Project Role :
Security ArchitectProject Role Description :
Define the cloud security framework and architecture, ensuring it meets the business requirements and performance goals. Document the implementation of the cloud security controls and transition to cloud security-managed operations.Must have skills :
Identity Access Management (IAM), Microsoft Active Directory, Microsoft Azure Active DirectoryGood to have skills :
NAMinimum 7.5 Year(s) Of Experience Is Required
Educational Qualification :
15 years full time educationSummary We are seeking a highly experienced Entra ID (formerly Azure AD) & Active Directory Architect to design, implement, and optimize enterprise identity and access management (IAM) solutions. The ideal candidate will bring deep expertise in Microsoft identity platforms, with a focus on hybrid identity architecture, federation, and zero trust security models. This role involves strategic planning, hands-on engineering, and close collaboration with security, infrastructure, and application teams. Roles & Responsibilities Design and architect secure, scalable, and high-performing Entra ID (Azure AD) and Active Directory infrastructures. Design and maintain PKI infrastructure (ADCS) including Enterprise/Subordinate CAs, CRLs, certificate templates. Own and manage the end-to-end response for RFPs (Request for Proposals) and RFIs, ensuring that all identity-related components are technically sound, compliant, and aligned with business objectives. Participate in solution architecture reviews, identifying risks and validating feasibility and scalability of proposed identity solutions. Prepare high-quality design documentation, including Security Impact Assessments Lead efforts to modernize identity platforms, including hybrid identity, cloud-only identity, and passwordless authentication. Develop and enforce IAM standards, policies, and governance aligned with organizational security frameworks (e.g., Zero Trust, NIST, CIS). Architect solutions for SSO, MFA, Conditional Access, and Privileged Identity Management (PIM). Manage identity integrations with SaaS applications using SAML, OIDC, OAuth2, and SCIM protocols. Drive federation strategies involving Entra ID B2B, B2C, and on-prem Active Directory Federation Services (ADFS). Collaborate with cybersecurity teams to ensure secure access and compliance with internal and regulatory requirements. Conduct identity assessments, architecture reviews, and provide remediation guidance for IAM-related gaps. Serve as a subject matter expert (SME) in incident response, access reviews, lifecycle automation, and role-based access control (RBAC). Review implementation deliverables, and act as a technical escalation point. Professional & Technical Skills Strong leadership and communication skills; ability to present architectural strategies to executives and stakeholders. Proven track record in delivering large-scale identity modernization programs. Strategic thinker with strong problem-solving and analytical skills. Ability to work cross-functionally with security, networking, compliance, and application teams. Entra ID / Azure Active Directory (Tenant design, CA policies, SSO, B2B/B2C) Microsoft Active Directory (AD) and Group Policy Objects (GPO) ADFS, Azure AD Connect, Pass-through Authentication, Password Hash Sync Conditional Access, MFA, SSPR, Identity Governance Privileged Identity Management (PIM) and Access Reviews Proficient with identity federation protocols like SAML 2.0, OAuth 2.0, OpenID Connect Experience integrating identity with platforms like: Microsoft 365, ServiceNow, PingOne, Okta, SailPoint, Workday and other LOB applications Strong knowledge on Scripting and automation: PowerShell, Graph API, Logic Apps, Azure automation. Knowledge in IAM frameworks like Zero trust security, Lifecycle management & Just-in-time access. Security standards such as ISO 27001, NIST 800-53, GDPR, SOX. Additional Information: Minimum 12 or more years’ experience in designing & implementing Identity & Access Management solutions. This position is based on Pan India A 15-year full time education is required