- Location
- IND.Pune, India
- Workplace
- Hybrid
- Type
- Full-time
- Department
- Engineering
- Experience
- 5+ years
- Source
- Workday
Description
Your work days are brighter here.
We’re obsessed with making hard work pay off, for our people, our customers, and the world around us. As a Fortune 500 company and a leading AI platform for managing people, money, and agents, we’re shaping the future of work so teams can reach their potential and focus on what matters most. The minute you join, you’ll feel it. Not just in the products we build, but in how we show up for each other. Our culture is rooted in integrity, empathy, and shared enthusiasm. We’re in this together, tackling big challenges with bold ideas and genuine care. We look for curious minds and courageous collaborators who bring sun-drenched optimism and drive. Whether you're building smarter solutions, supporting customers, or creating a space where everyone belongs, you’ll do meaningful work with Workmates who’ve got your back. In return, we’ll give you the trust to take risks, the tools to grow, the skills to develop and the support of a company invested in you for the long haul. So, if you want to inspire a brighter work day for everyone, including yourself, you’ve found a match in Workday, and we hope to be a match for you too.
About the Team
The Identity and Access management team manages the identity suite including Okta, Delinea, AD, Entra ID and KeyFactor. Team manages employees, customers and partners identity in IAM system.About the Role
The ideal candidate brings deep hands-on expertise in Windows Active Directory, Entra ID, hybrid identity, authentication and authorization protocols, certificate lifecycle management, and identity-related incident resolution. They will partner with infrastructure, security, application, endpoint, and service-management teams to deliver resilient, scalable identity services.
Key Responsibilities
Active Directory and Hybrid Identity Engineering
- Design, deploy, configure, and maintain enterprise Active Directory Domain Services, including forests, domains, sites, organizational units, trusts, DNS integration, Group Policy, replication, and domain controller lifecycle management.
- Engineer and support hybrid identity integration between on-premises AD and Microsoft Entra ID, including Microsoft Entra Connect Sync or Cloud Sync, password hash synchronization, pass-through authentication, federation where applicable, and seamless single sign-on.
- Develop and maintain logical AD designs, delegation models, administrative tiering, privileged access controls, naming standards, and lifecycle processes.
- Monitor and troubleshoot AD replication, DNS, authentication, domain controller health, Group Policy processing, directory synchronization, and identity-related service degradation.
- Plan and execute upgrades, migrations, consolidations, domain controller replacements, disaster-recovery testing, and capacity improvements with minimal business disruption.
- Implement secure configuration baselines and hardening controls aligned to organizational standards and recognized security practices.
- Administer and engineer Microsoft Entra ID capabilities, including users, groups, administrative roles, enterprise applications, app registrations, service principals, managed identities, and directory settings.
- Design and operate identity access patterns for cloud and hybrid applications using SSO, SAML, OAuth 2.0, OpenID Connect, SCIM provisioning, and modern authentication.
- Implement and maintain Conditional Access policies, multifactor authentication, passwordless authentication, authentication methods, self-service password reset, Identity Protection, and risk-based access controls.
- Support privileged identity management processes, role activation, access reviews, entitlement management, and least-privilege access models.
- Partner with application owners to onboard applications to Entra ID, resolve authentication and provisioning issues, and improve the security posture of enterprise applications.
- Manage directory synchronization and identity lifecycle workflows, including joiner, mover, leaver, group management, and access-provisioning integrations.
- Evaluate and implement relevant Microsoft Entra capabilities to enhance identity security, governance, and operational efficiency.
- Design, deploy, administer, and support enterprise PKI services, including Microsoft Active Directory Certificate Services (AD CS), certification authorities, certificate templates, enrollment policies, CRL and AIA distribution points, OCSP, and key archival/recovery where required.
- Manage the complete certificate lifecycle for internal and public certificates: request, issuance, renewal, revocation, discovery, inventory, monitoring, and retirement.
- Engineer certificate-based authentication and encryption solutions for users, devices, servers, applications, network infrastructure, and services.
- Configure and support auto-enrollment, certificate template permissions, certificate policies, enrollment agents, and secure key-management practices.
- Maintain root and subordinate CA hierarchy, offline root CA procedures, CA backup and recovery processes, HSM integrations where applicable, and documented key-ceremony controls.
- Resolve certificate-chain, trust, revocation, TLS/SSL, smart-card, device, application, and network authentication issues.
- Establish proactive certificate-expiry monitoring and automation to reduce service interruption risk.
- Identify identity and PKI risks, lead remediation activities, and support security audits, vulnerability management, compliance assessments, and incident investigations.
- Analyze identity, authentication, directory, and certificate logs to investigate incidents and provide root-cause analysis and corrective actions.
- Build and maintain automation using PowerShell, Microsoft Graph API, REST APIs, and other appropriate tooling for administration, reporting, provisioning, compliance checks, and operational tasks.
- Develop operational dashboards, health checks, alerting, and reporting for AD, Entra ID, synchronization services, authentication, and certificate infrastructure.
- Produce and maintain high-quality architecture diagrams, technical standards, runbooks, knowledge articles, implementation plans, and recovery procedures.
- Participate in on-call support, major incident response, change management, problem management, and post-incident reviews as required.
- Collaborate with cybersecurity, cloud engineering, endpoint engineering, network, application, and service-management teams to deliver integrated solutions.
About You
- Active Directory (AD DS): Multi-forest/multi-domain topologies, Group Policy Architecture, Trust relationships, Sites & Services, Kerberos/NTLM authentication flows, and AD security hardening (Tiered Administration model).
- Microsoft Entra ID (Azure AD): Advanced Conditional Access, Entra Connect/Cloud Sync, Entra ID Protection, PIM, Workload Identities, B2B/B2C, and Microsoft Graph.
- Keyfactor Ecosystem: Deep hands-on experience with Keyfactor Command, Orchestrators, Certificate Managers, and Keyfactor API integration.
- PKI & Cryptography: Deep understanding of Public Key Infrastructure principles, X.509 certificates, CRL/OCSP validation, CA hierarchy design, SSH key governance, and HSM management.
- Automation & Scripting: Expert level in PowerShell, Python, or Bash, alongside RESTful API integration for identity and PKI orchestration.
- Protocol Mastery: Deep knowledge of SAML, OAuth, OIDC, Kerberos, LDAP, SCEP, EST, ACME, and TLS/SSL.
- Experience: 10+ years in Enterprise IAM/Infrastructure Engineering, with at least 5+ years in a dedicated Lead or Solution Architect capacity.
- Communication: Ability to articulate complex cryptographic and identity concepts to C-level executives, security teams, and application developers.
- Strategic Problem Solving: Proven track record of executing large-scale PKI transitions and AD/Entra ID modernizations in complex, global environments.
• Keyfactor Certifications: Keyfactor Certified Professional / Engineer.
• Microsoft Certifications:
Microsoft Certified: Identity and Access Administrator Associate (SC-300).
Microsoft Certified: Cybersecurity Architect Expert (SC-100).
Azure Solutions Architect Expert (AZ-305).
• Industry Security Certifications: CISSP, CISM, or Certified PKI Professional (CPKIP).
Our Approach to Flexible Work
With Flex Work, we’re combining the best of both worlds: in-person time and remote. Our approach enables our teams to deepen connections, maintain a strong community, and do their best work. We know that flexibility can take shape in many ways, so rather than a number of required days in-office each week, we simply spend at least half (50%) of our time each quarter in the office or in the field with our customers, prospects, and partners (depending on role). This means you'll have the freedom to create a flexible schedule that caters to your business, team, and personal needs, while being intentional to make the most of time spent together. Those in our remote "home office" roles also have the opportunity to come together in our offices for important moments that matter.
Workday is committed to providing reasonable accommodations for qualified individuals during our application process, in order to perform one or more essential functions of their job, as well as regarding the use of AI tools for employment decision-making to any degree. Please see below for more details including how to request an accommodation as a qualified veteran, due to a disability or for religious reasons, or as otherwise provided under applicable law.
Workday prohibits taking adverse action against any candidate or employee for reporting a possible violation of this policy, requesting one or more work accommodations, exercising a privacy right, or cooperating in an investigation in accordance with applicable law. Any employee who retaliates against a candidate or employee for doing so may be subject to disciplinary action, up to and including termination of employment, to the fullest extent allowable under applicable law.
If you require a reasonable accommodation, you may email [email protected], as far in advance as possible.
Are you being referred to one of our roles? If so, ask your connection at Workday about our Employee Referral process!
At Workday, we value our candidates’ privacy and data security. Workday will never ask candidates to apply to jobs through websites that are not Workday Careers.
Please be aware of sites that may ask for you to input your data in connection with a job posting that appears to be from Workday but is not.
In addition, Workday will never ask candidates to pay a recruiting fee, or pay for consulting or coaching services, in order to apply for a job at Workday.