20 Aug
|
Questhiring
|
Bengaluru
20 Aug
Questhiring
Bengaluru
Staff Identity & Access Management Engineer
Location: Bangalore, India
Experience: 10+ Years
Employment Type: Full Time
Role Overview
We are looking for a Staff Identity & Access Management (IAM) Engineer to serve as a senior technical authority for enterprise identity and access management. The role will be responsible for designing, modernizing, integrating, and governing identity platforms across a complex enterprise environment.
You will work closely with Information Security, Cloud Engineering, IT, and Business Applications teams to establish scalable identity architectures, automate identity lifecycle management, strengthen access controls, and advance the organization's Zero Trust strategy.
This is a highly hands-on technical leadership role requiring strong expertise across Okta, Microsoft Entra ID/Azure AD, Active Directory, SSO, federation, SCIM, IAM automation, and identity security .
Key Responsibilities
- Design and lead the modernization of enterprise IAM architecture across Okta, Active Directory, Microsoft Entra ID/Azure AD , and related identity services.
- Define and implement enterprise standards for user provisioning, deprovisioning, authentication, authorization, federation, access management, and privileged access .
- Develop and maintain integrations with Microsoft 365, Intune, Jamf, Workday/HRIS, AWS, SaaS platforms, and enterprise applications .
- Implement and manage SSO, SCIM, SAML, OAuth 2.0, and OpenID Connect integrations.
- Drive automation of identity lifecycle processes using PowerShell, Python, REST APIs, Okta Workflows , and other automation technologies.
- Partner with Security teams to implement Zero Trust, MFA, Conditional Access, PAM, least-privilege access, and identity governance .
- Establish mechanisms to identify and remediate orphaned accounts, excessive privileges, entitlement drift, inactive users, and access exceptions .
- Design monitoring, reporting,
and governance processes to improve IAM visibility and auditability.
- Provide technical leadership for complex IAM transformation and platform consolidation initiatives.
- Serve as a subject matter expert on authentication, authorization, federation, identity integrations, and enterprise access management.
- Mentor engineers and IT teams on IAM architecture, implementation standards, troubleshooting, and best practices.
- Collaborate with audit, risk, and compliance teams to support ISO 27001, SOC 2 , and internal security requirements.
- Evaluate emerging IAM technologies and recommend solutions that improve security, scalability, user experience, and operational efficiency.
Required Skills & Experience
- 10+ years of experience in IT Infrastructure, Security Engineering, or related technology domains.
- 5+ years of strong hands-on experience in Enterprise IAM.
- Deep expertise with:
- Okta
- Microsoft Entra ID / Azure AD
- Active Directory
- SCIM
- SAML
- OAuth 2.0
- OpenID Connect
- Strong experience designing and implementing SSO and identity federation .
- Proven experience integrating IAM platforms with HRIS, SaaS, cloud platforms, and enterprise applications .
- Hands-on experience with identity lifecycle automation and API-based integrations.
- Robust scripting/programming capabilities using PowerShell, Python, or similar languages .
- Good understanding of Zero Trust, MFA, Conditional Access, PAM, IGA, RBAC, and least-privilege principles .
- Experience working with cloud environments such as AWS and Microsoft 365 .
- Strong understanding of enterprise security architecture and identity governance.
- Excellent communication skills with the ability to influence architecture and technical decisions across teams.
Preferred Skills
- Experience with Okta Workflows .
- Experience with Azure Conditional Access .
- Experience with BeyondTrust, AdminByRequest , or other PAM solutions.
- Experience with Workday identity integrations .
- Experience supporting ISO 27001 / SOC 2 audits and control requirements.
- Experience working in large, complex, or multi-directory environments.
- Experience with identity consolidation following mergers, acquisitions, domain migrations, or hybrid identity transformations .
- Certifications such as Okta Certified Professional/Architect, Microsoft SC-300, CISSP , or equivalent are desirable.
What Success Looks Like
- Enterprise identity platforms are standardized under a scalable governance and provisioning model.
- Significant reduction in manual identity lifecycle activities.
- Improved automation of joiner, mover, and leaver processes.
- Reduction in orphaned accounts, excessive access, and entitlement drift.
- Stronger adoption of MFA, Conditional Access, and Zero Trust principles.
- Improved audit readiness and compliance across identity controls.
- Reliable and frictionless authentication experience for employees and users.
- Clear IAM architecture, standards, documentation, and roadmap established across the organization.
Ideal Candidate Profile The ideal candidate is a hands-on Staff IAM Engineer / IAM Architect who combines deep technical expertise with architecture and technical leadership capabilities. You should be comfortable working directly with Okta, Entra ID, Active Directory, SSO, SCIM, APIs, and automation , while also influencing enterprise-wide IAM strategy and security transformation.
📌 Identity Management Consultant (Bengaluru)
🏢 Questhiring
📍 Bengaluru