Azure PIM (Privileged Identity Management) Senior Engineer

Luxoft

India

On-site

INR 800,000 - 1,200,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Luxoft is seeking an experienced Azure Privileged Identity Management (PIM) Senior Engineer to lead the design, implementation, automation, and governance of privileged access within Microsoft Entra ID and Azure environments. You will own end-to-end PIM operations, including role governance, access lifecycle, and security controls, collaborating with IAM, Cloud Eng, Cybersecurity and DevOps teams.

The ideal candidate has hands-on experience with large-scale Azure PIM deployments, automation

Qualifications

  • 7+ years experience in Identity and Access Management (IAM) and Microsoft Azure environments.
  • Experience integrating identity security controls with enterprise DevSecOps practices
  • Terraform (Mandatory and Expert Level)
  • Git-Based Source Control and Automation Frameworks (Mandatory and Expert Level)
  • REST API Integrations and CI/CD Pipelines (Mandatory and Expert Level)
  • PowerShell (Mandatory and Expert Level)
  • Python (Mandatory and Expert Level)
  • Microsoft Certified: Identity and Access Administrator Associate (SC-300)
  • Microsoft Certified: Azure Security Engineer Associate (AZ-500)
  • Microsoft Certified: Azure Administrator Associate (AZ-104)
  • Experience supporting large enterprise or global Azure environments.
  • Experience implementing Zero Trust security principles.
  • Knowledge of cloud security, governance, and compliance frameworks.

Responsibilities

  • Lead the design, implementation, configuration, and ongoing administration of Microsoft Entra ID (Azure AD) Privileged Identity Management (PIM).
  • Manage privileged access controls across Microsoft Entra ID, Azure subscriptions, management groups, resource groups, and Azure resources.
  • Define and maintain privileged access governance policies, standards, operational procedures, and security controls aligned with enterprise requirements.
  • Design and implement Just-In-Time (JIT) access, role eligibility, approval workflows, access reviews, Privileged Access Groups, and role activation policies.
  • Perform privileged access assessments, role reviews, recertifications, and remediation of excessive or inappropriate access.
  • Develop, maintain, and enhance automation solutions using Terraform, Git, CI/CD Pipelines, Ansible, PowerShell, and Python for identity and privileged access management.
  • Build reusable Infrastructure-as-Code (IaC) modules and deployment frameworks for Azure PIM, role assignments, Service Principals, Managed Identities, and related identity governance controls.
  • Design, customize, and support federation integrations and authentication workflows using automated CI/CD pipelines.
  • Manage and troubleshoot federation configurations, claims transformations, token issuance policies, and authentication-related issues.
  • Develop and maintain REST API-based integrations and automation workflows for identity lifecycle management.
  • Manage the complete lifecycle of Service Principals, Enterprise Applications, and Managed Identities, including provisioning, governance, credential management, and decommissioning.
  • Implement and manage secrets, certificates, credential rotation, expiration monitoring, and secure authentication practices for non-human identities.
  • Automate onboarding, access assignment, certification, and retirement processes for privileged and service identities.
  • Monitor privileged access activities and maintain reporting, dashboards, and audit evidence to support security, compliance, and operational requirements.
  • Support internal and external audits, security reviews, risk assessments, and compliance initiatives related to privileged access management.
  • Investigate and resolve identity, authentication, authorization, and privileged access issues across Azure environments.
  • Collaborate with IAM, Security, Cloud Engineering, DevOps, and application teams to implement secure and scalable access management solutions.
  • Drive continuous improvements in privileged access governance, identity security, automation, and operational efficiency.

Skills

IAM expertise
DevSecOps experience
Zero Trust
Azure
Large-scale Azure

Tools

Terraform
Git
CI/CD pipelines
PowerShell
Python
Ansible
REST API

Job description

Project description

We are seeking an experienced Azure Privileged Identity Management (PIM) Senior Engineer to drive the design, implementation, automation, and governance of privileged access management within Microsoft Entra ID (Azure AD) and Azure environments. This role requires a highly skilled identity professional with proven expertise in managing Azure PIM end-to-end, including privileged role governance, access lifecycle management, automation, compliance, and security controls.The ideal candidate will have hands-on experience implementing and operating Azure PIM in large-scale enterprise environments, developing automation using Terraform, Git, Ansible, PowerShell, and Python and customizing federation integrations through CI/CD pipelines. The candidate should possess deep knowledge of privileged identity governance, Service Principal lifecycle management, Managed Identity administration, and privileged access controls aligned with Zero Trust principles.This role will partner closely with Identity & Access Management, Cloud Engineering, Cybersecurity, DevOps, and Compliance teams to ensure privileged access is managed securely, efficiently, and in accordance with enterprise security standards.

Responsibilities
  • Lead the design, implementation, configuration, and ongoing administration of Microsoft Entra ID (Azure AD) Privileged Identity Management (PIM).
  • Manage privileged access controls across Microsoft Entra ID, Azure subscriptions, management groups, resource groups, and Azure resources.
  • Define and maintain privileged access governance policies, standards, operational procedures, and security controls aligned with enterprise requirements.
  • Design and implement Just-In-Time (JIT) access, role eligibility, approval workflows, access reviews, Privileged Access Groups, and role activation policies.
  • Perform privileged access assessments, role reviews, recertifications, and remediation of excessive or inappropriate access.
  • Develop, maintain, and enhance automation solutions using Terraform, Git, CI/CD Pipelines, Ansible, PowerShell, and Python for identity and privileged access management.
  • Build reusable Infrastructure-as-Code (IaC) modules and deployment frameworks for Azure PIM, role assignments, Service Principals, Managed Identities, and related identity governance controls.
  • Design, customize, and support federation integrations and authentication workflows using automated CI/CD pipelines.
  • Manage and troubleshoot federation configurations, claims transformations, token issuance policies, and authentication-related issues.
  • Develop and maintain REST API-based integrations and automation workflows for identity lifecycle management.
  • Manage the complete lifecycle of Service Principals, Enterprise Applications, and Managed Identities, including provisioning, governance, credential management, and decommissioning.
  • Implement and manage secrets, certificates, credential rotation, expiration monitoring, and secure authentication practices for non-human identities.
  • Automate onboarding, access assignment, certification, and retirement processes for privileged and service identities.
  • Monitor privileged access activities and maintain reporting, dashboards, and audit evidence to support security, compliance, and operational requirements.
  • Support internal and external audits, security reviews, risk assessments, and compliance initiatives related to privileged access management.
  • Investigate and resolve identity, authentication, authorization, and privileged access issues across Azure environments.
  • Collaborate with IAM, Security, Cloud Engineering, DevOps, and application teams to implement secure and scalable access management solutions.
  • Drive continuous improvements in privileged access governance, identity security, automation, and operational efficiency.

SKILLS
Must have
  • 7+ years of experience in Identity and Access Management (IAM) and Microsoft Azure environments.
  • Experience integrating identity security controls with enterprise DevSecOps practices
  • Terraform (Mandatory and Expert Level)
  • Git-Based Source Control and Automation Frameworks (Mandatory and Expert Level)
  • REST API Integrations and CI/CD Pipelines (Mandatory and Expert Level)
  • PowerShell (Mandatory and Expert Level)
  • Python (Mandatory and Expert Level)
  • Microsoft Certified: Identity and Access Administrator Associate (SC-300)
  • Microsoft Certified: Azure Security Engineer Associate (AZ-500)
  • Microsoft Certified: Azure Administrator Associate (AZ-104)
  • Experience supporting large enterprise or global Azure environments.
  • Experience implementing Zero Trust security principles.
  • Knowledge of cloud security, governance, and compliance frameworks.

Nice to have

Work in agile environment

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Azure IAM Engineer
Azure IAM Engineer

Luxoft • Bengaluru

On-site
INR 4,000,000 - 7,000,000
Privilega Access management + Azure Devoper
Privilega Access management + Azure Devoper

Statusneo Technology Consulting • Bengaluru

On-site
INR 3,500,000 - 5,500,000
Architect - R01570781
Architect - R01570781

Brillio • Bengaluru

On-site
INR 4,000,000 - 6,000,000
Identity & Access Management Engineer
Identity & Access Management Engineer

Cherry Bekaert • Chennai District

On-site
INR 1,200,000 - 1,500,000
Senior Data Scientist - R01570780
Senior Data Scientist - R01570780

Brillio • Bengaluru

On-site
INR 3,000,000 - 4,500,000
Principal Specialist, IT Application and Infra Management (NL)
Principal Specialist, IT Application and Infra Management (NL)

Randstad • Hyderabad

On-site
INR 1,800,000 - 2,800,000
IAM Architect
IAM Architect

Gas Strategies • Bengaluru

On-site
INR 3,500,000 - 5,500,000
Developer - Microsoft Entra ID PIM & Terraform Automation - Nexifyr
Developer - Microsoft Entra ID PIM & Terraform Automation - Nexifyr

OpenTalent • Karnataka

Hybrid
INR 1,600,000 - 2,600,000
Executive Manager - IAM / Azure AD
Executive Manager - IAM / Azure AD

PepsiCo • Hyderabad

On-site
INR 1,500,000 - 2,000,000
Senior IAM Engineer
Senior IAM Engineer

Jobtailor • Dadri

On-site
INR 900,000 - 1,500,000