TymblHub

© 2026 TymblHub

Identity & Access Management Engineer (AD, Entra ID, Agentic identity)

Crisil
Posted on
Crisil logo

Experience
8 - 9 yrs
Job Location
Mumbai, India
Vacancy
1
Designation
Identity and Access Management Engineer
Job Type
ONSITE

Job Description

Senior Identity & Access Management Engineer

(Active Directory, Entra ID, Agentic identity)

Experience: 10+ Years
Location: Mumbai
Work Mode: Work From Office
Role Type: Senior Individual Contributor (L3 / L4)

Role Summary

We are hiring a Senior IAM Engineer with strong hands-on experience in Active Directory, Microsoft Entra ID (Azure AD), and DNS to support and enhance enterprise identity platforms. This role highly requires ownership. You will be the organization’s subject-matter expert responsible for designing, deploying, and governing identities for AI agents, service principals, managed identities, and non-human identities (NHIs) across Microsoft Entra ID and associated cloud environments. You will ensure that every agent — whether it reads a SharePoint file, triggers a Power Automate flow, or calls an external API — operates under a least-privilege, auditable, and governable identity model.

 

Key Responsibilities

  • Design, implement, and maintain enterprise-scale Active Directory and Entra ID infrastructures, ensuring high availability, security, and scalability.
  • Lead identity lifecycle management, including provisioning, deprovisioning, access reviews, and role-based access control (RBAC).
  • Manage and optimize DNS infrastructure to support seamless authentication and directory services.
  • Develop and enforce identity governance policies, integrating agentic identity principles by empowering users and automating secure access workflows.
  • Collaborate with cross-functional teams to architect and deploy secure authentication and authorization solutions (e.g., SSO, MFA, conditional access).
  • Deep understanding of OAuth 2.0 flows: Authorization Code, Client Credentials, Device Code, and On-Behalf-Of (OBO).
  • OpenID Connect (OIDC) for identity federation — how ID tokens, access tokens, and refresh tokens work.
  • SAML 2.0: assertions, IdP-initiated vs SP-initiated SSO, attribute mapping.
  • Multi-Factor Authentication (MFA): TOTP, FIDO2/Passkeys, Windows Hello for Business, and Conditional Access policy construction.
  • Monitor, troubleshoot, and resolve complex directory and DNS issues, leveraging advanced diagnostic tools and logs.
  • Drive continuous improvement by proactively identifying areas for automation, efficiency, and enhanced user experience.
  • Zero Trust & Security Principles for identity and access management.
  • identity management, cloud security, and agentic identity frameworks.
    • Agentic Identity Architecture & Design, Define and maintain the Agentic Identity Framework for all AI agents operating in the organization — spanning managed identities, service principals, workload federation, and delegated permissions.
    • Design agent-to-agent and agent-to-human trust models including Entra Workload Identity Federation for keyless authentication.
    • Implementation & Engineering, Deploy and manage Managed Identities (system-assigned and user-assigned) for Azure-hosted AI workloads and automation pipelines.
    • Implement scoped API permissions in Microsoft Graph API and enforce admin consent policies to prevent over-privileged agent access.
    • Integrate agent identities into Privileged Identity Management (PIM) for just-in-time access and approval workflows.
    • Build and maintain Identity Governance policies — access reviews, entitlement management, and lifecycle workflows — covering agent identities in addition to human users.
    • Security, Compliance & Governance, Enforce Zero Trust principles for all agentic workloads: verify explicitly, use least privilege, assume breach.
    • Monitor agent identity signals through Microsoft Entra Identity Protection, Defender for Cloud Apps, and Microsoft Sentinel; respond to anomalous or over-privileged activity.
    • Implement policy-driven identity controls using Conditional Access, identity protection, and leastprivilege enforcement
    • Proactively identify identity-related risks and improvement opportunities without dependency on external direction
    • Ensure identity controls align with Zero Trust security architecture

 

Required Skills

  • 10+ years of hands-on experience with:
    • Active Directory (multi-domain / forest)
    • Microsoft Entra ID (Azure AD)
    • DNS administration and troubleshooting
    • Azure B2B and B2C concepts
  • Strong understanding of:
    • Identity lifecycle management
    • SSO, MFA, Conditional Access
    • Authentication protocols (LDAP, SAML, OAuth, OpenID Connect)
    • Agentic identity, Non human Identity management.
  • Experience with PowerShell automation
  • Solid grasp of identity security and Zero Trust principles
  • Strong problem-solving and communication skills

 

Senior Identity & Access Management Engineer

(Active Directory, Entra ID, Agentic identity)

Experience: 10+ Years
Location: Mumbai
Work Mode: Work From Office
Role Type: Senior Individual Contributor (L3 / L4)

Role Summary

We are hiring a Senior IAM Engineer with strong hands-on experience in Active Directory, Microsoft Entra ID (Azure AD), and DNS to support and enhance enterprise identity platforms. This role highly requires ownership. You will be the organization’s subject-matter expert responsible for designing, deploying, and governing identities for AI agents, service principals, managed identities, and non-human identities (NHIs) across Microsoft Entra ID and associated cloud environments. You will ensure that every agent — whether it reads a SharePoint file, triggers a Power Automate flow, or calls an external API — operates under a least-privilege, auditable, and governable identity model.

 

Key Responsibilities

  • Design, implement, and maintain enterprise-scale Active Directory and Entra ID infrastructures, ensuring high availability, security, and scalability.
  • Lead identity lifecycle management, including provisioning, deprovisioning, access reviews, and role-based access control (RBAC).
  • Manage and optimize DNS infrastructure to support seamless authentication and directory services.
  • Develop and enforce identity governance policies, integrating agentic identity principles by empowering users and automating secure access workflows.
  • Collaborate with cross-functional teams to architect and deploy secure authentication and authorization solutions (e.g., SSO, MFA, conditional access).
  • Deep understanding of OAuth 2.0 flows: Authorization Code, Client Credentials, Device Code, and On-Behalf-Of (OBO).
  • OpenID Connect (OIDC) for identity federation — how ID tokens, access tokens, and refresh tokens work.
  • SAML 2.0: assertions, IdP-initiated vs SP-initiated SSO, attribute mapping.
  • Multi-Factor Authentication (MFA): TOTP, FIDO2/Passkeys, Windows Hello for Business, and Conditional Access policy construction.
  • Monitor, troubleshoot, and resolve complex directory and DNS issues, leveraging advanced diagnostic tools and logs.
  • Drive continuous improvement by proactively identifying areas for automation, efficiency, and enhanced user experience.
  • Zero Trust & Security Principles for identity and access management.
  • identity management, cloud security, and agentic identity frameworks.
    • Agentic Identity Architecture & Design, Define and maintain the Agentic Identity Framework for all AI agents operating in the organization — spanning managed identities, service principals, workload federation, and delegated permissions.
    • Design agent-to-agent and agent-to-human trust models including Entra Workload Identity Federation for keyless authentication.
    • Implementation & Engineering, Deploy and manage Managed Identities (system-assigned and user-assigned) for Azure-hosted AI workloads and automation pipelines.
    • Implement scoped API permissions in Microsoft Graph API and enforce admin consent policies to prevent over-privileged agent access.
    • Integrate agent identities into Privileged Identity Management (PIM) for just-in-time access and approval workflows.
    • Build and maintain Identity Governance policies — access reviews, entitlement management, and lifecycle workflows — covering agent identities in addition to human users.
    • Security, Compliance & Governance, Enforce Zero Trust principles for all agentic workloads: verify explicitly, use least privilege, assume breach.
    • Monitor agent identity signals through Microsoft Entra Identity Protection, Defender for Cloud Apps, and Microsoft Sentinel; respond to anomalous or over-privileged activity.
    • Implement policy-driven identity controls using Conditional Access, identity protection, and leastprivilege enforcement
    • Proactively identify identity-related risks and improvement opportunities without dependency on external direction
    • Ensure identity controls align with Zero Trust security architecture

 

Required Skills

  • 10+ years of hands-on experience with:
    • Active Directory (multi-domain / forest)
    • Microsoft Entra ID (Azure AD)
    • DNS administration and troubleshooting
    • Azure B2B and B2C concepts
  • Strong understanding of:
    • Identity lifecycle management
    • SSO, MFA, Conditional Access
    • Authentication protocols (LDAP, SAML, OAuth, OpenID Connect)
    • Agentic identity, Non human Identity management.
  • Experience with PowerShell automation
  • Solid grasp of identity security and Zero Trust principles
  • Strong problem-solving and communication skills

 

 

No Referrers Available

There are currently no referrers available for this job. You can still apply, will let you know once there is any referrer available.