Azure PIM (Privileged Identity Management) Senior Engineer

Apply
Apply

Share

successfully icon

Successfully

The vacancy has been successfully added to favorites

location icon

Bengaluru, India

specialization icon

Cybersecurity

lob icon

Cross Industry Solutions

date icon

27/08/2026

Req. VR-124770

Apply
Project description

We are seeking an experienced Azure Privileged Identity Management (PIM) Senior Engineer to drive the design, implementation, automation, and governance of privileged access management within Microsoft Entra ID (Azure AD) and Azure environments. This role requires a highly skilled identity professional with proven expertise in managing Azure PIM end-to-end, including privileged role governance, access lifecycle management, automation, compliance, and security controls.
The ideal candidate will have hands-on experience implementing and operating Azure PIM in large-scale enterprise environments, developing automation using Terraform, Git, Ansible, PowerShell, and Python and customizing federation integrations through CI/CD pipelines. The candidate should possess deep knowledge of privileged identity governance, Service Principal lifecycle management, Managed Identity administration, and privileged access controls aligned with Zero Trust principles.
This role will partner closely with Identity & Access Management, Cloud Engineering, Cybersecurity, DevOps, and Compliance teams to ensure privileged access is managed securely, efficiently, and in accordance with enterprise security standards.

Responsibilities
bullet icon

Lead the design, implementation, configuration, and ongoing administration of Microsoft Entra ID (Azure AD) Privileged Identity Management (PIM).

bullet icon

Manage privileged access controls across Microsoft Entra ID, Azure subscriptions, management groups, resource groups, and Azure resources.

bullet icon

Define and maintain privileged access governance policies, standards, operational procedures, and security controls aligned with enterprise requirements.

bullet icon

Design and implement Just-In-Time (JIT) access, role eligibility, approval workflows, access reviews, Privileged Access Groups, and role activation policies.

bullet icon

Perform privileged access assessments, role reviews, recertifications, and remediation of excessive or inappropriate access.

bullet icon

Develop, maintain, and enhance automation solutions using Terraform, Git, CI/CD Pipelines, Ansible, PowerShell, and Python for identity and privileged access management.

bullet icon

Build reusable Infrastructure-as-Code (IaC) modules and deployment frameworks for Azure PIM, role assignments, Service Principals, Managed Identities, and related identity governance controls.

bullet icon

Design, customize, and support federation integrations and authentication workflows using automated CI/CD pipelines.

bullet icon

Manage and troubleshoot federation configurations, claims transformations, token issuance policies, and authentication-related issues.

bullet icon

Develop and maintain REST API-based integrations and automation workflows for identity lifecycle management.

bullet icon

Manage the complete lifecycle of Service Principals, Enterprise Applications, and Managed Identities, including provisioning, governance, credential management, and decommissioning.

bullet icon

Implement and manage secrets, certificates, credential rotation, expiration monitoring, and secure authentication practices for non-human identities.

bullet icon

Automate onboarding, access assignment, certification, and retirement processes for privileged and service identities.

bullet icon

Monitor privileged access activities and maintain reporting, dashboards, and audit evidence to support security, compliance, and operational requirements.

bullet icon

Support internal and external audits, security reviews, risk assessments, and compliance initiatives related to privileged access management.

bullet icon

Investigate and resolve identity, authentication, authorization, and privileged access issues across Azure environments.

bullet icon

Collaborate with IAM, Security, Cloud Engineering, DevOps, and application teams to implement secure and scalable access management solutions.

bullet icon

Drive continuous improvements in privileged access governance, identity security, automation, and operational efficiency.

Skills

Must have

bullet icon

7+ years of experience in Identity and Access Management (IAM) and Microsoft Azure environments.

bullet icon

Experience integrating identity security controls with enterprise DevSecOps practices

bullet icon

Terraform (Mandatory and Expert Level)

bullet icon

Git-Based Source Control and Automation Frameworks (Mandatory and Expert Level)

bullet icon

REST API Integrations and CI/CD Pipelines (Mandatory and Expert Level)

bullet icon

PowerShell (Mandatory and Expert Level)

bullet icon

Python (Mandatory and Expert Level)

bullet icon

Microsoft Certified: Identity and Access Administrator Associate (SC-300)

bullet icon

Microsoft Certified: Azure Security Engineer Associate (AZ-500)

bullet icon

Microsoft Certified: Azure Administrator Associate (AZ-104)

bullet icon

Experience supporting large enterprise or global Azure environments.

bullet icon

Experience implementing Zero Trust security principles.

bullet icon

Knowledge of cloud security, governance, and compliance frameworks.

Nice to have

bullet icon

Work in agile environment

Other
seniority icon

Languages

English: C1 Advanced

seniority icon

Seniority

Senior

Bengaluru, India

Req. VR-124770

Cybersecurity

Cross Industry Solutions

27/08/2026

Req. VR-124770

Apply for Azure PIM (Privileged Identity Management) Senior Engineer in Bengaluru

*Indicates a required field

Under the terms of your specific consent or to perform our obligations under a contract with you, as applicable, we, Luxoft Holding Inc. will manually and electronically process your personal data, specifically your first name, last name, phone number, e-mail address and other data you provide us through this form.


Within this context, we process personal data only for the specific purpose(s) indicated in the individual consent language or other notices provided below.


We will – insofar as reasonably necessary for the purpose you have agreed to and within the scope of applicable laws – transfer your personal data to other entities within the Luxoft Group and to the group of third party recipients listed in our Privacy Notice. Such Recipients can be located outside the European Union (EU) and/or the European Economic Area (EEA) (“Third Countries”). The Third Countries concerned, e.g. the USA, may not have the level of data protection that you enjoy e.g. under the GDPR. This can result in disadvantages such as an impeded enforcement of data subjects’ rights, a lack of control over further processing and access by state authorities. You may only have limited legal remedies against this. Insofar our transfer of your personal data to recipients in Third Countries is not covered by an adequacy decision of the EU Commission, we achieve an adequate level of data protection as further detailed out in our Privacy Notice.


With your consent, we personalise marketing communications to you by way of carrying out marketing research analysis, analysing the surfing-behaviour of our website visitors and to adjust it to their detected tendencies, as well as to plan more efficient future marketing activities. This personalised marketing does not include any automated decision-making activities.


Further information on how we process personal data in general is available in our Privacy Notice. You may withdraw any given consent at any time. The withdrawal of your consent(s) will not affect the lawfulness of processing before its withdrawal. For any request in this context, please e-mail us at: DPO@luxoft.com.


Before uploading CV or any other information to this website, to learn more about your obligations and restrictions arising from the use of this website, please read our Terms of Use.