CIAM Engineer
ICON plc · State of Karnataka, India
Free to search · AI fit score against your CV · tailor your résumé in one click
ICON plc · State of Karnataka, India
CIAM Engineer - Bangalore / Chennai ICON is a global healthcare intelligence and clinical research organisation united by a mission to bring new medicines and treatments to patients faster. As a values-driven organisation, integrity, collaboration, agility, and inclusion are at the heart of how we work and interact with each other, customers, patients and suppliers. Role: CIAM (Customer Identity & Access Management) Specialist / Engineer Role Overview The CIAM Specialist/Engineer will be responsible for designing, implementing, and supporting customer identity solutions across the organization, with a focus on secure, scalable, and compliant access for external users (B2B and B2C). This role will play a key part in integrating customer identity services into externally facing applications, leveraging Microsoft Entra ID (including External ID / B2C capabilities), while aligning with enterprise IAM standards, security controls, and regulatory requirements. The position operates within the broader IAM function and will collaborate closely with application teams, security architecture, and engineering teams to deliver robust and audit-compliant identity integrations. Key Responsibilities CIAM & External Identity Engineering • Design, implement, and maintain CIAM solutions supporting B2B and B2C identity use cases • Develop and manage Microsoft Entra ID (EntraID) and Entra External ID / B2C configurations • Build and maintain identity federation, authentication, and authorization flows (OIDC, OAuth2, SAML) • Configure and manage: • User journeys / policies (B2C) • Identity providers (social, enterprise federation) • Conditional access and security controls for external users Application Integration • Integrate CIAM services into externally facing applications and platforms • Partner with development teams to: • Embed authentication and authorization flows • Ensure secure API access and token handling • Support onboarding of new applications into CIAM platforms • Troubleshoot identity-related issues across application integrations Project Delivery • Lead or contribute to projects involving: • B2C customer identity integrations • External partner onboarding (B2B federation) • Modernization of legacy authentication platforms • Translate business and security requirements into technical identity solutions • Support delivery within defined timelines and governance frameworks (e.g., change control, SDLC) IAM Ecosystem Alignment • Ensure CIAM solutions align with broader IAM architecture, including: • Identity Governance & Administration (IGA) • Privileged Access Management (PAM) • Collaborate with IAM, and architecture teams to ensure: • Consistent identity policies • Centralized identity lifecycle practices • Secure access models across internal and external identities Security, Compliance & Audit Readiness • Implement identity controls aligned with security policies and standards • Support compliance efforts including: • SOX (Sarbanes-Oxley) • GxP (where applicable) • Produce and maintain documentation for: • Solution design • Access controls • Audit evidence and control validation • Participate in internal and external audits as required Operational Support • Provide L3 support for CIAM platforms and integrations • Monitor platform performance, availability, and security events • Support incident response activities related to identity and access issues • Identify and implement continuous improvements in CIAM processes Required Skills & Experience Core Technical Skills • Strong hands-on experience with: • Microsoft Entra ID (EntraID) • EntraID B2C / Entra External ID • Experience implementing: • OAuth2, OpenID Connect (OIDC), SAML • Identity federation and Single Sign-On (SSO) • Experience integrating identity solutions into web and mobile applications • Strong understanding of: • Token-based authentication • API security concepts CIAM Domain Expertise • Practical experience delivering B2B and B2C identity solutions • Understanding of customer identity lifecycle and external user management • Experience with custom policies, user flows, and identity providers in B2C Broader IAM Awareness • Working knowledge of: • Identity Governance & Administration (IGA) (e.g., SailPoint or similar) • Privileged Access Management (PAM) (e.g., CyberArk or similar) • Understanding of identity lifecycle, access certification, and privileged access controls Desirable / Advantageous • Experience working in regulated environments (e.g., SOX, GxP ) • Familiarity with secure SDLC and DevSecOps practices • Experience with API gateways, microservices architectures, or cloud-native application design • Scripting / automation experience (PowerShell, Python, etc.) • Experience with external identity providers and social login integrations Key Competencies • Strong problem-solving and troubleshooting skills • Ability to translate business requirements into technical designs • Effective communication across technical and non-technical stakeholders • Structured, audit-aware approach to delivery and documentation • Ability to work across cross-functional teams in a global environment Success Measures (First 6–12 Months) • Successful delivery of CIAM integrations into key external applications • Establishment of consistent B2C onboarding patterns and standards • Reduction in identity-related incidents for external-facing systems • Positive audit outcomes with clear and defensible identity controls Employment with ICON is contingent upon having the legal right to work in the country where the role is based. Rewards & Benefits ICON offers a competitive and comprehensive total rewards package designed to support your health, wellbeing, and career development. Benefits may include: -