Developer - Microsoft Entra ID PIM & Terraform Automation - Nexifyr

OpenTalent

Karnataka

Hybrid

INR 1,600,000 - 2,600,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

OpenTalent in Bengaluru (Whitefield) seeks an identity and infrastructure engineer to design and automate Entra ID PIM and Terraform-based identity infrastructure in a hybrid setup. You will build CI/CD pipelines (Azure DevOps / GitHub Actions), implement JIT access, PIM workflows, and collaborate with security and platform teams to enforce least privilege and Zero Standing Privilege.

The role requires 3–6 years of hands-on experience with Entra ID, Terraform, Graph API, RBAC, and scripting

Qualifications

  • Hands-on experience with Microsoft Entra ID including Privileged Identity Management (PIM) for directory and Azure resource roles.
  • Strong Terraform knowledge: modules, state, workspaces, and provider configuration (AzureRM, AzureAD/Entra, AzAPI).
  • Experience with Microsoft Graph API for identity governance and automation use cases.
  • Solid understanding of Azure IAM concepts: RBAC, conditional access, access reviews, entitlement management, and just-in-time access.

Responsibilities

  • Design, develop, and maintain Terraform modules to provision and manage Entra ID resources, including PIM role assignments, eligible/active role settings, and access review policies.
  • Implement and automate Just-In-Time (JIT) privileged access workflows using Entra ID PIM for both Entra roles and Azure resource roles.
  • Build and maintain CI/CD pipelines (Azure DevOps / GitHub Actions) to deploy and test Terraform-based identity infrastructure changes.
  • Configure and manage PIM approval workflows, access reviews, notification settings, and role activation policies (MFA, justification, approval chains).
  • Integrate Terraform automation with Microsoft Graph API / AzAPI provider for advanced Entra ID configuration not covered by standard providers.
  • Collaborate with security, identity, and platform teams to define least-privilege access models and enforce Zero Standing Privilege (ZSP) principles.
  • Monitor, audit, and report on privileged role activations, PIM alerts, and compliance posture; remediate drift between code and live configuration.
  • Write clean, reusable, and well-documented Terraform code following IaC best practices (state management, modularity, version control).
  • Troubleshoot access-related incidents and support audits by providing evidence of automated access controls.
  • Contribute to internal documentation, runbooks, and knowledge-sharing on Entra ID PIM and Terraform automation practices.

Skills

Entra ID
PIM
Terraform
AzureRM
AzureAD/Entra
AzAPI
Graph API
RBAC
Conditional Access
Access Reviews
Just-In-Time
PowerShell
Python
Go
Git
CI/CD
Azure DevOps
GitHub Actions
SOC 2
ISO 27001
Zero Trust
Least Privilege

Tools

Terraform

Job description

Experience: 3-6 years

Mode of Work: (Hybrid – 3 Days Work From Office)

Location: Whitefield, Bangalore

Key Responsibilities
  • Design, develop, and maintain Terraform modules to provision and manage Microsoft Entra ID resources, including PIM role assignments, eligible/active role settings, and access review policies.
  • Implement and automate Just-In-Time (JIT) privileged access workflows using Entra ID PIM for both Entra roles and Azure resource roles.
  • Build and maintain CI/CD pipelines (Azure DevOps / GitHub Actions) to deploy and test Terraform-based identity infrastructure changes.
  • Configure and manage PIM approval workflows, access reviews, notification settings, and role activation policies (MFA, justification, approval chains).
  • Integrate Terraform automation with Microsoft Graph API / AzAPI provider for advanced Entra ID configuration not covered by standard providers.
  • Collaborate with security, identity, and platform teams to define least-privilege access models and enforce Zero Standing Privilege (ZSP) principles.
  • Monitor, audit, and report on privileged role activations, PIM alerts, and compliance posture; remediate drift between code and live configuration.
  • Write clean, reusable, and well-documented Terraform code following IaC best practices (state management, modularity, version control).
  • Troubleshoot access-related incidents and support audits by providing evidence of automated access controls.
  • Contribute to internal documentation, runbooks, and knowledge-sharing on Entra ID PIM and Terraform automation practices.
  • Required Skills & Experience
  • Hands-on experience with Microsoft Entra ID (Azure AD), including Privileged Identity Management (PIM) for both directory roles and Azure resource roles.
  • Strong working knowledge of Terraform, including module design, state management, workspaces, and provider configuration (AzureRM, AzureAD/Entra, AzAPI).
  • Experience with Microsoft Graph API for identity governance and automation use cases.
  • Solid understanding of Azure IAM concepts: RBAC, conditional access, access reviews, entitlement management, and just-in-time access.
  • Proficiency with a scripting/programming language such as PowerShell, Python, or Go for automation and tooling.
  • Experience with version control (Git) and CI/CD pipelines (Azure DevOps, GitHub Actions, or similar).
  • Familiarity with security and compliance frameworks (e.g., least privilege, Zero Trust, SOC 2, ISO 27001) as applied to identity access.
  • Strong troubleshooting skills and ability to work with cross-functional security and infrastructure teams.
Preferred Qualifications
  • Microsoft certifications such as SC-300 (Identity and Access Administrator) or AZ-104/AZ-400.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Azure IAM Engineer
Azure IAM Engineer

Luxoft • Bengaluru

On-site
INR 4,000,000 - 7,000,000
Azure PIM (Privileged Identity Management) Senior Engineer
Azure PIM (Privileged Identity Management) Senior Engineer

Luxoft • India

On-site
INR 800,000 - 1,200,000
Privilega Access management + Azure Devoper
Privilega Access management + Azure Devoper

Statusneo Technology Consulting • Bengaluru

On-site
INR 3,500,000 - 5,500,000
Systems & Cloud Infrastructure Engineer: Microsoft 365, Entra & Azure
Systems & Cloud Infrastructure Engineer: Microsoft 365, Entra & Azure

Summitnext • Pune District

On-site
INR 1,600,000 - 2,600,000
Entra ID_Security Specialist
Entra ID_Security Specialist

Fujitsu • Bengaluru Urban

On-site
INR 1,800,000 - 2,700,000
EntraID Platform Architect
EntraID Platform Architect

MajorKey Technologies • India

On-site
INR 1,500,000 - 2,000,000
Entra ID_Security Specialist
Entra ID_Security Specialist

Fujitsu • Dadri, Pune District, Bengaluru

On-site
INR 2,500,000 - 5,200,000
Identity & Access Management Engineer (AD, Entra ID, Agentic identity)
Identity & Access Management Engineer (AD, Entra ID, Agentic identity)

Crisil • Mumbai

On-site
INR 3,500,000 - 5,500,000
Microsoft Hybrid Identity Engineer -MIM, Active Directory, ENTRA ID
Microsoft Hybrid Identity Engineer -MIM, Active Directory, ENTRA ID

Cerebra • Hyderabad, Chennai District, Bengaluru

Hybrid
INR 1,500,000 - 3,000,000
Senior IAM Engineer
Senior IAM Engineer

Jobtailor • Dadri

On-site
INR 900,000 - 1,500,000