10 Sep
|
ConglomerateIT
|
Telangana
10 Sep
ConglomerateIT
Telangana
Role: Azure AD B2C Lead
Location: Hyderabad, India
This is a technical leadership role focused on Azure AD B2C / Microsoft Entra External ID, customer identity architecture, hands-on delivery, platform modernization, and cross-functional technical direction. The Lead is expected to establish standards and target-state architecture while remaining sufficiently hands-on to implement, troubleshoot, and drive critical identity initiatives.
What We Need This Lead To Own
- Lead the end-to-end architecture, implementation, modernization, and operational maturity of Bose's customer identity platform using Azure AD B2C / Microsoft Entra External ID.
- Serve as the primary technical lead and subject matter expert for Azure customer identity, with strong working knowledge of the broader Azure environment, services, architecture patterns, dependencies, and platform capabilities.
- Design secure, scalable, and seamless authentication and authorization experiences across Bose customer-facing digital platforms, including web, mobile, e-commerce, support, and connected-product ecosystems.
- Provide technical leadership across identity architecture and broader Azure platform decisions, connecting customer identity requirements to cloud, application, API, security, and platform engineering needs.
- Define target-state identity architecture, reusable enterprise patterns, engineering standards, and implementation guidance.
- Remain hands-on with custom policies, integrations, automation, troubleshooting, architecture validation, and critical delivery work.
- Lead technical decisions, architecture reviews, design discussions, and resolution of complex identity and Azure platform issues.
- Apply FinOps principles and practical cloud-security judgment to architecture and implementation decisions.
Core Technical Responsibilities 1. Azure AD B2C / Microsoft Entra External ID Leadership & Architecture
- Architect and implement Azure AD B2C / Microsoft Entra External ID tenant configurations for customer-facing applications.
- Own user journeys, custom policies, built-in user flows, identity providers, claims providers, and orchestration steps.
- Build secure authentication experiences for sign-up, sign-in, account linking, password reset, profile updates, and account recovery.
- Configure and optimize social identity provider integrations and other required external identity providers.
- Design scalable identity patterns supporting multiple applications, brands, regions, and customer segments.
- Establish tenant strategy, environment separation, configuration management, release governance, and reusable implementation standards across development, test, staging, and production.
- Lead technical reviews and provide direction to engineers implementing customer identity capabilities.
2. Azure Architecture & Cloud Platform
- Provide architectural leadership beyond B2C, demonstrating strong understanding of Azure services, resources, networking, compute, storage, integration, monitoring, security, and platform dependencies.
- Evaluate architecture choices across the Azure environment and ensure identity services integrate effectively with broader cloud platforms and enterprise applications.
- Guide scalability, availability, resiliency, performance, operational readiness, and platform modernization decisions.
- Translate business and application requirements into secure, scalable, maintainable Azure architecture patterns.
- Collaborate with cloud engineering, platform, application, security, and infrastructure teams on cross-platform architecture decisions.
3. Authentication, Authorization, IAM & Customer Identity Experience
- Lead contemporary authentication patterns including MFA, adaptive authentication, passwordless authentication, biometric authentication support, and risk-based access controls where applicable.
- Define secure session management, token lifecycle, refresh-token handling, logout behavior, and single sign-on patterns.
- Implement and govern OAuth 2.0, OpenID Connect, SAML, JWT, federation, SSO, MFA, and API authorization standards.
- Apply IAM principles to customer and application identity use cases, including authentication, authorization, federation, identity lifecycle, and access controls.
- Architect role-based and attribute-based authorization models for customer, partner, support, and administrative access scenarios.
- Lead customer account linking, identity federation, duplicate-account handling, and account migration strategies.
4. Application, API & Digital Platform Integration
- Lead integration of Azure AD B2C / Entra External ID with web applications, mobile applications, APIs, microservices, e-commerce platforms, CRM platforms, and customer-support systems.
- Design secure API access patterns using scopes, app registrations, API permissions, token validation, and delegated/application authorization models.
- Guide application engineering teams on identity SDKs, authentication middleware, authorization controls, and secure token handling.
- Support integrations with customer profile platforms, marketing platforms, loyalty systems, commerce systems, and connected-device ecosystems.
- Define API gateway and backend-service authentication patterns for customer-facing and machine-to-machine interactions.
- Ensure identity architecture supports scalable digital experiences across global markets and high-volume customer traffic.
5. Custom Policy Engineering & Identity Automation
- Develop and maintain Azure AD B2C custom policies using Identity Experience Framework (IEF).
- Build reusable policy components, claims transformations, technical profiles, REST API integrations, and orchestration patterns.
- Integrate custom policies with external REST APIs for customer validation, entitlement checks, fraud controls, profile enrichment, consent validation, and account lifecycle workflows.
- Automate tenant configuration, policy deployment, application registrations, secret rotation, and environment promotion using Infrastructure as Code and CI/CD pipelines.
- Build version-controlled deployment patterns for B2C policies, configuration artifacts, and application integration settings.
- Establish automated testing, validation, rollback, and release controls for identity configuration changes.
6. FinOps & Cloud Cost Management
- Apply FinOps principles to cloud architecture, resource utilization, cost visibility, optimization, governance, and accountability.
- Evaluate architecture and resource decisions for cost efficiency without compromising security, performance, scalability, or reliability.
- Partner with cloud/platform teams to identify optimization opportunities, establish cost controls, and improve ongoing cloud financial governance.
7. Security, Privacy & Compliance
- Apply strong practical cloud-security knowledge to Azure and identity architecture; deep cybersecurity specialization is not required.
- Design identity controls aligned with enterprise security, privacy, and compliance requirements.
- Implement secure handling of customer PII, consent records, preferences, authentication data, and profile attributes.
- Apply least-privilege access, privileged-access controls, certificate management, secret management, and secure credential lifecycle practices.
- Partner with cybersecurity, privacy, legal, and compliance teams to ensure customer identity architecture supports applicable regulatory obligations.
- Define audit logging, monitoring, anomaly detection, and investigation capabilities for authentication events and identity-related security incidents.
- Ensure identity design aligns with Zero Trust principles, secure-by-design practices, and Bose enterprise security standards.
8. Monitoring, Observability & Operational Readiness
- Implement monitoring and observability for authentication success/failure rates, policy errors, token issues, suspicious login activity, and external identity provider failures.
- Integrate identity telemetry with enterprise monitoring and logging platforms such as New Relic, LogicMonitor, Azure Monitor, Application Insights, and SIEM platforms.
- Define operational dashboards, alert thresholds, service health monitoring, and incident-response procedures for customer identity services.
- Build automated diagnostics and remediation workflows for recurring authentication, policy, and integration failures.
- Drive reduction of customer-impacting identity incidents through proactive monitoring, root-cause analysis, and resilient architecture patterns.
- Establish runbooks, support procedures, escalation paths, and operational documentation for identity platform support teams.
9. Technical Leadership, Governance & Stakeholder Management
- Define enterprise standards for customer identity architecture, authentication patterns,
authorization models, application onboarding, custom-policy development, and release practices.
- Lead architecture reviews for new customer-facing applications and integrations requiring Azure AD B2C / Entra External ID.
- Act as the technical escalation point for complex identity architecture, implementation, integration, and production issues.
- Partner with product, engineering, security, privacy, e-commerce, mobile, cloud, and support teams to translate business requirements into secure identity and Azure solutions.
- Provide technical guidance, design reviews, mentoring, and troubleshooting support to developers, platform engineers, and support teams.
- Document architecture decisions, integration patterns, custom-policy standards, security controls, FinOps considerations, and operational procedures.
- Drive roadmap planning for modernization, feature adoption, migration, scalability, cost optimization, and long-term platform maturity.
Required Technical Background
- Hands-on experience in Identity and Access Management, authentication, authorization, customer identity, Azure architecture, or closely related architecture/leadership roles.
- Deep hands-on experience with Azure AD B2C / Microsoft Entra External ID, including claims transformations, technical profiles, REST API integrations, custom user journeys, and identity-provider integrations.
- Strong understanding of customer identity, customer profile management, consent, account lifecycle, and customer authentication experience design.
- Experience integrating identity platforms with web applications, mobile applications, APIs, microservices, and cloud-native platforms.
- Proficiency with Azure services such as Azure Key Vault, Azure Monitor, Application Insights, Azure DevOps, API Management, Functions, and Microsoft Graph.
- Experience implementing CI/CD pipelines and Infrastructure as Code for identity configurations and application integrations.
- Strong knowledge of identity security, token security, secrets management, encryption, logging, auditing, and Zero Trust principles.
- Demonstrated ability to lead technical discussions, influence engineering decisions, and communicate effectively with technical teams, product stakeholders, security teams, cloud/platform teams, and senior leadership.
- Ability to balance architecture ownership with hands-on implementation and production troubleshooting.
Preferred Qualifications
- Multi-cloud experience across Azure, AWS, or other major cloud platforms.
- Experience applying FinOps across more than one cloud platform.
- Experience with Microsoft Entra ID, Entra ID Governance, Conditional Access, Privileged Identity Management, or related IAM capabilities.
- Experience migrating customer identity platforms from legacy IAM, custom authentication systems, Okta, Auth0, Ping Identity, ForgeRock, or similar platforms.
- Experience with customer-facing e-commerce, mobile, connected-device, consumer-product, or high-volume digital platforms.
- Experience integrating with CRM, CDP, marketing automation, loyalty, commerce, or customer-support platforms.
- Experience with API gateways, microservices security, service-to-service authentication, and cloud-native authorization.
- Experience with Azure DevOps, GitHub Actions, Terraform, Bicep, ARM templates, PowerShell, Python, or REST API automation.
- Familiarity with privacy and compliance requirements affecting customer identity and PII, including GDPR, CCPA, and consent-management practices.
- Experience integrating identity telemetry with SIEM, SOC workflows, and enterprise incident-management processes.
Founded in 2014, ConglomerateIT is a global leader in delivering innovative IT solutions and services. Headquartered in the USA with a presence in the UK, Canada, and India, we specialize in offering industry-leading expertise and cutting-edge products that help our clients maximize their technological investments. Our focus on best-in-class solutions, a highly knowledgeable team, and proactive talent mapping ensure we remain at the forefront of the IT industry.
ConglomerateIT is driven by our Center for Excellence and Innovation, an initiative dedicated to keeping us ahead in a rapidly evolving technology landscape. We understand that building strong relationships is key to our success, and this commitment has enabled us to partner with Fortune 500 companies and leading system integrators worldwide. Our ability to provide local talent on a global scale ensures that we can meet the contingent project requirements of our clients efficiently and effectively.
📌 Azure ADC Lead (Telangana)
🏢 ConglomerateIT
📍 Telangana