Evolent Health logo

Sr Engineer, Identity & Access Management

Evolent Health
NewPosted today

LOCATION

Pune · Remote

EXPERIENCE

7+ Years

TYPE

FullTime

SALARY

Negotiable

SKILLS REQUIRED

Identity and Access ManagementPythonIncident responseSQLRBACConditional Access

Job description

Overview

Design, implement, operate and continuously improve identity and access management capabilities across Microsoft Entra ID, Active Directory and adjacent platforms, with a focus on RBAC, conditional access, privileged access and identity governance. Build automation and agentic AI solutions to reduce manual administration and support a zero-trust security posture.

What you'll do

  • Design, implement and operate IAM capabilities including RBAC, conditional access, privileged identity management (PIM) and entitlement management.
  • Write and maintain scripts and integrations for identity provisioning, access reviews, certification workflows and reporting.
  • Design, build and deploy agentic AI solutions, such as role-mining agents, that analyze access patterns, recommend least privilege role assignments and automate periodic access certification.
  • Integrate IAM systems with endpoint management, security operations, ITSM and directory services to support end-to-end identity lifecycle management.
  • Monitor and report on identity-related security anomalies and support incident response and remediation for identity-based threats.
  • Support audit readiness by producing and maintaining documentation of IAM design, controls and automation.
  • Create, publish and communicate knowledgebase articles and standard operating procedures for IAM processes.
  • Act as a mentor to junior engineers and operations teams on IAM best practices, secure coding and responsible use of AI-driven automation.
  • Research, create proof of concepts and introduce new methods.
  • Guide others through problem solving involving technical issues, project impediments or conflicts.
  • Guide team delivery to make a positive impact on other parts of the company based on stakeholder needs and how those needs are supported by the team.
  • Own a relevant segment of systems used regularly for the business to function and understand the related KPIs.
  • Question the status quo constructively to identify areas for team improvement.
  • Regularly make an impact to the entire team.

What you'll need

  • 7+ years managing or supporting identity and access management, identity governance or related security platforms.
  • 3+ years of hands-on experience with Microsoft Entra ID (Azure AD), RBAC design, conditional access and privileged identity management (PIM).
  • Demonstrated coding or scripting ability with PowerShell, Python, Microsoft Graph API or similar, including building identity automation, integrations and reporting tools.
  • Hands-on experience designing or deploying agentic AI or automation solutions for identity/access use cases, such as role mining, access certification or anomaly detection.
  • Experience with identity protocols and standards including SAML, OAuth/OIDC and SCIM, and identity governance/compliance frameworks.
  • Working knowledge of Generative AI and agentic AI concepts, including LLM integration, tool/function calling and retrieval-augmented generation, as applied to identity and security operations.
  • Ability to write clear technical documentation.

Nice to have

  • Experience building or contributing to an internal AI agent/Center of Excellence pod, including agent design and application lifecycle management (ALM) practices.
  • Experience with Microsoft Copilot Studio or similar low-code AI agent platforms.
  • Passion for zero-trust security with an awareness of the latest identity and AI trends.
  • Bachelor’s degree in IT, Computer Science or a related field.
  • Microsoft Certified: Identity and Access Administrator Associate (SC-300).
  • Microsoft Certified: Azure AI Engineer Associate (AI-102) or Copilot Studio/agentic AI certification.

Details

  • Location: Pune.
  • Employees must have a high-speed broadband internet connection with a minimum speed of 50 Mbps and the ability to set up a wired connection to their home network to ensure effective remote work.
  • Final interviews may require onsite attendance.
  • All candidates must complete a comprehensive background check and in-person I-9 verification, and may be subject to drug screening prior to employment.
  • Identity verification during interviews includes submission of a government-issued photo ID.
  • The use of artificial intelligence tools during interviews is prohibited and monitored.

Read the full description and apply on the company’s own careers page.

Stay safe

Hiring on Abekus is free for applicants

We never charge a fee, and employers are prohibited from doing so. If a recruiter asks for payment, please report them right away.

Sr Engineer, Identity & Access Management