C

Microsoft Entra ID,Azure IAM, Conditional Access,PIM, RBAC,Entitlement

Cognizant · Bengaluru, Karnataka, India - Hyderabad, Telangana, India - Pune, Maharashtra, India

3–10 yrs experiencefull_timePosted 1w ago

Job description

Key Responsibilities - Design and deliver a governed Azure IAM platform using Microsoft Entra ID as the primary identity control plane. - Create and manage role-assignable security groups, dynamic user groups, and entitlement management catalogs for different access levels and actor types. - Build and configure Access Packages with standard and enhanced approval workflows, access expiry, and periodic self-review controls. - Enable and configure Privileged Identity Management (PIM) for privileged security groups, including MFA enforcement, justification, activation expiry, approval settings, and validation testing. - Define and implement Azure RBAC assignments across management groups, subscriptions, resource groups, and Azure DevOps projects. - Develop identity lifecycle workflows for Joiner, Mover, and Leaver scenarios using Microsoft Entra Lifecycle Workflows. - Integrate automation with Logic Apps and Microsoft Graph API to cancel active PIM sessions during mover or leaver events. - Design and implement Conditional Access policies for standard sign-in, privileged access activation, and secure administrative operations. - Create, validate, monitor, and document break-glass accounts with appropriate alerting through Azure Monitor. - Collaborate with HR, ITSM, security, cloud, and application teams to ensure identity attributes, governance processes, and access workflows are correctly maintained. - Conduct end-to-end user acceptance testing across all IAM phases and support remediation of defects or gaps. - Produce technical design documents, configuration guides, operational procedures, and handover documentation. Required Skills and Experience - Strong hands-on experience with Microsoft Entra ID, Azure IAM, Conditional Access, PIM, RBAC, and Entitlement Management. - Experience designing and implementing identity governance solutions across enterprise-scale Azure environments. - Good understanding of Azure management groups, subscriptions, resource groups, and role assignment models. - Experience with Microsoft Entra Lifecycle Workflows, access packages, access reviews, and approval-based access provisioning. - Working knowledge of Microsoft Graph API, Managed Identity, Logic Apps, and automation for identity operations. - Experience integrating identity processes with HR or ITSM systems, including attribute-driven identity lifecycle automation. - Ability to design secure privileged access models aligned to least privilege and zero trust principles. - Experience supporting UAT, validation, troubleshooting, and operational handover for IAM solutions. - Strong documentation skills, including HLD, LLD, SOPs, configuration guides, and runbooks. - Excellent communication and stakeholder management skills across technical and business teams. Preferred Qualifications - Microsoft certifications such as AZ-104, AZ-305, SC-300, SC-100, or equivalent identity and security certifications. - Experience delivering cloud foundation, landing zone, or enterprise identity transformation programs. - Knowledge of Azure DevOps security, project-level permissions, and integration with Entra ID groups. - Understanding of security frameworks such as Zero Trust, CIS, NIST, ISO 27001, or enterprise security baseline standards. - Experience working in large enterprise or multi-stakeholder transformation environments.