Lead delivery engineer for two access-security workstreams executed back-to-back: (1) migrating a legacy ERP thick client (Microsoft Dynamics NAV / Navision) to Citrix-published delivery with OKTA MFA enforced at the Citrix Gateway and retirement of local client distribution; (2) restricting a web-based workflow platform (OpenText Process360) to MFA-backed Citrix-only access with direct-URL bypass paths closed and privileged-access separation. You own thetechnical design, build, pilot, UAT support, cutover, and hypercare for both, operating inside enterprise change management.Key Responsibilities
- Produce the Technical Design Document: Citrix published-application architecture, Gateway authentication/MFApolicy, session policies (clipboard, drive mapping, printing), and AD security-group entitlement model
- Validate OKTA-to-Citrix Gateway federation state and bind application MFA policy (with IAM support in Week 1)
- Install and validate the Navision thick client on VDA servers; publish as a Citrix seamless application mapped to agoverned AD security group
- Run a structured pilot with finance power users; support business UAT and execute wave-based user migrationwith a fallback path
- Specify Software Center package retirement and GPO/AppLocker blocking for residual local installs; verifyexecution and produce compliance evidence
- For the second workstream: inventory application access paths and dependent URLs; design and deploy direct URL blocking rules at the approved enforcement point (reverse proxy / F5 / firewall / IIS); implement admin/user route separation with least privilege over the application's existing profile-based authorization
- Support regression and bypass-attempt testing; execute production cutovers under approved change records
with rehearsed rollback; deliver runbooks and one-week hypercare per workstreamRequired Skills & Experience
- 7+ years Citrix engineering: CVAD and/or Citrix Cloud (DaaS), VDA build and image management, Delivery Groups,
StoreFront/Workspace, seamless application publishing
- Hands-on Citrix Gateway (NetScaler/ADC) authentication policy configuration, including SAML/OIDC federationwith an IdP (OKTA strongly preferred 3+ years IAM exposure: MFA policy design, AD security-group entitlement models, least-privilege and accessreview concepts
- Experience virtualizing legacy thick-client/ERP applications on multi-session Windows Server without backendmodification
📌 Lead Software Engineer (Bengaluru)
🏢 Virtusa
📍 Bengaluru
Reply to this offer
Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.