Principal Engineer – Identity & Access Management (IAM) Directory Services

NXP Semiconductors

Bengaluru

On-site

INR 3,500,000 - 7,000,000

Full time

9 days ago
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

NXP Semiconductors in India is seeking a Principal Engineer for Identity & Access Management. This role leads architectural decisions for enterprise and customer-facing authentication, authorization, and directory services across multi-region environments.

It requires deep expertise in AD, Entra ID, OUD, and Linux authentication to ensure security, availability, and scalable identity platforms. The candidate will drive zero trust, RBAC/ABAC models, and non-human identities, while mentoring

Qualifications

  • Architectural expertise in enterprise IAM and directory services.
  • Proven experience with hybrid, multi-region deployments.
  • Hands-on with authentication, authorization, and federation protocols.

Responsibilities

  • Own global IAM and directory architecture for enterprise and customer apps.
  • Ensure high availability, disaster recovery, and regional resilience.
  • Implement RBAC/ABAC, policy-driven access controls and least privilege.

Skills

Active Directory
Entra ID/Azure AD
Oracle Unified Directory
Linux/Unix auth
RBAC/ABAC
SAML/OIDC/Kerberos
Zero Trust

Job description

Role Overview We are seeking a Principal Engineer – Identity & Access Management (IAM) to serve as the technical authority and architectural owner for enterprise and customer-facing authentication, authorization, and directory services. This role underpins the availability, security, and continuity of global digital platforms and business-critical environments. This is a deeply technical, hands‑on principal role requiring architectural-level expertise across Active Directory, Entra ID (Azure AD & B2C), Oracle Unified Directory (OUD), and Linux/Unix authentication systems, operating within a complex hybrid identity ecosystem. The role is mission critical: failures in identity architecture directly translate into widespread access disruption, security exposure, productivity loss, and compliance risk. This engineer will eliminate single points of failure, strengthen directory security posture, support M&A integrations, and ensure identity services scale securely and reliably across all regions.

Key Responsibilities
IAM & Directory Services Architecture Ownership

Act as the principal technical owner for global IAM and directory services platforms supporting enterprise, partner, and customer-facing applications. Define, document, and evolve end-to-end IAM architecture, including: Active Directory (enterprise-scale, hybrid, multi-region) Entra ID / Azure AD (including B2C and external identities) Oracle Unified Directory (OUD) Linux and Unix authentication and authorization integrations. Establish reference architectures, engineering standards, and operational patterns for identity platforms. Design for high availability, fault tolerance, disaster recovery, and regional resilience.

Authentication & Authorization Reliability

Ensure continuous availability of authentication and authorization services by proactively managing identity dependencies. Own directory synchronization, federation, and authentication flows across hybrid environments. Eliminate architectural and operational single points of failure. Prevent identity issues that could result in: Global user access degradation Business application downtime Customer- and partner-facing access disruption Security, Zero Trust & Risk Reduction.

Zero Trust & Risk Reduction

Make identity the primary control plane for Zero Trust initiatives. Enforce least privilege, strong authentication, and continuous verification. Design and implement RBAC, ABAC, and policy-based authorization models. Strengthen directory security posture by addressing: Privileged access exposure Legacy protocols and weak authentication mechanisms Inconsistent policy enforcement and configuration drift Reduce identity-based attack paths and systemic access risk.

Non-Human, AI & Machine Identity Protection

Architect and secure non-human identities, including: AI agent identities Robotic Process Automation (RPA) identities Service accounts, workloads, APIs, and system identities. Define lifecycle management, authentication, authorization, and rotation strategies for machine identities. Prevent credential sprawl, over-privileged access, and unmanaged secrets. Ensure AI and robotic identities adhere to Zero Trust, least privilege, and auditable access principles. Integrate non-human identity controls into enterprise IAM governance and monitoring.

Integration & User Experience

Improve identity integration across: Enterprise applications Partner platforms Customer-facing (B2C) ecosystems. Ensure seamless, low-friction authentication experiences without compromising security. Enable scalable access models for human and non-human identities.

Mergers & Acquisitions (M&A)

Support Serve as the IAM technical lead for M&A initiatives. Assess acquired company identity architectures, directory services, and authentication models. Design and execute secure identity integration, consolidation, or coexistence strategies. Mitigate access risk during transitions while maintaining business continuity. Ensure acquired environments align with enterprise IAM, Zero Trust, and security standards.

Continuity, Innovation & Long-Term Strategy

Ensure knowledge continuity and eliminate dependency on individual resources. Define a multi-year IAM and directory services roadmap aligned with enterprise architecture and Zero Trust maturity. Evaluate emerging identity technologies, protocols, and access models, including AI-driven identity use cases.

Mentor engineers

Elevate IAM engineering maturity across the organization.

Required Qualifications

Experience 12+ years of experience in Identity & Access Management, directory services, or security platform engineering. Proven experience supporting global, highly available, business-critical identity systems.

Technical Expertise Architectural-level expertise in: Active Directory (enterprise and hybrid environments) Entra ID / Azure AD, including B2C Oracle Unified Directory (OUD) Linux and Unix authentication mechanisms. Strong understanding of: Authentication and authorization flows Identity federation and synchronization RBAC, ABAC, and policy-driven access models Zero Trust and identity-centric security architecture. Hands‑on experience with identity protocols: SAML 2.0, OAuth 2.0, OpenID Connect (OIDC), Kerberos, LDAP/LDAPS, SCIM, RADIUS, SSH key-based authentication, PAM (Pluggable Authentication Modules) for Linux, certificate-based authentication (X.509), and modern API-based identity integrations, etc. Experience with automation and integration: PowerShell, Python, APIs, infrastructure-as-code preferred.

Architectural & Leadership Skills Ability to design for availability, resilience, and failure scenarios. Strong systems thinking and long-term technical judgment. Proven ability to influence architecture and strategy across teams without formal authority. Comfortable operating in ambiguous, high‑impact environments.

Preferred Qualifications

Experience supporting customer-facing digital platforms at global scale. Cloud IAM experience across Azure, AWS, and/or GCP. Familiarity with identity governance, privileged access, and compliance frameworks. Experience working with globally distributed teams, including India-based engineering support models. Prior experience supporting identity integration during M&A activities.

Why This Role Is Critical

Identity is a Tier-0 dependency. Without a resilient, well-architected IAM foundation, failures in authentication, authorization, or machine identity control quickly become enterprise-wide risk events. This role directly protects the organization from: Identity-driven downtime and degraded user access Over-privileged or unmanaged AI, robotic, and service identities Increased risk during mergers, acquisitions, and integrations Delays or failures in Zero Trust adoption Compliance exposure and erosion of trust. This Principal Engineer ensures continuity, resilience, and long-term sustainability of identity services—across humans, machines, and AI—that the business depends on every day.

More information about NXP in India... #LI-7013 NXP Semiconductors N.V. (NASDAQ: NXPI) enables a smarter, safer, and more sustainable world through innovation. As the world leader in secure connectivity solutions for embedded applications, NXP is pushing boundaries in the automotive, industrial & IoT, mobile, and communication infrastructure markets. For more information, visit www.nxp.com Bright Minds. Bright Futures. We believe that a key component to growing our business is to develop our people. To enable you to grow your career at NXP, we offer online and offline learning opportunities to help you develop some of your core and professional skills.

Commitment At NXP. We recognize NXP is a powerful change agent as we continue to deliver innovative solutions that advance a more sustainable future. We remain steadfast in our commitment to sustainability and making measurable year-on-year progress. Also, we aim to create an inclusive work environment and we will not tolerate racism, discrimination or harassment of any kind. We have programs in place focused on diversity, inclusion and equality.

Thank you for considering a career at NXP.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Principal Engineer
Principal Engineer

Saur Energy International • Bengaluru

On-site
INR 4,200,000 - 7,000,000
Senior IT Systems Engineer - DevOps LDAP Services
Senior IT Systems Engineer - DevOps LDAP Services

NXP Semiconductors • Dadri

On-site
INR 900,000 - 1,500,000
Senior IAM Architect
Senior IAM Architect

People Prime Worldwide • Bengaluru

On-site
INR 1,500,000 - 2,500,000
Manager - Identity and Access Management
Manager - Identity and Access Management

ameriprise • Gurugram District

On-site
INR 3,500,000 - 6,000,000
Senior Associate - Identity and Access Management
Senior Associate - Identity and Access Management

NPCI • Hyderabad

On-site
INR 1,200,000 - 1,800,000
Senior IT Systems Engineer - DevOps LDAP Services
Senior IT Systems Engineer - DevOps LDAP Services

NXP Semiconductors • Bengaluru

On-site
INR 1,500,000 - 2,500,000
Senior Principal Data and AI Engineer- R&D IT
Senior Principal Data and AI Engineer- R&D IT

NXP Semiconductors • Bengaluru

On-site
INR 2,000,000 - 3,000,000
Manager - Identity and Access Management
Manager - Identity and Access Management

Ameriprise Financial Services, LLC • Gurugram District

On-site
INR 4,200,000 - 6,400,000
Principal Software Engineer
Principal Software Engineer

Palo Alto Networks, Inc. • Hyderabad

On-site
INR 3,000,000 - 6,000,000
Senior Principal Engineer - IP Design
Senior Principal Engineer - IP Design

NXP Semiconductors • Dadri

On-site
INR 3,000,000 - 5,500,000