Overview
Security Engineer on the Identity & Access Management (IAM) – Directory Services team, responsible for engineering and operating secure, standardized, automated enterprise identity foundations across The Walt Disney Company.
What you'll do
- Engineer, harden, and operate large-scale, multi-domain Active Directory environments supporting critical business workloads.
- Lead Active Directory consolidation and domain rationalization across enterprise, eCommerce, and business-unit directories.
- Operate and enhance RadiantLogic’s Virtual Directory Services for federated and multi-source identity use cases.
- Establish, define, implement, and enforce baseline identity security standards across complex, multi-domain environments.
- Implement and mature RBAC-based access models within Active Directory.
- Integrate Active Directory with Privileged Identity Management and Privileged Access Management platforms.
- Eliminate standing privilege through group-based, time-bound, and just-in-time (JIT) access patterns.
- Implement and sustain Tier 0 security posture, including privileged account separation and Privileged Access Workstations (PAW).
- Implement and support bi-directional synchronization between Active Directory and Entra ID.
- Support cross-tenant identity governance for business segments and federated environments.
- Enable automated human and non-human identity governance, including monitoring, remediation, and compliance reporting.
- Improve identity governance and lifecycle accuracy through authoritative attribute synchronization and automation.
- Reduce directory and tool sprawl while maintaining service reliability and business continuity.
- Mentor and uplift junior engineers and contribute to repeatable engineering patterns and documentation.
What you'll need
- 8+ years of hands-on experience engineering and operating large-scale Active Directory environments.
- Deep expertise in Active Directory architecture, trusts, replication, DNS, and PKI.
- Deep expertise in multi-domain and multi-forest designs.
- Deep expertise in Active Directory security hardening and recovery.
- Deep expertise in RadiantLogic’s Virtual Directory Services.
- Proven experience implementing or supporting RBAC, PIM, and PAM.
- Proven experience with privileged account separation and Tier 0 controls.
- Strong troubleshooting skills in complex, highly regulated environments.
- Experience working in enterprise-scale IAM or directory services teams.
- Bachelor’s degree in Computer Science, Information Systems, Software, Electrical or Electronics Engineering, or a comparable field of study, and/or equivalent work experience.
Nice to have
- Experience integrating AD with Entra ID / Azure AD in hybrid or cloud-first environments.
- Familiarity with identity governance automation, non-human identity management, and continuous compliance.
- Experience supporting cross-tenant or multi-business-unit identity models.
- Background in directory consolidation, legacy system sunset, or M&A identity integration.
- Comfort operating in environments with high security, resilience, and audit expectations.
Details
- Employment type: Full time.
- Location: Bangalore, India.
Read the full description and apply on the company’s own careers page.