15 Sep
|
Important Company of the Sector
|
India
15 Sep
Important Company of the Sector
India
Job Title: T3-Level AD / SSO Support Engineer
- Entra ID, PingOne & IAM Experience: 7-12 Years Employment Type: Full-Time Role Overview We are looking for a highly experienced T3-Level AD / SSO Support Engineer with solid expertise in Active Directory, Identity & Access Management (IAM), SSO, Microsoft Entra ID, PingOne, security technologies, and automation . The ideal candidate should have hands-on experience supporting large-scale enterprise identity environments and managing business-critical platforms such as Entra ID and PingOne . The candidate should possess strong knowledge of identity protocols, authentication and authorization mechanisms, federation, security best practices, enterprise IAM architecture, troubleshooting, automation, and current identity/security trends . This role requires a strong production support and engineering mindset , with the ability to independently handle complex T3 escalations, perform root-cause analysis, implement permanent fixes, and continuously improve the reliability and security of identity services. Key Responsibilities 1. Active Directory
- T3 Support
- Provide advanced T3-level support for enterprise Active Directory environments.
- Troubleshoot complex issues related to AD authentication, domain services, DNS, Group Policy, LDAP, Kerberos, replication, and trust relationships .
- Analyze authentication failures, account lockouts, replication issues, Group Policy problems, and domain-related incidents.
- Perform detailed root-cause analysis (RCA) for recurring AD issues.
- Support large-scale, highly available enterprise AD environments.
- Work with infrastructure, networking, security, and application teams to resolve complex identity issues. 2. Microsoft Entra ID / Azure AD
- Provide advanced administration and troubleshooting for Microsoft Entra ID .
- Manage and troubleshoot enterprise applications, users, groups, authentication policies, MFA, Conditional Access, and identity synchronization .
- Support hybrid identity environments involving Active Directory and Entra ID .
- Troubleshoot Entra Connect / Azure AD Connect synchronization issues.
- Analyze sign-in logs, authentication failures, synchronization errors, and Conditional Access-related issues.
- Support secure application onboarding and enterprise SSO integrations.
- Implement and maintain Entra security best practices. 3. PingOne & SSO
- Provide T3-level support for PingOne / Ping Identity environments.
- Configure, troubleshoot, and maintain enterprise SSO integrations .
- Support application federation and authentication flows across enterprise and SaaS applications.
- Troubleshoot complex authentication and authorization issues.
- Work with application teams to onboard and integrate applications into the SSO platform.
- Configure and troubleshoot authentication policies, MFA, federation, and access controls.
- Monitor platform health and proactively identify potential authentication or availability issues. 4. Identity & Authentication Protocols Strong understanding of enterprise identity and authentication protocols, including:
- SAML 2.0
- OAuth 2.0
- OpenID Connect (OIDC)
- LDAP
- Kerberos
- WS-Federation
- Troubleshoot authentication flows by analyzing tokens, claims, certificates,
assertions, headers, logs, and protocol responses .
- Understand federation concepts including Identity Provider (IdP), Service Provider (SP), authentication, authorization, claims, and token validation .
- Troubleshoot complex cross-platform authentication and federation issues. 5. IAM & Security
- Apply robust Identity & Access Management (IAM) principles across enterprise environments.
- Implement and support least-privilege access, role-based access, MFA, privileged access, identity lifecycle management, and access governance .
- Follow enterprise security standards and identity security best practices.
- Identify potential security risks within authentication and access-management environments.
- Support security investigations involving identity, authentication, and access-related events.
- Stay updated on evolving IAM, cybersecurity, Zero Trust, authentication, and identity-security trends .
- Ensure identity platforms are configured according to enterprise security and compliance requirements. 6. Automation & Scripting
- Develop automation to reduce repetitive manual activities across AD, Entra ID, PingOne, and IAM operations.
- Use PowerShell, Python, REST APIs, or equivalent scripting technologies for automation. Automate activities such as:
- User and group management
- Access provisioning/deprovisioning
- Identity reporting
- Health checks
- Log analysis
- Application onboarding
- Troubleshooting and operational tasks
- Build reusable automation solutions that improve operational efficiency, accuracy, scalability, and security .
- Identify opportunities to automate recurring support and administration activities. 7. T3 Production Support & Troubleshooting
- Act as the highest-level technical escalation point for complex AD, SSO, IAM, and authentication incidents.
- Analyze application, identity, authentication, and infrastructure logs to identify root causes.
- Perform advanced troubleshooting across multiple technology layers.
- Lead technical resolution of P1/P2 production incidents when required.
- Perform detailed RCA, corrective actions, and preventive actions .
- Identify recurring issues and implement permanent solutions.
- Work closely with L1/L2 support teams to provide technical guidance and knowledge transfer.
- Participate in incident, problem, change, and release management processes. 8. Enterprise Application & SSO Integration
- Integrate enterprise and SaaS applications with Entra ID and PingOne .
- Analyze application authentication requirements and recommend appropriate identity protocols.
- Support SSO onboarding, configuration, testing, and production deployment.
- Troubleshoot issues related to SAML assertions, claims, certificates, redirects, tokens, endpoints, and authentication policies .
- Collaborate with application owners, developers,
security teams, and vendors to resolve integration issues.
- Ensure application integrations follow enterprise security and architecture standards. 9. Monitoring & Operational Excellence
- Monitor the health, availability, and performance of enterprise identity platforms.
- Analyze authentication and sign-in logs to identify abnormal patterns and recurring issues.
- Establish proactive monitoring and alerting for critical identity services.
- Develop dashboards and reports for identity-platform health and operational metrics.
- Identify opportunities to improve platform availability, reliability, security, and performance .
- Maintain technical documentation, knowledge articles, SOPs, troubleshooting guides, and operational runbooks. 10. Identity Architecture & Industry Trends
- Understand enterprise-scale IAM and SSO architecture and the interaction between identity, applications, infrastructure, and security.
- Provide technical recommendations for improving identity-platform architecture.
- Evaluate new identity technologies, security capabilities, and automation opportunities. Stay current with industry developments in:
- Zero Trust
- Cloud IAM
- Passwordless authentication
- Identity threat detection
- Privileged Identity Management
- Adaptive authentication
- Modern authentication protocols
- Identity governance
- AI-assisted security and automation
- Contribute to continuous improvement of enterprise identity services. Must-Have Technical Skills
- Robust hands-on experience with Microsoft Active Directory .
- Solid experience with Microsoft Entra ID / Azure AD .
- Hands-on experience with PingOne / Ping Identity .
- Strong experience in enterprise SSO and IAM .
- Strong understanding of SAML 2.0, OAuth 2.0, OIDC, LDAP, Kerberos, and WS-Federation .
- Advanced troubleshooting and T3-level production support experience.
- Strong knowledge of authentication, authorization, federation, MFA, and Conditional Access .
- Experience with hybrid AD / Entra identity environments .
- Experience troubleshooting Entra Connect / Azure AD Connect .
- Strong understanding of enterprise security and IAM best practices.
- Strong PowerShell and/or Python scripting skills.
- Experience with REST APIs and automation .
- Strong experience with log analysis, RCA, incident management, and problem management .
- Experience supporting large-scale enterprise deployments .
- Strong analytical, troubleshooting, and problem-solving skills. Good-to-Have Skills
- Experience with Microsoft Entra ID Governance .
- Microsoft Entra Privileged Identity Management (PIM) .
- Experience with Microsoft Defender for Identity .
- Knowledge of SCIM provisioning .
- Experience with identity governance and access reviews.
- Knowledge of Zero Trust architecture .
- Experience with passwordless authentication / FIDO2 .
- Experience with API-based identity integrations .
- Knowledge of Azure or AWS cloud security .
- Experience with IAM monitoring and observability tools .
- Knowledge of certificate management and PKI .
- Experience with CI/CD and DevSecOps .
- Exposure to AI-assisted tools for automation, troubleshooting …
📌 IAM and eMail Security Program Professional (Hyderabad) (India)
🏢 Important Company of the Sector
📍 India