Azure PIM (Privileged Identity Management) Senior Engineer
Primary stack
Nice to have's
Job description
About the Position
We are seeking an experienced Azure Privileged Identity Management (PIM) Senior Engineer to drive the design, implementation, automation, and governance of privileged access management within Microsoft Entra ID (Azure AD) and Azure environments. This role requires a highly skilled identity professional with proven expertise in managing Azure PIM end-to-end, including privileged role governance, access lifecycle management, automation, compliance, and security controls.
Responsibilities
- Lead the design, implementation, configuration, and ongoing administration of Microsoft Entra ID (Azure AD) Privileged Identity Management (PIM).
- Manage privileged access controls across Microsoft Entra ID, Azure subscriptions, management groups, resource groups, and Azure resources.
- Define and maintain privileged access governance policies, standards, operational procedures, and security controls aligned with enterprise requirements.
- Design and implement Just-In-Time (JIT) access, role eligibility, approval workflows, access reviews, Privileged Access Groups, and role activation policies.
- Perform privileged access assessments, role reviews, recertifications, and remediation of excessive or inappropriate access.
- Develop, maintain, and enhance automation solutions using Terraform, Git, CI/CD Pipelines, Ansible, PowerShell, and Python for identity and privileged access management.
- Build reusable Infrastructure-as-Code (IaC) modules and deployment frameworks for Azure PIM, role assignments, Service Principals, Managed Identities, and related identity governance controls.
- Design, customize, and support federation integrations and authentication workflows using automated CI/CD pipelines.
- Manage and troubleshoot federation configurations, claims transformations, token issuance policies, and authentication-related issues.
- Develop and maintain REST API-based integrations and automation workflows for identity lifecycle management.
- Manage the complete lifecycle of Service Principals, Enterprise Applications, and Managed Identities, including provisioning, governance, credential management, and decommissioning.
- Implement and manage secrets, certificates, credential rotation, expiration monitoring, and secure authentication practices for non-human identities.
- Automate onboarding, access assignment, certification, and retirement processes for privileged and service identities.
- Monitor privileged access activities and maintain reporting, dashboards, and audit evidence to support security, compliance, and operational requirements.
- Support internal and external audits, security reviews, risk assessments, and compliance initiatives related to privileged access management.
- Investigate and resolve identity, authentication, authorization, and privileged access issues across Azure environments.
- Collaborate with IAM, Security, Cloud Engineering, DevOps, and application teams to implement secure and scalable access management solutions.
- Drive continuous improvements in privileged access governance, identity security, automation, and operational efficiency.
Requirements
- 7+ years of experience in Identity and Access Management (IAM) and Microsoft Azure environments.
- Experience integrating identity security controls with enterprise DevSecOps practices.
- Terraform (Mandatory and Expert Level).
- Git-Based Source Control and Automation Frameworks (Mandatory and Expert Level).
- REST API Integrations and CI/CD Pipelines (Mandatory and Expert Level).
- PowerShell (Mandatory and Expert Level).
- Python (Mandatory and Expert Level).
- Microsoft Certified: Identity and Access Administrator Associate (SC-300).
- Microsoft Certified: Azure Security Engineer Associate (AZ-500).
- Microsoft Certified: Azure Administrator Associate (AZ-104).
- Experience supporting large enterprise or global Azure environments.
- Experience implementing Zero Trust security principles.
- Knowledge of cloud security, governance, and compliance frameworks.
Nice to Have
- Work in agile environment
We Offer
- Competitive salary
- Opportunity to work in a dynamic and innovative environment
- Professional growth and development opportunities
About the Company
Luxoft is a global leader in digital transformation, providing innovative solutions and services to clients across various industries. Our team is dedicated to delivering excellence and driving success for our clients.
Location
Bengaluru, India
Employment Type
FULL_TIME
© Luxoft DXC. This job description was sourced from the employer's public career page. TheJob is not the employer — we index the posting and route candidates to the source. All content rights and hiring decisions belong to the employer.
Automotive,Finance,Healthcare,Life Sciences,Tech and Telecom
About the Company Luxoft, a DXC Technology Company, is a global digital strategy and software engineering firm with over 17,000 international employees across 58 offices in 29 countries. Headquartered in Zug, Switzerland, Luxoft specializes in providing tailored tech solutions that drive global business transformation. The company focuses on enhancing customer experiences and boosting efficiency through strategy, consulting, and engineering services. Products, Services & Tech Stack Core Solutions: Digital strategy and software engineering services. Technologies & Frameworks: Specific platforms, languages, or tools are not mentioned in the provided text. Project Scope & Target Clients Client Base: Automotive, finance, healthcare, life sciences, tech, and telecom. Engineering Scale: Scope and complexity of engineering projects are not specified in the provided text.
More at Luxoft DXC
All 345 rolesSenior Storage Systems Engineer
Luxoft DXC · Mexico
Senior Fullstack Developer (Java & Angular)
Luxoft DXC · Romania
Experienced Bug Hunter
Luxoft DXC · Romania
Regular MS SQL Developer
Luxoft DXC · Ukraine