22 Aug
|
Nexifyr Consulting
|
Bengaluru
22 Aug
Nexifyr Consulting
Bengaluru
Experience: 3-6 years
Mode of Work: (Hybrid – 3 Days Work From Office)
Location: Whitefield, Bangalore
Key Responsibilities
- • Design, develop, and maintain Terraform modules to provision and manage Microsoft Entra ID resources, including PIM role assignments, eligible/active role settings, and access review policies.
- • Implement and automate Just-In-Time (JIT) privileged access workflows using Entra ID PIM for both Entra roles and Azure resource roles.
- • Build and maintain CI/CD pipelines (Azure DevOps / GitHub Actions) to deploy and test Terraform-based identity infrastructure changes.
- • Configure and manage PIM approval workflows, access reviews, notification settings, and role activation policies (MFA, justification, approval chains).
- • Integrate Terraform automation with Microsoft Graph API / AzAPI provider for advanced Entra ID configuration not covered by standard providers.
- • Collaborate with security, identity, and platform teams to define least-privilege access models and enforce Zero Standing Privilege (ZSP) principles.
- • Monitor, audit, and report on privileged role activations, PIM alerts, and compliance posture; remediate drift between code and live configuration.
- • Write clean, reusable, and well-documented Terraform code following IaC best practices (state management, modularity, version control).
- • Troubleshoot access-related incidents and support audits by providing evidence of automated access controls.
- • Contribute to internal documentation, runbooks, and knowledge-sharing on Entra ID PIM and Terraform automation practices.
- Required Skills & Experience
- • Hands-on experience with Microsoft Entra ID (Azure AD), including Privileged Identity Management (PIM) for both directory roles and Azure resource roles.
- • Strong working knowledge of Terraform, including module design, state management, workspaces, and provider configuration (AzureRM, AzureAD/Entra, AzAPI).
- • Experience with Microsoft Graph API for identity governance and automation use cases.
- • Solid understanding of Azure IAM concepts: RBAC, conditional access, access reviews, entitlement management, and just-in-time access.
- • Proficiency with a scripting/programming language such as PowerShell, Python, or Go for automation and tooling.
- • Experience with version control (Git) and CI/CD pipelines (Azure DevOps, GitHub Actions, or similar).
- • Familiarity with security and compliance frameworks (e.g., least privilege, Zero Trust, SOC 2, ISO 27001) as applied to identity access.
- • Robust troubleshooting skills and ability to work with cross-functional security and infrastructure teams.
Preferred Qualifications
- • Microsoft certifications such as SC-300 (Identity and Access Administrator) or AZ-104/AZ-400.
- • HashiCorp Terraform Associate certification.
- • Experience with Terraform Cloud/Enterprise, Sentinel policies, or OPA for policy-as-code.
- • Exposure to broader IAM tooling (e.g., Okta, SailPoint, CyberArk) and privileged access management (PAM) concepts.
- • Experience automating access reviews and compliance reporting for audit purposes.
- • Bachelor's degree in Computer Science, Information Security, or a related field, or equivalent practical experience.
📌 Developer – Microsoft Entra ID PIM & Terraform Automation (Bengaluru)
🏢 Nexifyr Consulting
📍 Bengaluru