Identity & Access Management Engineer (AD, Entra ID, Agentic identity) (Mumbai)

Identity & Access Management Engineer (AD, Entra ID, Agentic identity) (Mumbai)

20 Aug
|
Crisil
|
Mumbai

20 Aug

Crisil

Mumbai

Senior Identity & Access Management Engineer

(Active Directory, Entra ID, Agentic identity)

Experience: 10+ Years

Location: Mumbai

Work Mode: Work From Office

Role Type: Senior Individual Contributor (L3 / L4)

Role Summary

We are hiring a Senior IAM Engineer with strong hands-on experience in Active Directory, Microsoft Entra ID (Azure AD), and DNS to support and enhance enterprise identity platforms. This role highly requires ownership. You will be the organization’s subject-matter expert responsible for designing, deploying, and governing identities for AI agents, service principals, managed identities, and non-human identities (NHIs) across Microsoft Entra ID and associated cloud environments.

You will ensure that every agent — whether it reads a SharePoint file, triggers a Power Automate flow, or calls an external API — operates under a least-privilege, auditable, and governable identity model.

Key Responsibilities

- Design, implement, and maintain enterprise-scale Active Directory and Entra ID infrastructures, ensuring high availability, security, and scalability.
- Lead identity lifecycle management, including provisioning, deprovisioning, access reviews, and role-based access control (RBAC).
- Manage and optimize DNS infrastructure to support seamless authentication and directory services.
- Develop and enforce identity governance policies, integrating agentic identity principles by empowering users and automating secure access workflows.
- Collaborate with cross-functional teams to architect and deploy secure authentication and authorization solutions (e.g., SSO, MFA, conditional access).
- Deep understanding of OAuth 2.0 flows: Authorization Code, Client Credentials, Device Code, and On-Behalf-Of (OBO).
- OpenID Connect (OIDC) for identity federation — how ID tokens, access tokens, and refresh tokens work.
- SAML 2.0: assertions, IdP-initiated vs SP-initiated SSO, attribute mapping.
- Multi-Factor Authentication (MFA): TOTP, FIDO2/Passkeys, Windows Hello for Business, and Conditional Access policy construction.
- Monitor, troubleshoot, and resolve complex directory and DNS issues, leveraging advanced diagnostic tools and logs.
- Drive continuous improvement by proactively identifying areas for automation, efficiency, and enhanced user experience.
- Zero Trust & Security Principles for identity and access management.
- identity management, cloud security, and agentic identity frameworks.
- Agentic Identity Architecture & Design, Define and maintain the Agentic Identity Framework for all AI agents operating in the organization — spanning managed identities, service principals, workload federation, and delegated permissions.
- Design agent-to-agent and agent-to-human trust models including Entra Workload Identity Federation for keyless authentication.
- Implementation & Engineering, Deploy and manage Managed Identities (system-assigned and user-assigned) for Azure-hosted AI workloads and automation pipelines.
- Implement scoped API permissions in Microsoft Graph API and enforce admin consent policies to prevent over-privileged agent access.
- Integrate agent identities into Privileged Identity Management (PIM) for just-in-time access and approval workflows.




- Build and maintain Identity Governance policies — access reviews, entitlement management, and lifecycle workflows — covering agent identities in addition to human users.
- Security, Compliance & Governance, Enforce Zero Trust principles for all agentic workloads: verify explicitly, use least privilege, assume breach.
- Monitor agent identity signals through Microsoft Entra Identity Protection, Defender for Cloud Apps, and Microsoft Sentinel; respond to anomalous or over-privileged activity.
- Implement policy-driven identity controls using Conditional Access, identity protection, and leastprivilege enforcement
- Proactively identify identity-related risks and improvement opportunities without dependency on external direction
- Ensure identity controls align with Zero Trust security architecture

Required Skills

- 10+ years of hands-on experience with:
- Active Directory (multi-domain / forest)
- Microsoft Entra ID (Azure AD)
- DNS administration and troubleshooting
- Azure B2B and B2C concepts

- Solid understanding of:

- Identity lifecycle management
- SSO, MFA, Conditional Access
- Authentication protocols (LDAP, SAML, OAuth, OpenID Connect)
- Agentic identity, Non human Identity management.

- Experience with PowerShell automation
- Solid grasp of identity security and Zero Trust principles
- Strong problem-solving and communication skills

Senior Identity & Access Management Engineer (Active Directory, Entra ID, Agentic identity)

Experience: 10+ Years

Location: Mumbai

Work Mode: Work From Office

Role Type: Senior Individual Contributor (L3 / L4)

Role Summary

We are hiring a Senior IAM Engineer with strong hands-on experience in Active Directory, Microsoft Entra ID (Azure AD), and DNS to support and enhance enterprise identity platforms. This role highly requires ownership. You will be the organization’s subject-matter expert responsible for designing, deploying, and governing identities for AI agents, service principals, managed identities, and non-human identities (NHIs) across Microsoft Entra ID and associated cloud environments.

You will ensure that every agent — whether it reads a SharePoint file, triggers a Power Automate flow, or calls an external API — operates under a least-privilege, auditable, and governable identity model.

Key Responsibilities

- Design, implement, and maintain enterprise-scale Active Directory and Entra ID infrastructures, ensuring high availability, security, and scalability.
- Lead identity lifecycle management, including provisioning, deprovisioning, access reviews, and role-based access control (RBAC).
- Manage and optimize DNS infrastructure to support seamless authentication and directory services.
- Develop and enforce identity governance policies,



integrating agentic identity principles by empowering users and automating secure access workflows.
- Collaborate with cross-functional teams to architect and deploy secure authentication and authorization solutions (e.g., SSO, MFA, conditional access).
- Deep understanding of OAuth 2.0 flows: Authorization Code, Client Credentials, Device Code, and On-Behalf-Of (OBO).
- OpenID Connect (OIDC) for identity federation — how ID tokens, access tokens, and refresh tokens work.
- SAML 2.0: assertions, IdP-initiated vs SP-initiated SSO, attribute mapping.
- Multi-Factor Authentication (MFA): TOTP, FIDO2/Passkeys, Windows Hello for Business, and Conditional Access policy construction.
- Monitor, troubleshoot, and resolve complex directory and DNS issues, leveraging advanced diagnostic tools and logs.
- Drive continuous improvement by proactively identifying areas for automation, efficiency, and enhanced user experience.
- Zero Trust & Security Principles for identity and access management.
- identity management, cloud security, and agentic identity frameworks.
- Agentic Identity Architecture & Design, Define and maintain the Agentic Identity Framework for all AI agents operating in the organization — spanning managed identities, service principals, workload federation, and delegated permissions.
- Design agent-to-agent and agent-to-human trust models including Entra Workload Identity Federation for keyless authentication.
- Implementation & Engineering, Deploy and manage Managed Identities (system-assigned and user-assigned) for Azure-hosted AI workloads and automation pipelines.
- Implement scoped API permissions in Microsoft Graph API and enforce admin consent policies to prevent over-privileged agent access.
- Integrate agent identities into Privileged Identity Management (PIM) for just-in-time access and approval workflows.
- Build and maintain Identity Governance policies — access reviews, entitlement management, and lifecycle workflows — covering agent identities in addition to human users.
- Security, Compliance & Governance, Enforce Zero Trust principles for all agentic workloads: verify explicitly, use least privilege, assume breach.
- Monitor agent identity signals through Microsoft Entra Identity Protection, Defender for Cloud Apps, and Microsoft Sentinel; respond to anomalous or over-privileged activity.
- Implement policy-driven identity controls using Conditional Access, identity protection, and leastprivilege enforcement
- Proactively identify identity-related risks and improvement opportunities without dependency on external direction
- Ensure identity controls align with Zero Trust security architecture

Required Skills

- 10+ years of hands-on experience with:
- Active Directory (multi-domain / forest)
- Microsoft Entra ID (Azure AD)
- DNS administration and troubleshooting
- Azure B2B and B2C concepts

- Strong understanding of:

- Identity lifecycle management
- SSO, MFA, Conditional Access
- Authentication protocols (LDAP, SAML, OAuth, OpenID Connect)
- Agentic identity, Non human Identity management.

- Experience with PowerShell automation
- Solid grasp of identity security and Zero Trust principles
- Strong problem-solving and communication skills

📌 Identity & Access Management Engineer (AD, Entra ID, Agentic identity) (Mumbai)
🏢 Crisil
📍 Mumbai

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: identity & access management engineer (ad, entra id, agentic identity) (mumbai) / mumbai

Subscribe to this job alert:

Get the latest job offers by email for: identity & access management engineer (ad, entra id, agentic identity) (mumbai) / mumbai