Consultant, Identity & Access Management Karn 560087
Cargill · Consumer Goods (FMCG)
- Bangalore, India
- On-site
- Posted today
- Cybersecurity
About the job
Job Purpose and Impact
We are looking for an Active Directory / Entra ID Consultant to support day-to-day operations, incident resolution, security activities and automation. The role will primarily focus on Microsoft Active Directory, with additional responsibility for Microsoft Entra ID and hybrid identity services.
Key Accountabilities
Active Directory
Administer Active Directory users, groups, computers, OUs, delegation, GPOs, domain trusts, and related security configurations.
Provide L2/L3 support for domain controllers, authentication, authorization, replication, DNS, service availability, and overall AD health.
Troubleshoot complex issues involving login failures, account lockouts, access errors, GPO processing, replication, Kerberos, and domain connectivity.
Perform AD object restoration and support account, group, computer, and directory recovery activities.
Support the engineering and implementation of OU structures, OU-level delegations, subnet additions, domain trusts, Kerberos constrained delegation, and process-account password settings.
Support domain controller promotions and demotions, server capacity and uptime issues, backups, restores, disaster recovery, and business continuity activities.
Support AD security reviews, audits, password policies, hardening, remediation, and related compliance activities.
Implement and manage AD changes in line with approved engineering practices, request procedures, security requirements, and operational standards.
Develop and maintain PowerShell scripts for AD administration, reporting, auditing, health monitoring, object management, and operational automation.
Participate in AD migrations, upgrades, domain registrations, and service-improvement initiatives while maintaining accurate procedures, technical documentation, and knowledge articles.
Microsoft Entra ID
Support Microsoft Entra ID users, groups, roles, permissions, Enterprise Applications, App Registrations, SSO, MFA, Conditional Access, and application access.
Support Entra Connect and hybrid identity synchronization, including filtering, attribute mapping, synchronization health, and error resolution.
Support SAML and OAuth/OIDC-based SSO integrations, including metadata exchange, claims and attribute mapping, certificates, secrets, and authentication troubleshooting.
Support SSO secret and certificate-renewal activities, including monitoring expiry, coordinating renewals, updating approved configurations, and validating application connectivity.
Work with Microsoft Graph and other approved APIs for identity administration, reporting, application integration, and operational automation.
Support CI/CD based Entra and SSO configuration changes using GitHub, YAML configuration files, branches, pull requests, peer reviews, approvals, and controlled deployments.
Perform Entra ID health checks and review sign-in logs, audit logs, service health, and application connectivity to support incident resolution and continuous improvement.
Other Expectations
-
Own assigned incidents, service requests, changes, and project tasks through to completion, demonstrating accountability and a bias for action within the assigned scope.
Work independently on routine activities and seek guidance for complex or high-risk changes.
Communicate clearly and proactively with technical teams, stakeholders, and service owners.
Share knowledge with other team members and contribute to consistent operating practices.
Qualifications
Minimum requirement of 3-6 years of relevant work experience with Active Directory and Entra.
Good to have experience with Identity Governance and Administration (IGA) platforms such as SailPoint or Saviynt, ServiceNow for identity-related requests, incidents, changes, and workflow management, and Microsoft SC-300 or an equivalent Microsoft identity certification.