Rockwell Automation

Senior Identity and Access Management Engineer, API Security

Pune, India Hyderabad, India
API OAuth 2.0 OpenID Connect JWT mTLS OWASP NIST GDPR HIPAA PCI-DSS MuleSoft Kong Apigee AWS API Gateway HashiCorp Vault Python Bash Terraform Ansible Azure AWS GCP Microsoft Sentinel
Description

Senior IAM Engineer (API Security/NHI)

Location: India Pune (Mississippi Building), India Hyderabad, India Bengaluru

Remote Type: Hybrid

Time Type: Full time

Job Description

Rockwell Automation is a global technology leader focused on helping the world’s manufacturers be more productive, sustainable, and agile. With more than 28,000 employees who make the world better every day, we know we have something special. Behind our customers - amazing companies that help feed the world, provide life-saving medicine on a global scale, and focus on clean water and green mobility - our people are energized problem solvers that take pride in how the work we do changes the world for the better.

We welcome all makers, forward thinkers, and problem solvers who are looking for a place to do their best work. And if that’s you we would love to have you join us!

Job Description

Summary:

You will focus on Non‑Human and Machine Identity & Access Management (NHI/IAM) with a emphasis on API security, secrets management, and centralised API governance. You will define, implementing, and operationalizing secure identity, authentication, authorization, and secrets management for application of APIs, service accounts, and machine identities across the enterprise.

This is an IAM engineering and architecture role, centred on API protection, non‑human identities, machine credentials, and application‑to‑application security. The role partners with application, DevOps, platform, and security teams to embed secure API identity controls, enforce least‑privilege access, and improve adoption of centralised API and secrets management capabilities.

You will report to the Enterprise IAM Leader.

Your Responsibilities

  • Design and implement Non‑Human and Machine Identity controls for service accounts, API tokens, application credentials, and CI/CD system identities.
  • Establish centralised secrets management using HashiCorp Vault (or equivalent), enforcing secure storage, automated rotation and expiration, auditing, and removal of hard‑coded credentials.
  • Define API authentication and authorization standards, including OAuth 2.0, OpenID Connect, JWT, and mTLS, with least‑privilege access models.
  • Design and enforce API security policies using API Gateway platforms (MuleSoft, Kong, Apigee, AWS API Gateway, or equivalent), including rate limiting, throttling, and traffic control.
  • Lead centralised API governance, covering API registration, lifecycle management, and policy enforcement by an enterprise API gateway.
  • Increase adoption of the centralised IAM and API security stack, establishing and operationalizing the enterprise API gateway.
  • Implement API logging and monitoring, ensuring we forward API and identity events to the enterprise SIEM for visibility and threat detection.
  • Partner with SOC, platform, DevOps, and application teams to detect API abuse, anomalous behaviour, and misconfiguration.
  • Maintain architecture standards and reference designs for API identity, secrets management, and non‑human access control.
  • Ensure understanding of industry standards such as OWASP API Security Top 10, NIST, GDPR, HIPAA, and PCI‑DSS.

The Essentials - You Will Have:

  • Bachelor's degree in computer science, Engineering, or equivalent practical experience.
  • 8–10+ years of experience in IAM, API Security, or Application Security, with a focus on Non‑Human and Machine Identities.
  • Hands‑on experience with API Gateway platforms such as MuleSoft, Apigee, Kong, or AWS API Gateway, postman, Salt Security cloud-native API discovery, including policy enforcement and traffic control.
  • 1+ years experience with secrets management HashiCorp Vault, including token lifecycle management, rotation, and auditability.
  • Experience with API authentication and authorization using OAuth 2.0, OpenID Connect, JWT, and mTLS.
  • Experience with API discovery and non‑human identity inventory, including service accounts and API tokens.
  • Working knowledge of API security risks and controls, including OWASP API Security Top 10 and mitigation strategies.
  • Experience with network and API‑adjacent security concepts (WAF, firewalls, traffic inspection, rate limiting).

The Preferred – You Might Also Have

  • 3+ years of experience integrating IAM and API security controls into CI/CD pipelines and developer platforms.
  • Familiarity with infrastructure‑as‑code and automation (Terraform, Ansible, YAML‑based pipelines).
  • 1+ years of experience in cloud and hybrid environments (Azure, AWS, GCP).
  • Knowledge of API logging, monitoring, and SIEM integrations, with Microsoft Sentinel preferred.
  • Proficiency in scripting and automation (Python, Bash, or YAML).
  • Security or IAM‑related certifications (CISSP, CCSP, or API/IAM‑focused credentials), but not mandatory.

What We Offer:

Our benefits package includes …

  • Comprehensive mindfulness programme with a premium membership to Calm.
  • Volunteer Paid Time off available after 6 months of employment for eligible employees.
  • Company volunteer and donation matching programme – The company matches your volunteer hours or personal cash donations to an eligible charity with a charitable donation.
  • Employee Assistance Program.
  • Personalised wellbeing programmes through our OnTrack programme.
  • On-demand digital course library for professional development.

... and other local benefits!

At Rockwell Automation, we are dedicated to building a diverse, inclusive, and authentic workplace. If you're excited about this role but your experience doesn't align perfectly with every qualification in the job description, we encourage you to apply anyway. You may be just the right person for this or other roles.

#LI-Hybrid

#LI-SM1

Rockwell Automation’s hybrid policy aligns that employees are expected to work at a Rockwell location at least Mondays, Tuesdays, and Thursdays unless they have a business obligation out of the office.

Rockwell Automation
Rockwell Automation

0 applies

0 views

There are more than 50,000 engineering jobs:

Subscribe to membership and unlock all jobs

Engineering Jobs

60,000+ jobs from 4,500+ well-funded companies

Updated Daily

New jobs are added every day as companies post them

Refined Search

Use filters like skill, location, etc to narrow results

Become a member

🥳🥳🥳 452 happy customers and counting...

Overall, over 80% of customers chose to renew their subscriptions after the initial sign-up.

To try it out

For active job seekers

For those who are passive looking

Cancel anytime

Frequently Asked Questions

  • We prioritize job seekers as our customers, unlike bigger job sites, by charging a small fee to provide them with curated access to the best companies and up-to-date jobs. This focus allows us to deliver a more personalized and effective job search experience.
  • We've got over 200,000 jobs from 15,000+ vetted companies. No fake or sleazy jobs here!
  • We aggregate jobs from 15,000+ companies' career pages, so you can be sure that you're getting the most up-to-date and relevant jobs.
  • We're the only job board *for* software engineers, *by* software engineers… in case you needed a reminder! We add thousands of new jobs daily and offer powerful search filters just for you. 🛠️
  • Every single hour! We add 2,000-3,000 new jobs daily, so you'll always have fresh opportunities. 🚀
  • Typically, job searches take 3-6 months. EchoJobs helps you spend more time applying and less time hunting. 🎯
  • Check daily! We're always updating with new jobs. Set up job alerts for even quicker access. 📅

What Fellow Engineers Say