Information Security Analyst (IAM) at Burns & McDonnell – Bengaluru
Company: Burns & McDonnell
Job Role: Information Security Analyst (Identity & Access Management)
Location: Bengaluru, India
Experience: 0–2 years preferred
Employment Type: Full-time
Job Category: Information Technology
Travel: No travel
Req ID: 261090
Qualification: Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, Electronics & Communication, or related technical discipline
Key Skills: IAM, Identity Governance, SailPoint, Microsoft Entra ID, Active Directory, RBAC, Least Privilege, SSO, Federation, MFA, PowerShell, Cloud Identity, Cybersecurity, Access Control, Security Automation
Burns & McDonnell Information Security Analyst Job Overview
Burns & McDonnell is hiring an Information Security Analyst (Identity & Access Management) in Bengaluru. This is an entry-level opportunity focused on Identity and Access Management (IAM), cybersecurity, identity governance, access control, directory services, authentication, and security automation.
The position is particularly relevant for candidates who want to begin their careers in IAM engineering and enterprise cybersecurity. The company is looking for candidates with 0–2 years of experience, while strong fresh graduates with relevant academic projects or internship experience may also be considered.
The role provides exposure to enterprise identity platforms, identity lifecycle management, role-based access control, Microsoft Entra ID, Active Directory, authentication technologies, access governance, compliance validation, and PowerShell-based automation.
For candidates interested in cybersecurity but looking for a specialization beyond traditional security operations, this position provides a strong introduction to the identity security domain.
About Burns & McDonnell
Burns & McDonnell is an employee-owned engineering, architecture, construction, and consulting organization with a history spanning more than 125 years.
The company works across multiple industries and provides multidisciplinary solutions for complex infrastructure and engineering requirements. Its areas of work include oil and gas, chemical and petrochemical, energy and power, water, transportation, environmental services, and other critical infrastructure sectors.
Burns & McDonnell India supports global projects through teams of engineers, architects, consultants, and technology professionals. The Bengaluru operation combines international engineering practices with local technical capabilities.
The company also highlights its employee-ownership model. Being 100% employee-owned means employees have a direct stake in the organization’s long-term success.
For technology professionals, the company environment can provide opportunities to work with multidisciplinary teams and contribute to technology requirements supporting large-scale engineering and infrastructure projects.
What Does an Information Security Analyst – IAM Do?
Identity and Access Management is one of the fundamental areas of enterprise cybersecurity.
Organizations have thousands of employees, contractors, applications, servers, cloud services, and other systems. Each user or system needs appropriate access to resources. IAM helps ensure that users receive the right access to the right resources at the right time.
The Information Security Analyst in this position will support the engineering and administration of IAM systems and processes.
The responsibilities include:
- IAM platform configuration
- Identity lifecycle management
- Access control
- RBAC implementation
- Directory services
- Authentication
- SSO and federation
- MFA
- Cloud identity
- Security automation
- Access governance
- Compliance validation
- Technical documentation
- IAM platform testing
This makes the position broader than a conventional IT support role.
Key Responsibilities
1. Identity Governance and Administration
The analyst will support enterprise Identity Governance & Administration (IGA) platforms such as SailPoint or equivalent technologies.
IGA solutions help organizations manage identities, access requests, approvals, certifications, policies, and identity lifecycle processes.
The role includes assisting with the configuration and enhancement of these platforms.
Candidates should therefore understand the basic purpose of identity governance and why organizations need centralized access management.
2. Identity Lifecycle Management
One of the important concepts mentioned in the job description is the identity lifecycle.
The role specifically refers to:
- Joiner
- Mover
- Leaver
A Joiner is a new employee who needs access to appropriate systems.
A Mover is an existing employee whose job or department changes and whose access may need to be modified.
A Leaver is an employee who leaves the organization and whose access should be removed promptly.
Proper lifecycle management reduces the risk of unauthorized access and ensures that user permissions remain aligned with their current responsibilities.
3. Role-Based Access Control
The position involves supporting Role-Based Access Control (RBAC) models and access standards.
RBAC assigns permissions based on a user’s organizational role rather than granting permissions individually without structure.
For example, an organization might define roles such as:
- Developer
- Database Administrator
- HR Employee
- Finance Analyst
- System Administrator
Each role can have a predefined set of permissions.
Understanding RBAC is therefore important for candidates entering enterprise IAM and cybersecurity.
4. Least Privilege
The job description also highlights least privilege.
The principle of least privilege means users should receive only the access required to perform their responsibilities.
For example, an employee who only needs to read a particular system should not automatically receive administrative permissions.
Least privilege reduces the potential impact of compromised accounts and helps organizations strengthen their security posture.
Candidates preparing for IAM interviews should understand the relationship between authentication, authorization, RBAC, and least privilege.
5. Microsoft Entra ID and Active Directory
The position includes support for Microsoft Entra ID and Active Directory environments.
Active Directory has traditionally been widely used for managing identities, users, computers, groups, and access within enterprise environments.
Microsoft Entra ID provides cloud-based identity and access capabilities.
Candidates should understand fundamental concepts such as:
- Users
- Groups
- Roles
- Permissions
- Directory services
- Authentication
- Authorization
- Identity synchronization
- Cloud identity
Practical exposure through academic labs or personal projects can help candidates demonstrate their understanding.
6. SSO, Federation and MFA
The role also involves integrating enterprise applications with centralized authentication services.
This includes technologies and concepts such as:
Single Sign-On
SSO allows users to authenticate once and access multiple authorized applications without repeatedly entering credentials.
Federation
Federation enables identity and authentication relationships between different systems or organizations.
Multi-Factor Authentication
MFA adds additional verification factors beyond a password.
These technologies are important components of modern enterprise identity security.
7. IAM Architecture
The analyst will participate in IAM architecture reviews.
This means candidates should gradually learn how identity systems fit into a larger enterprise security architecture.
An IAM architecture may involve:
Users → Identity Provider → Authentication → Authorization → Applications → Access Governance
Understanding these relationships can help candidates move from basic IAM administration toward IAM engineering and architecture roles.
8. PowerShell and Security Automation
The position specifically mentions PowerShell for automation initiatives.
PowerShell can be used to automate repetitive administrative tasks involving Windows systems, users, groups, permissions, and identity environments.
For example, scripting can help automate repetitive activities such as:
- User management
- Group management
- Access validation
- Reporting
- Account checks
- Administrative workflows
Candidates do not necessarily need advanced scripting experience, but basic PowerShell knowledge can strengthen their profile.
9. Compliance and Access Validation
IAM is closely connected to cybersecurity compliance.
The analyst will support reporting and validation of access governance controls to meet compliance and audit requirements.
Organizations need to demonstrate that:
- Users have appropriate access.
- Excessive permissions are identified.
- Access reviews are performed.
- Former employees do not retain access.
- Access policies are followed.
- Security controls are documented.
Therefore, IAM professionals often work at the intersection of technology, cybersecurity, risk, and compliance.
Skills Required for the Burns & McDonnell IAM Role
Identity and Access Management
IAM is the core skill for this position. Candidates should understand how organizations manage digital identities and control access to applications and infrastructure.
Identity Governance & Administration
IGA knowledge helps candidates understand identity lifecycle management, access requests, approvals, certifications, and governance processes.
SailPoint
SailPoint is mentioned as an example of an enterprise IGA platform. Familiarity with SailPoint or a comparable IAM platform can be useful.
RBAC
Role-Based Access Control is important for designing structured permission models.
Least Privilege
Candidates should understand how limiting access can reduce security risks.
Active Directory
Active Directory knowledge provides a foundation for understanding enterprise identity and directory services.
Microsoft Entra ID
Knowledge of Microsoft Entra ID is useful for modern cloud identity environments.
Authentication
Authentication determines whether an identity is genuinely who they claim to be.
Authorization
Authorization determines what an authenticated identity is allowed to access.
SSO
Single Sign-On is widely used to simplify enterprise application authentication while maintaining centralized identity controls.
Federation
Federation enables authentication and identity relationships across systems and organizations.
MFA
Multi-factor authentication provides an additional layer of identity verification.
PowerShell
PowerShell knowledge can help automate identity and administrative tasks.
Cloud Identity
Understanding identity in Azure or AWS environments is increasingly important as organizations adopt cloud infrastructure.
Cybersecurity
The role requires foundational cybersecurity knowledge, particularly around identity, access control, and enterprise security.
Security Automation
Automation can improve efficiency and reduce repetitive manual security activities.
Documentation
IAM environments require clear documentation of configurations, workflows, integrations, and security processes.
Analytical and Problem-Solving Skills
IAM issues can involve users, applications, permissions, directories, authentication systems, and policies. Analytical thinking is therefore essential.
Communication
IAM professionals frequently work with IT teams, security teams, application owners, auditors, and business stakeholders. Strong written and verbal communication is important.
Who Can Apply?
The position is suitable for candidates with a Bachelor’s degree in:
- Computer Science
- Information Technology
- Cybersecurity
- Electronics & Communication
- Other related technical disciplines
The job prefers 0–2 years of experience in areas such as:
- Cybersecurity
- IAM engineering
- IT infrastructure
- Related technology roles
However, strong fresh graduates with relevant academic or project experience will also be considered.
This makes the position particularly relevant for students and recent graduates who have completed cybersecurity, IAM, cloud, or infrastructure projects.
Certifications That Can Help
The job description mentions relevant entry-level certifications as a preferred qualification.
Candidates can consider certifications related to:
- Microsoft Identity
- CompTIA Security+
- Cloud security
- IAM fundamentals
Certifications are not a replacement for practical knowledge, but they can demonstrate structured learning and foundational cybersecurity understanding.
How to Prepare for the Interview
Candidates should prepare both cybersecurity fundamentals and practical IAM concepts.
Technical Topics
Focus on:
- IAM fundamentals
- Authentication vs authorization
- RBAC
- Least privilege
- Identity lifecycle
- Joiner-Mover-Leaver processes
- Active Directory
- Microsoft Entra ID
- SSO
- Federation
- MFA
- Cloud identity
- PowerShell basics
- Cybersecurity fundamentals
- Access reviews
- Identity governance
- Security automation
Practical Projects
A candidate can strengthen their resume with projects such as:
Project 1: Active Directory Lab
Create users, groups, organizational units, and permissions in a controlled lab environment.
Project 2: RBAC Demonstration
Create a simple role-based permission system demonstrating different levels of access.
Project 3: PowerShell Automation
Create PowerShell scripts for basic user or group administration and reporting.
Project 4: Cloud Identity Lab
Explore identity and access management concepts using a cloud platform’s learning environment.
Project 5: IAM Documentation
Create a sample Joiner-Mover-Leaver workflow showing how employee access should be provisioned, modified, and removed.
These projects can provide useful talking points during interviews.
Career Growth in IAM
IAM is a specialized cybersecurity domain with multiple potential career paths.
An entry-level analyst can eventually progress toward roles such as:
- IAM Analyst
- IAM Engineer
- Identity Security Engineer
- IGA Engineer
- Cloud Identity Engineer
- Cybersecurity Engineer
- IAM Consultant
- Security Architect
- Identity Architect
As cloud adoption increases, identity has become an important part of modern security architecture.
Knowledge of both traditional directory services and cloud identity platforms can therefore create a strong foundation for long-term cybersecurity development.
Why This Job Is a Good Opportunity for Fresh Graduates
This position stands out because the company explicitly states that strong fresh graduates with relevant academic or project experience will be considered.
The role also provides exposure to multiple areas rather than restricting the candidate to a single technology.
A candidate can potentially learn:
IAM → Identity Governance → RBAC → Active Directory → Entra ID → Authentication → SSO → MFA → Cloud Identity → Automation → Compliance
This creates a structured learning path for someone beginning a career in identity security.
Another advantage is that the role does not require travel, and it is a full-time position in Bengaluru.
Burns & McDonnell IAM Job Details at a Glance
| Category | Details |
|---|---|
| Company | Burns & McDonnell |
| Position | Information Security Analyst (Identity & Access Management) |
| Location | Bengaluru, India |
| Job Category | Information Technology |
| Experience | 0–2 years preferred |
| Employment Type | Full-time |
| Travel | No travel |
| Req ID | 261090 |
| Qualification | Bachelor’s degree in a relevant technical discipline |
| Core Domain | Cybersecurity / IAM |
| Key Platform | SailPoint or equivalent |
| Identity Platforms | Microsoft Entra ID, Active Directory |
| Automation | PowerShell |
| Security Areas | RBAC, Least Privilege, SSO, Federation, MFA |
Final Thoughts
The Information Security Analyst (Identity & Access Management) role at Burns & McDonnell in Bengaluru is a strong entry-level opportunity for candidates interested in building a career in enterprise cybersecurity and identity security.
The role focuses on some of the most important components of modern IAM, including identity governance, lifecycle management, RBAC, least privilege, directory services, authentication, federation, MFA, cloud identity, security automation, and compliance.
For fresh graduates, the most important preparation should be to understand the fundamentals rather than trying to memorize every IAM product. A candidate should be able to clearly explain the difference between authentication and authorization, describe RBAC and least privilege, understand the Joiner-Mover-Leaver lifecycle, and explain how Active Directory and Microsoft Entra ID fit into enterprise identity management.
Learning basic PowerShell can further strengthen the profile because automation is specifically included in the position.
Candidates who combine cybersecurity fundamentals with practical labs, IAM projects, cloud identity exposure, and strong communication skills can position themselves well for this opportunity and for future IAM engineering roles.
The job posting states that 0–2 years of experience is preferred, while strong fresh graduates with relevant academic or project experience will be considered. This makes it particularly relevant for recent graduates looking to enter the cybersecurity field through the IAM specialization.
Apply Link: Please click here to apply

IAM professional with 4.6 years of experience designing and managing identity lifecycle, access governance, and authentication solutions across enterprise environments. Skilled in implementing SSO, MFA, and RBAC/ABAC models to secure access to critical systems while enabling business efficiency. Hands-on experience with GD, AD / CyberArk for user provisioning, de-provisioning, and periodic access reviews. Strong background in supporting compliance audits (SOX, ISO 27001, GDPR) and reducing access-related risk through least-privilege enforcement. Adept at collaborating with cross-functional teams including HR, IT, and Security to streamline onboarding/offboarding workflows and integrate new applications via SAML, OAuth, and SCIM.
Top 5 key skills:
Identity Access Management,SQL,IAM,Cyber Security,Cyberark,Servicenow,Active Directory,LDAP
Really need this role I’m preparing from last 6 months for this role and job opportunity. Please let me know if you need any other requirement.