IT Lead
Bengaluru • FullTime
Posted 3mo ago
Remote Work Policy
On-site
Employment Type
FullTime
Categories
Applied AI Engineer
About the job
Sarvam is seeking an IT Lead to establish and manage the company's internal IT and IT-security functions from the ground up. This hands-on, foundational role involves setting up tooling, creating operational procedures, and directly managing identity, endpoints, network, data protection, and audit/compliance processes. The IT Lead will be responsible for ensuring the company meets stringent security standards required for regulated and financial institutions, including passing SOC 2, ISO 27001, and other critical audits. This position requires close collaboration with Security, People, and Finance teams, and will serve as the primary point of contact for auditors.
Responsibilities
- Administer identity providers (Okta, Entra, Google) including SSO, SCIM, and conditional access.
- Enforce MFA and passkey usage for privileged accounts.
- Manage all internal tools and services to ensure productive and efficient use.
- Automate provisioning and offboarding processes for new hires, movers, and leavers according to defined SLAs.
- Conduct quarterly access reviews and prepare User Access Review (UAR) evidence for auditors.
- Implement and manage Mobile Device Management (MDM) across Mac, Windows, and Linux for fleet enrollment and compliance.
- Operate Endpoint Detection and Response (EDR) systems, including deployment, triage, and quarantine workflows.
- Enforce disk encryption with key escrow for endpoints.
- Manage privilege access, ensuring no standing local administrator rights and implementing elevation-on-demand.
- Administer Zero Trust Network Access (ZTNA) for per-app access with device-posture checks.
- Manage VPN configurations, ensuring always-on and no split-tunneling for production environments.
- Implement DNS filtering for endpoint-level, network-independent security.
- Administer cloud and SaaS platforms, focusing on tenant security configuration and identity/access governance.
- Implement Data Loss Prevention (DLP) across endpoints and SaaS platforms.
- Manage Secure Access Service Edge (SASE) / Secure Web Gateway (SWG) for web filtering and shadow-IT discovery.
- Operate evidence collection and reporting for ISO 27001 and SOC 2 audits.
- Manage the asset lifecycle from procurement to disposal with an auditable trail.
- Maintain a SaaS/vendor register including ownership and security reviews.
- Oversee vendor management, including selection, contracts, security reviews, and ongoing accountability.
- Configure SIEM log forwarding for endpoint and IdP events.
- Establish and maintain IT Service Management (ITSM) discipline with auditable ticket trails.
- Lead incident response activities, including device isolation and forensic data collection.
- Develop and test remote-wipe and lost-device runbooks with defined SLAs.
- Plan and test Business Continuity/Disaster Recovery (BCP/DR) for IT systems annually.
Requirements
- Proven track record in participating in and managing audits, particularly for financial and regulated entities (BFSI/fintech).
- Demonstrated experience in managing SOC 2 and/or ISO 27001 evidence operations and certification cycles.
- Strong IT administration expertise in identity, endpoint management, and operational systems.
- Experience in vendor management, including security reviews, contracts, and accountability.
- Proficiency in networking, cloud, and SaaS administration.
- Excellent communication skills (rated 4/5 or higher) for writing runbooks, briefing auditors, and explaining controls to non-technical stakeholders.
- Comfort and experience in building functions from scratch (0→1), not just maintaining existing ones.
- Scripting skills for fleet automation (Python, Bash, or PowerShell) are a plus.
- Hands-on experience with SIEM, EDR, ZTNA, and DLP tooling at scale is a plus.
- Experience in a high-growth or regulated-industry environment is a plus.