- Location
- Bangalore, India
- Workplace
- Hybrid
- Type
- Full-time
- Department
- Engineering
- Seniority
- Lead
- Experience
- 12+ years
- Source
- Workday
Description
Role Overview
We are seeking a Principal Engineer – Identity & Access Management (IAM) to serve as the technical authority and architectural owner for enterprise and customer-facing authentication, authorization, and directory services. This role underpins the availability, security, and continuity of global digital platforms and business-critical environments.
This is a deeply technical, hands-on principal role requiring architectural-level expertise across Active Directory, Entra ID (Azure AD & B2C), Oracle Unified Directory (OUD), and Linux/Unix authentication systems, operating within a complex hybrid identity ecosystem.
The role is mission critical: failures in identity architecture directly translate into widespread access disruption, security exposure, productivity loss, and compliance risk. This engineer will eliminate single points of failure, strengthen directory security posture, support M&A integrations, and ensure identity services scale securely and reliably across all regions.
Key Responsibilities
IAM & Directory Services Architecture Ownership
- Act as the principal technical owner for global IAM and directory services platforms supporting enterprise, partner, and customer-facing applications
- Define, document, and evolve end-to-end IAM architecture, including:
- Active Directory (enterprise-scale, hybrid, multi-region)
- Entra ID / Azure AD (including B2C and external identities)
- Oracle Unified Directory (OUD)
- Linux and Unix authentication and authorization integrations
- Establish reference architectures, engineering standards, and operational patterns for identity platforms
- Design for high availability, fault tolerance, disaster recovery, and regional resilience
Authentication & Authorization Reliability
- Ensure continuous availability of authentication and authorization services by proactively managing identity dependencies
- Own directory synchronization, federation, and authentication flows across hybrid environments
- Eliminate architectural and operational single points of failure
- Prevent identity issues that could result in:
- Global user access degradation
- Business application downtime
- Customer- and partner-facing access disruption
Security, Zero Trust & Risk Reduction
- Make identity the primary control plane for Zero Trust initiatives
- Enforce least privilege, strong authentication, and continuous verification
- Design and implement RBAC, ABAC, and policy-based authorization models
- Strengthen directory security posture by addressing:
- Privileged access exposure
- Legacy protocols and weak authentication mechanisms
- Inconsistent policy enforcement and configuration drift
- Reduce identity-based attack paths and systemic access risk
Non-Human, AI & Machine Identity Protection
- Architect and secure non-human identities, including:
- AI agent identities
- Robotic Process Automation (RPA) identities
- Service accounts, workloads, APIs, and system identities
- Define lifecycle management, authentication, authorization, and rotation strategies for machine identities
- Prevent credential sprawl, over-privileged access, and unmanaged secrets
- Ensure AI and robotic identities adhere to Zero Trust, least privilege, and auditable access principles
- Integrate non-human identity controls into enterprise IAM governance and monitoring
Integration & User Experience
- Improve identity integration across:
- Enterprise applications
- Partner platforms
- Customer-facing (B2C) ecosystems
- Ensure seamless, low-friction authentication experiences without compromising security
- Enable scalable access models for human and non-human identities
Mergers & Acquisitions (M&A) Support
- Serve as the IAM technical lead for M&A initiatives
- Assess acquired company identity architectures, directory services, and authentication models
- Design and execute secure identity integration, consolidation, or coexistence strategies
- Mitigate access risk during transitions while maintaining business continuity
- Ensure acquired environments align with enterprise IAM, Zero Trust, and security standards
Continuity, Innovation & Long-Term Strategy
- Ensure knowledge continuity and eliminate dependency on individual resources
- Define a multi-year IAM and directory services roadmap aligned with enterprise architecture and Zero Trust maturity
- Evaluate emerging identity technologies, protocols, and access models, including AI-driven identity use cases
- Mentor engineers and elevate IAM engineering maturity across the organization
Required Qualifications
Experience
- 12+ years of experience in Identity & Access Management, directory services, or security platform engineering
- Proven experience supporting global, highly available, business-critical identity systems
Technical Expertise
- Architectural-level expertise in:
- Active Directory (enterprise and hybrid environments)
- Entra ID / Azure AD, including B2C
- Oracle Unified Directory (OUD)
- Linux and Unix authentication mechanisms
- Strong understanding of:
- Authentication and authorization flows
- Identity federation and synchronization
- RBAC, ABAC, and policy-driven access models
- Zero Trust and identity-centric security architecture
- Hands-on experience with identity protocols:
- SAML 2.0, OAuth 2.0, OpenID Connect (OIDC), Kerberos, LDAP/LDAPS, SCIM, RADIUS, SSH key-based authentication, PAM (Pluggable Authentication Modules) for Linux, certificate-based authentication (X.509), and modern API-based identity integrations, etc.
- Experience with automation and integration:
- PowerShell, Python, APIs, infrastructure-as-code preferred
Architectural & Leadership Skills
- Ability to design for availability, resilience, and failure scenarios
- Strong systems thinking and long-term technical judgment
- Proven ability to influence architecture and strategy across teams without formal authority
- Comfortable operating in ambiguous, high-impact environments
Preferred Qualifications
- Experience supporting customer-facing digital platforms at global scale
- Cloud IAM experience across Azure, AWS, and/or GCP
- Familiarity with identity governance, privileged access, and compliance frameworks
- Experience working with globally distributed teams, including India-based engineering support models
- Prior experience supporting identity integration during M&A activities
Why This Role Is Critical
Identity is a Tier-0 dependency. Without a resilient, well-architected IAM foundation, failures in authentication, authorization, or machine identity control quickly become enterprise-wide risk events.
This role directly protects the organization from:
- Identity-driven downtime and degraded user access
- Over-privileged or unmanaged AI, robotic, and service identities
- Increased risk during mergers, acquisitions, and integrations
- Delays or failures in Zero Trust adoption
- Compliance exposure and erosion of trust
This Principal Engineer ensures continuity, resilience, and long-term sustainabiliy of identity services—across humans, machines, and AI—that the business depends on every day.
#LI-7013