Senior Identity & Access Management (IAM) Engineer – L3
Sonata Software · Bengaluru, Karnataka, India
Sonata Software · Bengaluru, Karnataka, India
**IAM L3 Lead / Senior Engineer – Job Description** **Position** **Senior Identity & Access Management (IAM) Engineer – L3** **Experience** 8+ Years **Location:Bengaluru** **Role Summary** The IAM L3 Engineer will act as the technical lead for Identity Governance, Access Management, Privileged Access Management, and Enterprise Application integrations. The role is responsible for governance, escalations, architecture reviews, operational excellence, and continuous improvement of IAM services across the organization. **Key Responsibilities** **Identity Lifecycle Management (JML)** - Lead HR-driven Joiner, Mover, and Leaver (JML) processes. - Design and improve identity lifecycle workflows. - Resolve complex identity synchronization issues. - Troubleshoot provisioning failures and automation issues. - Govern dormant, stale, and disabled account management. **Authentication & Access Management** - Manage and optimize MFA deployment and operations. - Review and maintain Conditional Access policies. - Support Passwordless Authentication initiatives. - Analyze risky sign-ins and authentication anomalies. - Govern Conditional Access exceptions and legacy authentication remediation. **Privileged Access Management (PIM/RBAC)** - Manage Microsoft Entra PIM operations. - Govern privileged role assignments and activations. - Conduct segregation of duties (SoD) reviews. - Lead least-privilege implementation initiatives. - Support privileged access audits and compliance requirements. **Enterprise Applications** - Lead SSO integrations using SAML, OAuth, OIDC, and SCIM. - Support onboarding/offboarding of enterprise applications. - Manage AWS IAM Identity Center integrations. - Support AI application governance and access controls. - Oversee certificate lifecycle management for enterprise applications. **Guest Access Governance** - Define and enforce guest user governance policies. - Review guest access and lifecycle controls. - Ensure MFA and application restrictions for external identities. **Monitoring & Governance** - Review IAM operational KPIs and service metrics. - Lead audit preparation and evidence collection. - Track IAM policy changes and governance compliance. - Drive process improvements and automation initiatives. **Technical Skills** - Microsoft Entra ID (Azure AD) - Microsoft Entra PIM - Conditional Access Policies - Identity Governance - MFA and Passwordless Authentication - SAML, OAuth 2.0, OpenID Connect (OIDC) - SCIM Provisioning - AWS IAM Identity Center - Active Directory & Hybrid Identity - PowerShell Automation - IAM Audit & Compliance - Microsoft Defender for Identity (Preferred) **Deliverables Ownership** - Monthly Governance Reports - Monthly Privileged Access Reports - Conditional Access Review Reports - Audit Evidence Packs - IAM Governance Documentation - Operational Runbooks and SOPs **Required Certifications (Preferred)** - Microsoft Certified: Identity and Access Administrator Associate (SC-300) - Microsoft Certified: Cybersecurity Architect Expert (SC-100) - AWS Security Specialty (Preferred)