About this role
Zoetis, Inc. is the world's largest producer of medicine and vaccinations for pets and livestock. The Zoetis Tech & Digital (ZTD) Global Technology Risk Management Organization is a key building block of ZTD.
Join us at Zoetis India Capability Center (ZICC) in Hyderabad, where innovation meets excellence. As part of the world's leading animal healthcare company, ZICC is at the forefront of driving transformative advancements and applying technology to solve the most complex problems. Our mission is to ensure sustainable growth and maintain a competitive edge for Zoetis globally by leveraging the exceptional talent in India.
At ZICC, you'll be part of a dynamic team that partners with colleagues worldwide, embodying the true spirit of One Zoetis. Together, we ensure seamless integration and collaboration, fostering an environment where your contributions can make a real impact. Be a part of our journey to pioneer innovation and drive the future of animal healthcare.
The global Identity, Directory & Access Management (IDAM) team defines and enforces policies, executes processes, and enables systems to ensure appropriate access management across Zoetis' digital ecosystem. Key IDAM functions at Zoetis include Identity Governance & Administration (IGA), Directory & Authentication Services, Multi-Factor Authentication (MFA), Public Key Infrastructure (PKI), Customer Identity & Access Management (CIAM), and Privileged Access Management (PAM), among others.
The IDAM Technology Lead is responsible for overseeing several key Identity, Directory, and Access Management (IDAM) functions from both a technology and day-to-day operational perspective within the ZICC. This is a hands-on technical leadership role, where the candidate is expected to be a senior technical contributor in addition to leading the team. These functions include IGA, PAM, Identity Data Hygiene, and Level 2 (L2) Support. Within the ZICC, this position will lead a team of approximately 10 colleagues, including technical and functional engineers, administrators, and support analysts. The ideal candidate must possess deep, hands-on expertise in at least one core IDAM technology, preferably SailPoint IdentityIQ (IIQ)and maintain a broad understanding of related IDAM domains and integrations. As IDAM services are mission-critical to all Zoetis information systems, this role is primarily responsible for ensuring maximum uptime, security, and operational efficiency. The ideal candidate should also possess deep expertise in business processes enabled by IAM solutions and will engage on multiple projects while collaborating with stakeholders at all levels, including executives.
POSITION RESPONSIBILITIES
Percent of Time
- Oversee 16x5 operations for Identity, Directory, and Access Management (IDAM) services, ensuring uninterrupted service and providing off-hours escalation support for high-priority incidents (P1, P2).
- Provide technical leadership and oversight for all relevant IDAM services, focusing primarily on Identity Governance and Administration (IGA), Privileged Access Management (PAM), data flows, and related integrations.
- Act as a technical SME/lead , providing day-to-day guidance, coaching, and technical direction to L2/L3 engineers and SMEs across SailPoint/IGA and PAM.
- Drive automations and improve efficiency (e.g., SailPoint workflows, connector optimizations, scripts, auto-remediation, monitoring/alerting improvements) to reduce manual effort, improve accuracy, and accelerate turnaround times.
- Hands-on troubleshooting of complex authentication, provisioning, and integration failures; collaborate with application teams to resolve availability and access issues.
- Identify opportunities to enhance IDAM services , introduce new features to support business objectives, build compelling business cases, and drive initiatives from conception to successful implementation.
- Provide hands-on leadership for IDAM platform lifecycle management , including version upgrades , patching , OS refreshes , and infrastructure/application migrations (on-prem and/or cloud), ensuring minimal downtime and controlled risk.
- Drive Disaster Recovery (DR) planning and readiness for in-scope IDAM platforms (e.g., SailPoint IIQ, PAM), including DR strategy , runbooks , RTO/RPO alignment , and regular DR testing with documented results and remediation.
- Plan and execute changes via formal change management, including upgrade/refresh/migration cutover planning , stakeholder communications, rollback plans, and post-change validation.
- Lead incident and problem management processes, ensuring service level agreements (SLAs) are consistently met, root causes are identified, and issues are effectively addressed to prevent recurrence.
- Troubleshoot authentication failures and collaborate with application teams to resolve availability issues, maintaining system reliability and addressing critical challenges.
- Supervise incident response and root cause analysis for authentication service outages, identity synchronization issues, and cybersecurity events to ensure timely recovery and mitigation.
- Serve as a key point of contact and subject matter expert for relevant IDAM programs, providing technical guidance and strategic input for projects and initiatives.
- Drive adherence to global IDAM policies and processes, ensuring secure and efficient access to Zoetis information systems for all users.
- Ensure the ZICC IDAM team collaborates closely with Service Desk, Site Services, and Security Operations teams to enhance IAM support processes and optimize cross-team collaboration.
- Oversee IDAM Data Hygiene activities, ensuring clean, accurate, and well-managed identity data across systems. Collaborate closely with HR and other stakeholders to maintain data quality and integrity.
100%
ORGANIZATIONAL RELATIONSHIPS
- Reports to ZICC based IDAM Program Lead, with dotted line to US-based Head of IDAM and IDAM Operations Lead
- Be part of the global Technology Risk Management organization, which reports to the Chief Information Security Officer (CISO).
- Collaborate regularly with ZTD application, business partner, and infrastructure teams to understand requirements, provide technical guidance , and deliver secure IAM integrations.
- Partner closely with application teams and platform owners to identify and implement automation opportunities across provisioning, access requests, certifications, PAM onboarding, and operational workflows.
- Interact with external vendors or partners providing software, services, or APIs that require integration with IDAM systems, including establishing requirements, negotiating contracts, and facilitating technical integration.
- Collaborate with implementation partners responsible for deploying, configuring, or maintaining integrated solutions within Zoetis’ IT landscape, ensuring hands-on technical oversight and quality of delivery .
RESOURCES MANAGED
Supervision
Approximately 10 members of the IDAM team.
EDUCATION AND EXPERIENCE
Education:
- University Degree in Computer Science or Information Systems is required
- MS or advanced security/identity courses or other applicable certifications is desirable, including Certified Information Systems Security Professional (CISSP)
Experience:
• Minimum 10+ years of experience in Information Systems
• 6+ years of detailed, hands-on experience with IDAM, including IGA and PAM
• 2+ years of experience in the pharmaceutical or other regulated industry, especially Animal Health.
• Experience working with global teams across multiple time zones.
• Proven experience in managing medium to large-scale, global IT projects.
• Demonstrated ability to work within diverse technical teams.
• Proven experience in leading technical teams and managing end-to-end solution delivery.
• Strong experience collaborating with Managed Service Providers (MSPs), with a focus on ensuring quality and alignment.
TECHNICAL SKILLS REQUIREMENTS
This is a combination functional, technical, and leadership roles. The ideal candidate will demonstrate strong hands-on technical depth in at least one core IDAM technology (preferably SailPoint IdentityIQ ) and provide leadership and guidance across the broader IDAM scope, including IGA, PAM, integrations, and operations.
- Identity Governance & Administration (IGA) – SailPoint IdentityIQ Hands-on SailPoint IdentityIQ (IIQ) SME experience : installation, configuration, upgrades, and end-to-end operations.
- Strong understanding of Identity Lifecycle , Access Requests , Certifications/Recertifications , Provisioning/Deprovisioning , and Role/Entitlement governance.
- Proven experience gathering integration requirements from application teams and translating them into solution designs and delivery plans (connectors, workflows, data flows, controls).
- Strong development/configuration skills for IIQ customization and automation (e.g., Java, BeanShell, XML , APIs/REST, rules, workflows).
- Solid database/SQL skills for troubleshooting, reporting, and data analysis.
- Ability to lead SailPoint SMEs , guide technical decisions, and drive automation and enhancements ; capable of building a roadmap and pitching enhancements/business value to the organization.
- Exposure to other IGA platforms (e.g., SailPoint ISC, Saviynt) is a plus.
- Privileged Access Management Strong understanding of how PAM works : vaulting, password rotation, approvals, session management/recording, break-glass, and JIT/JEA concepts.
- Prior experience working with PAM teams and ability to lead PAM SMEs to deliver enhancements, integrations, and operational improvements.
- Experience with vault/JIT tools (e.g., Delinea Secret Server , Netwrix SecureOne; CyberArk knowledge is a plus).
- Experience integrating PAM solutions with Windows, Linux, databases, network devices , and enterprise applications.
- Data Hygiene Experience ensuring clean, accurate, and well-managed identity data across systems.
- Proven ability to establish procedures for decommissioning access for departing employees and reassigning service accounts and entitlements.
- Ability to collaborate with HR to ensure timely and accurate flows of authoritative user data.
Operations, Platform Lifecycle, and Resilience
o Experience leading 16x5 operations and providing escalation support for P1/P2 incidents; ability to manage and guide L2/L3 support teams .
o Strong incident/problem management and RCA discipline; ability to drive service stability and SLA performance.
o Hands-on experience planning and executing upgrades , patching , OS refresh , and migrations (infra/app/platform), including cutover planning, risk management, and rollback planning.
o Knowledge and practical experience with Disaster Recovery (DR) : DR strategy/runbooks, RTO/RPO understanding, DR testing execution, and remediation tracking.
Integrations & Identity Data
o Experience integrating IDAM with enterprise systems such as Active Directory , ServiceNow , Workday , SAP , and other business applications.
o Strong understanding of identity data flows and data hygiene practices; ability to partner with HR and authoritative sources to maintain identity data integrity.
- Must be fluent in both written and spoken English, with the ability to communicate effectively across technical and non-technical audiences.
PHYSICAL POSITION REQUIREMENTS
- Availability to work between 2 PM IST to 11 PM IST hours (minimum 3 hours of daily overlap with US ET Time zone)
· Office attendance- Min 50% in a month or as per local HR policy
Full time
Notice: Zoetis Recruiters will contact candidates via email from an address ending in @zoetis.com and may also initially connect with candidates through LinkedIn , including LinkedIn InMail. Zoetis does not use Gmail, Outlook, Yahoo, or other web-based/generic email domains to communicate about job opportunities, interviews, or offers of employment. If you receive a recruitment-related email message claiming to be from Zoetis that does not come from @zoetis.com , please treat it as suspicious. For your security, do not reply, click links, open attachments, share personal or financial information, or send money in response to unexpected or questionable recruitment communications.