowing the five Flexible Single Master Operation roles and their placements across domain controllers.

9.       Enabling security audit logs on OUs to trace which admin modified or moved a specific object.

10.   Applying Group Policy Objects conditionally based on hardware traits like operating system version or laptop vs. desktop.

11.   Mapping network printers, deploying registry changes, and configuring local shortcut files natively

12.   Understanding about networking concepts LAN, MAN & WAN.

13.   Knowledge of IP addressing and subnetting.

1.2.              Good to have skills:

1.       Strong analytical mindset with an ability to troubleshoot basic issues.

2.       High willingness to learn, adapt, and grasp new technologies quickly.

3.       Excellent verbal and written communication skills in English.

4.       Understanding of networking & diagnosing system / vm related issues.

5.       Understanding of cloud network architecture & administration techniques.

6.       Exposure on AWS, Azure & GCP cloud platforms.

 

1.3.              Education:

1.       Bachelors in engineering in departments such as IT/EEE are preferred.



Skills Required

  • Understanding of authentication flow mechanics and troubleshooting clock-skew and time synchronization errors
  • Ability to manually create and update A, AAAA, CNAME, PTR, and SRV DNS records
  • Experience monitoring Active Directory policy replication health across domain controllers using DFSR commands
  • Ability to configure DNS zones, DHCP scopes, and IPAM structures
  • Experience creating, managing, and rotating passwords for standard and Managed Service Accounts
  • Ability to implement password complexity rules for high-risk user groups
  • Knowledge of security and sharing tabs, inheritance, and AGDLP best practices
  • Knowledge of the five Flexible Single Master Operation roles and their placement across domain controllers
  • Ability to enable security audit logs on organizational units to trace object changes
  • Ability to apply Group Policy Objects conditionally based on hardware and operating system traits
  • Ability to map network printers, deploy registry changes, and configure local shortcut files natively
  • Understanding of LAN, MAN, and WAN networking concepts
  • Knowledge of IP addressing and subnetting
  • Strong analytical and troubleshooting skills
  • Willingness to learn, adapt, and grasp new technologies quickly
  • Excellent verbal and written communication skills in English
  • Understanding of networking and system or virtual machine troubleshooting
  • Understanding of cloud network architecture and administration techniques
  • Exposure to AWS, Azure, and GCP cloud platforms
  • Bachelor's degree in engineering, preferably IT or EEE
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
100 Employees
Year Founded: 2015

What We Do

ENH iSecure is a cybersecurity consulting and solution-deployment company established by information-security experts. It focuses on identity-based security and human identity risks, delivering solutions across BFSI, telecom, healthcare, utilities, and other sectors. Its expertise includes identity security, privileged identity management, access management, email and cloud security, endpoint privilege security, and GRC/SIEM services for enterprise clients, from risk assessment through implementation.

Similar Jobs

The Aerospace Corporation Logo The Aerospace Corporation

Advanced Hardware Engr

Aerospace • Artificial Intelligence • Cloud • Machine Learning • Software • Cybersecurity • Defense
Remote or Hybrid
India
4600 Employees
Hybrid
Hyderabad, Telangana, IND
289097 Employees
Hybrid
Hyderabad, Telangana, IND
289097 Employees
Hybrid
Hyderabad, Telangana, IND
289097 Employees

Similar Companies Hiring

Standard Template Labs Thumbnail
Artificial Intelligence • Information Technology • Software
New York, NY
25 Employees
NODA AI Thumbnail
Artificial Intelligence • Information Technology • Software • Cybersecurity
Sydney, AU
54 Employees
Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account