Sr Engineer, Identity & Access Management

Evolent Health International Private Limited

Pune District

Remote

INR 3,000,000 - 6,000,000

Full time

26 hours ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Evolent Health International Private Limited is seeking a senior IAM engineer to design, implement, and continuously improve identity management across Entra ID and adjacent platforms. You will lead RBAC design, conditional access, and privileged identity management while building automated, AI-assisted solutions to strengthen zero-trust security.

You will collaborate with security, compliance, and platform teams to ensure policy alignment and regulatory readiness, mentoring junior engineers and

Qualifications

  • 7+ years managing or supporting identity and access management or related security platforms.
  • 3+ years hands-on with Microsoft Entra ID (Azure AD), RBAC, conditional access and PIM.
  • Experience writing scripts and integrations for identity provisioning and access reviews.
  • Hands-on with agentic AI/automation for identity use cases.
  • Knowledge of SAML, OAuth/OIDC, SCIM and identity governance frameworks.

Responsibilities

  • Design, implement and operate IAM capabilities including RBAC, conditional access, PIM, and entitlement management.
  • Develop scripts and integrations (PowerShell, Python, Graph API) for provisioning, reviews, certification, and reporting.
  • Build agentic AI solutions (e.g., role-mining) to optimize least-privilege access and automate certifications.
  • Integrate IAM with endpoint management, ITSM, and security operations for end-to-end identity lifecycle.
  • Monitor identity-related security events and support incident response and remediation.

Skills

IAM governance
RBAC design
Conditional access
PIM
Scripting (PowerShell, Python)
Microsoft Graph API
Agentic AI in IAM
Documentation

Education

Bachelor's degree in IT/CS or related field

Tools

Microsoft Entra ID (Azure AD)
PowerShell
Python
Microsoft Graph API

Job description

Your Future Evolves Here Evolent partners with health plans and providers to achieve better outcomes for people with most complex and costly health conditions. Working across specialties and primary care, we seek to connect the pieces of fragmented health care system and ensure people get the same level of care and compassion we would want for our loved ones. Evolent employees enjoy work/life balance, the flexibility to suit their work to their lives, and autonomy they need to get things done. We believe that people do their best work when they're supported to live their best lives, and when they feel welcome to bring their whole selves to work. That's one reason why diversity and inclusion are core to our business. Join Evolent for the mission. Stay for the culture.

What You’ll Be Doing:

Job Summary

This role designs, implements and continuously improves identity and access management (IAM) capabilities across Microsoft Entra ID, Active Directory and adjacent platforms, with particular focus on role-based access control (RBAC), conditional access, privileged access and identity governance. The engineer builds automation and agentic AI solutions—such as access-review and role-mining agents—to reduce manual administrative overhead and strengthen the organization’s zero-trust security posture. The engineer collaborates with security, compliance and platform teams to ensure identity controls align with company policy and applicable regulations.

Essential Functions
  • Design, implement and operate IAM capabilities including RBAC, conditional access, privileged identity management (PIM), and entitlement management
  • Write and maintain scripts and integrations (PowerShell, Python, Microsoft Graph API, or similar) for identity provisioning, access reviews, certification workflows and reporting
  • Design, build and deploy agentic AI solutions (e.g., a role-mining agent) that analyze access patterns, recommend least privilege role assignments and automate periodic access certification
  • Integrate IAM systems with adjacent technologies (endpoint management, security operations, ITSM, directory services) to support end-to-end identity lifecycle management
  • Monitor and report on identity-related security anomalies and support incident response and remediation for identity-based threats
  • Support audit readiness by producing and maintaining documentation of IAM design, controls, and automation
  • Create, publish and communicate knowledgebase articles and standard operating procedures for IAM processes
  • Act as a mentor to junior engineers and operations teams on IAM for best practices, secure coding and responsible use of AI-driven automation
Required Qualifications
  • 7+ years managing or supporting identity and access management, identity governance, or related security platforms
  • 3+ years of hands‑on experience with Microsoft Entra ID (Azure AD), RBAC design, conditional access and privileged identity management (PIM)
  • Demonstrated coding/scripting ability (PowerShell, Python, Microsoft Graph API, or similar) with a track record of building identity automation, integrations and reporting tools
  • Hands‑on experience designing or deploying agentic AI or automation solutions for identity/access use cases (e.g., role mining, access certification, anomaly detection)
  • Experience with identity protocols and standards (SAML, OAuth/OIDC, SCIM) and identity governance/compliance frameworks
  • Working knowledge of Generative AI and agentic AI concepts (LLM integration, tool/function calling, retrieval‑augmented generation) as applied to identity and security operations
  • Ability to write clear technical documentation
Preferred Qualifications
  • Experience building or contributing to an internal AI agent/Center of Excellence pod, including agent design and application lifecycle management (ALM) practices
  • Experience with Microsoft Copilot Studio or similar low‑code AI agent platforms
  • Passion for zero‑trust security with an awareness of the latest identity and AI trends
Preferred Education

Bachelor’s degree in IT, Computer Science, or related field

Preferred Certifications
  • Microsoft Certified: Identity and Access Administrator Associate (SC-300)
  • Microsoft Certified: Azure AI Engineer Associate (AI-102) or Copilot Studio/agentic AI certification
General Performance Criteria
  • Expertise: You research, create proof of concepts, and introduce new methods
  • Communication: You guide others through problem solving whether it is a technical issue, project impediment, or conflict
  • Domain: You guide the delivery of your team to make a positive impact on other parts of the company based on detailed knowledge of the needs of those stakeholders and how those needs are supported by your team
  • System: You own relevant segment of systems that are used regularly for the business to function and are well versed in the related KPIs
  • Process: You question the status quo in a constructive manner to find areas for the team to improve
  • Influence: You regularly make an impact to your entire team

To ensure a secure hiring process we have implemented several identity verification steps, including submission of a government issued photo ID. We conduct identity verification during interviews, and final interviews may require onsite attendance. All candidates must complete a comprehensive background check, in‑person I‑9 verification, and may be subject to drug screening prior to employment. The use of artificial intelligence tools during interviews is prohibited and monitored. Misrepresentation will result in immediate disqualification from consideration.

Mandatory Requirements: Employees must have a high‑speed broadband internet connection with a minimum speed of 50 Mbps and the ability to set up a wired connection to their home network to ensure effective remote work. These requirements may be updated as needed by the business.

Evolent is an equal opportunity employer and considers all qualified applicants equally without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, veteran status, or disability status.

If you need reasonable accommodation to access the information provided on this website, please contact recruitingteam@evolent.com for further assistance.

The expected base salary/wage range for this position is $. As part of our total compensation package, Evolent is proud to offer comprehensive benefits (including health insurance benefits) to qualifying employees. All compensation determinations are based on the skills and experience required for the position and commensurate with experience of selected individuals, which may vary above and below the stated amounts.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Sr Engineer, Digital Workplace Engineering
Sr Engineer, Digital Workplace Engineering

Evolent Health International Private Limited • Pune District

Remote
INR 1,800,000 - 2,800,000
Sr Platform Engineer - DevOps
Sr Platform Engineer - DevOps

Evolent Health International Private Limited • Pune District

On-site
INR 3,000,000 - 5,000,000
Health insurance
Cloud Platform Architect
Cloud Platform Architect

Evolent Health International Private Limited • Pune District

Remote
INR 14,451,000 - 20,231,000
Health insurance
Platform Engineer - Observability
Platform Engineer - Observability

Evolent • Maharashtra

Remote
INR 1,500,000 - 2,300,000
Platform Engineer - Observability
Platform Engineer - Observability

Evolent Health International Private Limited • Pune District

Remote
INR 1,200,000 - 1,800,000
Health insurance
Platform Engineer - Internal Developer Platform
Platform Engineer - Internal Developer Platform

Evolent Health International Private Limited • Pune District

Remote
INR 1,500,000 - 2,100,000
Health insurance
Cloud Platform Architect
Cloud Platform Architect

Evolent • Pune District

Remote
INR 11,572,000 - 16,393,000
Database Administrator
Database Administrator

Evolent Health International Private Limited • Pune District

Remote
INR 1,200,000 - 2,200,000
Health insurance
Sr SaaS Administrator, Enterprise Applications
Sr SaaS Administrator, Enterprise Applications

Evolent Health • Pune District

On-site
INR 1,800,000 - 3,200,000
Identity & Access Management (IAM) Engineer
Identity & Access Management (IAM) Engineer

Interscripts, Inc. • Hyderabad

On-site
INR 2,800,000 - 4,000,000