Role Summary
The
Entra Senior IGA Engineer
is responsible for implementing, supporting, and optimizing identity governance solutions using
Microsoft Entra ID (Azure AD)
. This role focuses on user lifecycle automation, access governance, SSO integrations, and strengthening enterprise identity security. The engineer will work closely with the architecture, security, and application teams to develop & deploy scalable, compliant IGA controls across the organization.
Key Responsibilities
Identity Governance (IGA)
- Implement and maintain Microsoft Entra ID Identity Governance components:
- Access Reviews
- Privileged Identity Management (PIM)
- Lifecycle Workflows
- Entitlement Management (Access Packages)
- Configure and optimize Joiner–Mover–Leaver (JML) automation.
- Support integration of HR systems (Workday, SuccessFactors, Oracle HCM) with Entra ID for identity lifecycle.
- Create and maintain RBAC models, group design, and access policies.
Identity Lifecycle & Provisioning
- Build and maintain provisioning workflows using SCIM, Graph API, and Azure automations.
- Manage group-based access, dynamic groups, and conditional access assignments.
- Implement automated deprovisioning to ensure least-privilege access.
SSO & Federation
- Integrate enterprise applications with Entra ID using:
- Configure Conditional Access, MFA, and Passwordless authentication methods.
Operations & Security
- Troubleshoot identity issues, SSO failures, provisioning errors, and access assignment problems.
- Monitor, report, and remediate identity risks using Identity Protection and Secure Score.
- Support audit, SOX compliance, and access certification cycles.
- Maintain detailed documentation (runbooks, configuration guides, SOPs).
Technical Delivery
- Assist architects with HLD/LLD design inputs.
- Participate in onboarding new applications and services into Entra ID.
- Collaborate with DevOps and automation teams to streamline identity workflows.
- Provide L3 support for identity-related incidents.
Required Skills & Experience
- 8-10 years in IAM/IGA engineering roles.
- Deep hands-on experience with Microsoft Entra ID / Azure AD.
- Strong practical expertise in:
- Access Reviews
- PIM
- Lifecycle Workflows
- Access Packages / Entitlement Management
- Group automation & RBAC
- Experience with SCIM connectors, Graph API, and PowerShell scripting.
- Solid understanding of SSO protocols (SAML, OAuth/OIDC).
- Experience in troubleshooting identity provisioning and SSO issues.
- Strong understanding of identity security, Zero Trust, and compliance requirements.
Preferred Qualifications
- Microsoft certifications: SC-300, AZ-104, MS-100/101.
- Experience with Conditional Access, Identity Protection, and Privileged Access strategies.
- Experience with Azure Automation, Logic Apps, or PowerShell modules for Entra ID.
Soft Skills
- Strong analytical and problem-solving abilities.
- Excellent communication and documentation skills.
- Ability to work independently and in cross-functional teams.
- Detail-oriented with a focus on governance and security.