Senior Identity & Access Management Engineer
(Active Directory, Entra ID, Agentic identity)
Experience: 10+ Years
Location: Mumbai
Work Mode: Work From Office
Role Type: Senior Individual Contributor (L3 / L4)
Role Summary
We are hiring a Senior IAM Engineer with strong hands-on experience in Active Directory, Microsoft Entra ID (Azure AD), and DNS to support and enhance enterprise identity platforms. This role highly requires ownership. You will be the organization’s subject-matter expert responsible for designing, deploying, and governing identities for AI agents, service principals, managed identities, and non-human identities (NHIs) across Microsoft Entra ID and associated cloud environments.
You will ensure that every agent — whether it reads a SharePoint file, triggers a Power Automate flow, or calls an external API — operates under a least-privilege, auditable, and governable identity model.
Key Responsibilities
- Design, implement, and maintain enterprise-scale Active Directory and Entra ID infrastructures, ensuring high availability, security, and scalability.
- Lead identity lifecycle management, including provisioning, deprovisioning, access reviews, and role-based access control (RBAC).
- Manage and optimize DNS infrastructure to support seamless authentication and directory services.
- Develop and enforce identity governance policies, integrating agentic identity principles by empowering users and automating secure access workflows.
- Collaborate with cross-functional teams to architect and deploy secure authentication and authorization solutions (e.g., SSO, MFA, conditional access).
- Deep understanding of OAuth 2.0 flows: Authorization Code, Client Credentials, Device Code, and On-Behalf-Of (OBO).
- OpenID Connect (OIDC) for identity federation — how ID tokens, access tokens, and refresh tokens work.
- SAML 2.0: assertions, IdP-initiated vs SP-initiated SSO, attribute mapping.
- Multi-Factor Authentication (MFA): TOTP, FIDO2/Passkeys, Windows Hello for Business, and Conditional Access policy construction.
- Monitor, troubleshoot, and resolve complex directory and DNS issues, leveraging advanced diagnostic tools and logs.
- Drive continuous improvement by proactively identifying areas for automation, efficiency, and enhanced user experience.
- Zero Trust & Security Principles for identity and access management.
- identity management, cloud security, and agentic identity frameworks.
- Agentic Identity Architecture & Design, Define and maintain the Agentic Identity Framework for all AI agents operating in the organization — spanning managed identities, service principals, workload federation, and delegated permissions.
- Design agent-to-agent and agent-to-human trust models including Entra Workload Identity Federation for keyless authentication.
- Implementation & Engineering, Deploy and manage Managed Identities (system-assigned and user-assigned) for Azure-hosted AI workloads and automation pipelines.
- Implement scoped API permissions in Microsoft Graph API and enforce admin consent policies to prevent over-privileged agent access.
- Integrate agent identities into Privileged Identity Management (PIM) for just-in-time access and approval workflows.
- Build and maintain Identity Governance policies — access reviews, entitlement management, and lifecycle workflows — covering agent identities in addition to human users.
- Security, Compliance & Governance, Enforce Zero Trust principles for all agentic workloads: verify explicitly, use least privilege, assume breach.
- Monitor agent identity signals through Microsoft Entra Identity Protection, Defender for Cloud Apps, and Microsoft Sentinel; respond to anomalous or over-privileged activity.
- Implement policy-driven identity controls using Conditional Access, identity protection, and leastprivilege enforcement
- Proactively identify identity-related risks and improvement opportunities without dependency on external direction
- Ensure identity controls align with Zero Trust security architecture
Required Skills
- 10+ years of hands-on experience with:
- Active Directory (multi-domain / forest)
- Microsoft Entra ID (Azure AD)
- DNS administration and troubleshooting
- Azure B2B and B2C concepts
- Solid understanding of:
- Identity lifecycle management
- SSO, MFA, Conditional Access
- Authentication protocols (LDAP, SAML, OAuth, OpenID Connect)
- Agentic identity, Non human Identity management.
- Experience with PowerShell automation
- Solid grasp of identity security and Zero Trust principles
- Strong problem-solving and communication skills
Senior Identity & Access Management Engineer (Active Directory, Entra ID, Agentic identity)
Experience: 10+ Years
Location: Mumbai
Work Mode: Work From Office
Role Type: Senior Individual Contributor (L3 / L4)
Role Summary
We are hiring a Senior IAM Engineer with strong hands-on experience in Active Directory, Microsoft Entra ID (Azure AD), and DNS to support and enhance enterprise identity platforms. This role highly requires ownership. You will be the organization’s subject-matter expert responsible for designing, deploying, and governing identities for AI agents, service principals, managed identities, and non-human identities (NHIs) across Microsoft Entra ID and associated cloud environments.
You will ensure that every agent — whether it reads a SharePoint file, triggers a Power Automate flow, or calls an external API — operates under a least-privilege, auditable, and governable identity model.
Key Responsibilities
- Design, implement, and maintain enterprise-scale Active Directory and Entra ID infrastructures, ensuring high availability, security, and scalability.
- Lead identity lifecycle management, including provisioning, deprovisioning, access reviews, and role-based access control (RBAC).
- Manage and optimize DNS infrastructure to support seamless authentication and directory services.
- Develop and enforce identity governance policies,
integrating agentic identity principles by empowering users and automating secure access workflows.
- Collaborate with cross-functional teams to architect and deploy secure authentication and authorization solutions (e.g., SSO, MFA, conditional access).
- Deep understanding of OAuth 2.0 flows: Authorization Code, Client Credentials, Device Code, and On-Behalf-Of (OBO).
- OpenID Connect (OIDC) for identity federation — how ID tokens, access tokens, and refresh tokens work.
- SAML 2.0: assertions, IdP-initiated vs SP-initiated SSO, attribute mapping.
- Multi-Factor Authentication (MFA): TOTP, FIDO2/Passkeys, Windows Hello for Business, and Conditional Access policy construction.
- Monitor, troubleshoot, and resolve complex directory and DNS issues, leveraging advanced diagnostic tools and logs.
- Drive continuous improvement by proactively identifying areas for automation, efficiency, and enhanced user experience.
- Zero Trust & Security Principles for identity and access management.
- identity management, cloud security, and agentic identity frameworks.
- Agentic Identity Architecture & Design, Define and maintain the Agentic Identity Framework for all AI agents operating in the organization — spanning managed identities, service principals, workload federation, and delegated permissions.
- Design agent-to-agent and agent-to-human trust models including Entra Workload Identity Federation for keyless authentication.
- Implementation & Engineering, Deploy and manage Managed Identities (system-assigned and user-assigned) for Azure-hosted AI workloads and automation pipelines.
- Implement scoped API permissions in Microsoft Graph API and enforce admin consent policies to prevent over-privileged agent access.
- Integrate agent identities into Privileged Identity Management (PIM) for just-in-time access and approval workflows.
- Build and maintain Identity Governance policies — access reviews, entitlement management, and lifecycle workflows — covering agent identities in addition to human users.
- Security, Compliance & Governance, Enforce Zero Trust principles for all agentic workloads: verify explicitly, use least privilege, assume breach.
- Monitor agent identity signals through Microsoft Entra Identity Protection, Defender for Cloud Apps, and Microsoft Sentinel; respond to anomalous or over-privileged activity.
- Implement policy-driven identity controls using Conditional Access, identity protection, and leastprivilege enforcement
- Proactively identify identity-related risks and improvement opportunities without dependency on external direction
- Ensure identity controls align with Zero Trust security architecture
Required Skills
- 10+ years of hands-on experience with:
- Active Directory (multi-domain / forest)
- Microsoft Entra ID (Azure AD)
- DNS administration and troubleshooting
- Azure B2B and B2C concepts
- Strong understanding of:
- Identity lifecycle management
- SSO, MFA, Conditional Access
- Authentication protocols (LDAP, SAML, OAuth, OpenID Connect)
- Agentic identity, Non human Identity management.
- Experience with PowerShell automation
- Solid grasp of identity security and Zero Trust principles
- Strong problem-solving and communication skills
📌 Identity & Access Management Engineer (AD, Entra ID, Agentic identity) (Mumbai)
🏢 Crisil
📍 Mumbai