…

Senior Engineer - Microsoft Entra / Identity & Access Management (IAM)

NTT DATA · IT Services & Consulting

  • Bangalore, IN-KA, India
  • Hybrid
  • Posted today
  • Cybersecurity

About the job

Req ID:   392115

NTT DATA strives to hire exceptional, innovative and passionate individuals who want to grow with us. If you want to be part of an inclusive, adaptable, and forward-thinking organization, apply now.

We are currently seeking a Senior Engineer - Microsoft Entra / Identity & Access Management (IAM) to join our team in Bangalore, Karnātaka (IN-KA), India (IN).

Job Description – Senior Engineer – Microsoft Entra / Identity & Access Management (IAM)

Experience: 8+ Years

Location: Preerred Bangalore

Technology: Microsoft Entra ID / Azure Active Directory

Domain: Identity & Access Management (IAM) / Cybersecurity

Position Summary

We are seeking an experienced Senior Microsoft Entra / Identity & Access Management (IAM) Engineer with strong hands-on expertise in designing, implementing, securing, automating, and supporting enterprise identity solutions using Microsoft Entra ID (formerly Azure Active Directory) and related Microsoft identity technologies.

The ideal candidate will have deep technical experience across identity architecture, authentication, authorization, SSO, MFA, Conditional Access, Privileged Identity Management (PIM), Identity Governance, hybrid identity, application integration, and identity lifecycle management.

This is a senior hands-on engineering role, not primarily an IAM administration position. The successful candidate should demonstrate the ability to independently design IAM solutions, lead complex application integrations, automate identity processes, troubleshoot advanced authentication and provisioning issues, and provide technical leadership.

The engineer will collaborate with Cybersecurity, Cloud, Infrastructure, Application, Architecture, Compliance, and Operations teams to deliver scalable identity solutions aligned with Zero Trust and least-privilege security principles.

Key Responsibilities

Microsoft Entra ID Engineering

Design, implement, configure, and support Microsoft Entra ID solutions across complex enterprise environments.
Develop secure and scalable identity architectures for cloud, SaaS, on-premises, and hybrid environments.
Translate security and business requirements into detailed IAM technical designs.
Establish reusable identity engineering patterns, standards, and implementation approaches.
Lead technical implementation of IAM modernization and migration initiatives.

Authentication & Access Management

Design and implement enterprise authentication and authorization solutions involving:
Single Sign-On (SSO)
Multi-Factor Authentication (MFA)
Passwordless Authentication
FIDO2
Windows Hello for Business
Role-Based Access Control (RBAC)
Federation
Develop and maintain Conditional Access policies based on user, device, application, location, authentication strength, and identity risk.
Implement access models based on Zero Trust and least-privilege principles.
Support Entra ID Protection, identity-risk detection, investigation, and remediation.

Application Integration & Federation

Integrate enterprise, cloud, and SaaS applications with Microsoft Entra ID.
Design and troubleshoot identity integrations using:
SAML 2.0
OAuth 2.0
OpenID Connect (OIDC)
SCIM
Configure and support Enterprise Applications and App Registrations.
Lead migrations from legacy authentication and federation platforms to Microsoft Entra ID.
Participate in application architecture and security reviews to define appropriate identity-integration patterns.

Identity Governance & Lifecycle Management

Design, implement, and manage Microsoft Entra ID Governance capabilities.
Configure and support:
Access Reviews
Entitlement Management
Access Packages
Lifecycle Workflows
Identity Governance policies
Engineer identity lifecycle processes covering Joiner, Mover, and Leaver (JML) scenarios.
Develop automated provisioning and deprovisioning processes.
Support access certification and periodic entitlement reviews.

Privileged Identity Management

Design, implement, and administer Microsoft Entra Privileged Identity Management (PIM).
Implement Just-in-Time (JIT) privileged access and least-privilege controls.
Establish appropriate approval, activation, expiration, and access-review processes for privileged roles.
Reduce standing administrative privileges and improve governance of elevated access.

Hybrid Identity

Design and support hybrid identity solutions integrating on-premises Active Directory with Microsoft Entra ID.
Implement and support Entra Connect and Cloud Sync.
Troubleshoot directory synchronization, authentication, provisioning, and federation issues.
Support migration and modernization from traditional on-premises identity environments to cloud-based identity services.

IAM Automation

Automate IAM administration, provisioning, governance, and operational activities using:
PowerShell
Microsoft Graph API
REST APIs
Infrastructure-as-Code approaches, where applicable
Develop reusable automation scripts and engineering components.
Identify manual identity processes that can be automated to improve efficiency, consistency, and security.
Support integration of IAM engineering with DevOps and CI/CD practices where appropriate.

Advanced Troubleshooting & Security Monitoring

Troubleshoot complex issues involving:
Authentication
Authorization
SSO
Federation
Provisioning
Synchronization
Conditional Access
Application access
Analyze sign-in logs, audit logs, provisioning logs, and security events to diagnose identity-related issues.
Conduct root-cause analysis for complex or recurring IAM incidents.
Partner with Security Operations/SOC teams to investigate identity-related security events.
Support production incidents and drive issues through resolution.

Zero Trust & Identity Security

Partner with cybersecurity teams to implement Zero Trust identity architecture.
Implement controls supporting continuous verification, strong authentication, least privilege, and risk-based access.
Identify identity-related security and operational risks and recommend appropriate controls.
Participate in cybersecurity architecture, application security, and IAM risk reviews.

Technical Leadership

Own IAM solutions from requirements and technical design through implementation and production support.
Develop architecture diagrams, technical designs, implementation plans, operational procedures, and engineering documentation.
Lead complex IAM implementations, migrations, and troubleshooting activities.
Establish engineering standards and reusable identity patterns.
Conduct technical design and peer reviews.
Mentor junior and mid-level IAM engineers.
Provide technical recommendations to security, architecture, and technology leadership.

Required Technical Skills

Candidates should demonstrate strong hands-on experience with:

Microsoft Entra ID / Azure Active Directory
Entra Conditional Access
Multi-Factor Authentication (MFA)
Passwordless Authentication
FIDO2 / Windows Hello for Business
Entra Privileged Identity Management (PIM)
Entra ID Governance
Entra ID Protection
Enterprise Applications & App Registrations
SSO & Federation
SAML 2.0
OAuth 2.0
OpenID Connect (OIDC)
SCIM Provisioning
Active Directory
Hybrid Identity
Entra Connect / Cloud Sync
Microsoft Graph API
PowerShell Automation
RBAC & Least-Privilege Access
Identity Lifecycle Management / JML
Authentication & Provisioning Troubleshooting
Identity Security Logging & Monitoring

Required Experience

8+ years of IAM, Identity Engineering, Cybersecurity, or related experience.
5+ years of significant hands-on experience with Microsoft Entra ID / Azure Active Directory.
5+ years of proven experience designing and implementing enterprise IAM solutions rather than primarily performing operational administration.
3+ years of strong experience with complex SSO and application integrations.
3+ years of hands-on experience with Conditional Access, MFA, PIM, Identity Governance, and hybrid identity.
3+ yeas of experience developing IAM automation using PowerShell and Microsoft Graph API.
1 to 3 years of strong understanding of identity security and Zero Trust architecture.
Demonstrated ability to independently troubleshoot complex identity and access issues.
Strong technical documentation, communication, analytical, and problem-solving skills.

Preferred Qualifications

Experience supporting large-scale enterprise or multi-tenant Entra environments.
Experience migrating applications from legacy authentication/federation technologies to Entra ID.
Experience integrating Entra with:
Microsoft 365
Microsoft Azure
Endpoint/device-management platforms
SIEM/SOC solutions
Third-party SaaS applications
Familiarity with other IAM/PAM platforms such as SailPoint, Saviynt, Okta, CyberArk, or Ping Identity.
Experience with Infrastructure as Code and/or CI/CD approaches for IAM deployments.
Familiarity with security and regulatory frameworks such as NIST, ISO 27001, SOC 2, and PCI DSS.

Preferred Certifications

Microsoft Certified: Identity and Access Administrator Associate (SC-300)
Microsoft Certified: Cybersecurity Architect Expert (SC-100)
Microsoft Azure/Security certifications
CISSP
Other relevant IAM or cybersecurity certifications

Senior-Level Expectations

The Senior Entra IAM Engineer should operate with limited technical supervision and demonstrate capabilities beyond routine Microsoft Entra administration.

Candidates should have proven expertise in:

Hands-on Entra engineering
IAM solution architecture and technical design
Complex SSO/application integrations
Advanced authentication and provisioning troubleshooting
IAM automation using PowerShell/Graph API
Conditional Access and security policy engineering
Zero Trust and least-privilege implementation
Technical leadership and mentoring

The ideal profile can be summarized as:

Senior Entra IAM Engineer = Hands-on Engineering + Solution Design + Complex Integrations + Advanced Troubleshooting + Automation + Security Engineering + Technical Leadership

About NTT DATA

NTT DATA is a $30 billion business and technology services leader, serving 75% of the Fortune Global 100. We are committed to accelerating client success and positively impacting society through responsible innovation. We are one of the world's leading AI and digital infrastructure providers, with unmatched capabilities in enterprise-scale AI, cloud, security, connectivity, data centers and application services. our consulting and Industry solutions help organizations and society move confidently and sustainably into the digital future. As a Global Top Employer, we have experts in more than 50 countries. We also offer clients access to a robust ecosystem of innovation centers as well as established and start-up partners. NTT DATA is a part of NTT Group, which invests over $3 billion each year in R&D.

Whenever possible, we hire locally to NTT DATA offices or client sites. This ensures we can provide timely and effective support tailored to each client’s needs. While many positions offer remote or hybrid work options, these arrangements are subject to change based on client requirements. For employees near an NTT DATA office or client site, in-office attendance may be required for meetings or events, depending on business needs. At NTT DATA, we are committed to staying flexible and meeting the evolving needs of both our clients and employees. NTT DATA recruiters will never ask for payment or banking information and will only use @nttdata.com, @nttdatafed.com and @talent.nttdataservices.com email addresses. If you are requested to provide payment or disclose banking information, please submit a contact us form,  https://us.nttdata.com/en/contact-us .

NTT DATA endeavors to make https://us.nttdata.com  accessible to any and all users. If you would like to contact us regarding the accessibility of our website or need assistance completing the application process, please contact us at https://us.nttdata.com/en/contact-us .  This contact information is for accommodation requests only and cannot be used to inquire about the status of applications. NTT DATA is an equal opportunity employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or protected veteran status. For our EEO Policy Statement, please click here . If you'd like more information on your EEO rights under the law, please click here . For Pay Transparency information, please click here .