Principal Engineer – Identity & Access Management (IAM) Directory Services

Posted 2 Days Ago
Be an Early Applicant
Bangalore, Bengaluru Urban, Karnataka, IND
In-Office
Expert/Leader
Automotive • Internet of Things • Mobile • Semiconductor • Industrial
The Role
Own the architecture, reliability, security, and long-term strategy of global IAM and directory services. Design resilient Active Directory, Entra ID, OUD, and Linux/Unix identity environments; lead authentication, authorization, federation, synchronization, Zero Trust, and machine identity protection. Support M&A identity integrations, reduce systemic access risks, improve customer and enterprise authentication, establish engineering standards, and mentor teams.
Summary Generated by Built In

Role Overview

We are seeking a Principal Engineer – Identity & Access Management (IAM) to serve as the technical authority and architectural owner for enterprise and customer-facing authentication, authorization, and directory services. This role underpins the availability, security, and continuity of global digital platforms and business-critical environments.

This is a deeply technical, hands-on principal role requiring architectural-level expertise across Active Directory, Entra ID (Azure AD & B2C), Oracle Unified Directory (OUD), and Linux/Unix authentication systems, operating within a complex hybrid identity ecosystem.

The role is mission critical: failures in identity architecture directly translate into widespread access disruption, security exposure, productivity loss, and compliance risk. This engineer will eliminate single points of failure, strengthen directory security posture, support M&A integrations, and ensure identity services scale securely and reliably across all regions.

Key Responsibilities

IAM & Directory Services Architecture Ownership

  • Act as the principal technical owner for global IAM and directory services platforms supporting enterprise, partner, and customer-facing applications
  • Define, document, and evolve end-to-end IAM architecture, including:
    • Active Directory (enterprise-scale, hybrid, multi-region)
    • Entra ID / Azure AD (including B2C and external identities)
    • Oracle Unified Directory (OUD)
    • Linux and Unix authentication and authorization integrations
  • Establish reference architectures, engineering standards, and operational patterns for identity platforms
  • Design for high availability, fault tolerance, disaster recovery, and regional resilience

Authentication & Authorization Reliability

  • Ensure continuous availability of authentication and authorization services by proactively managing identity dependencies
  • Own directory synchronization, federation, and authentication flows across hybrid environments
  • Eliminate architectural and operational single points of failure
  • Prevent identity issues that could result in:
    • Global user access degradation
    • Business application downtime
    • Customer- and partner-facing access disruption

Security, Zero Trust & Risk Reduction

  • Make identity the primary control plane for Zero Trust initiatives
  • Enforce least privilege, strong authentication, and continuous verification
  • Design and implement RBAC, ABAC, and policy-based authorization models
  • Strengthen directory security posture by addressing:
    • Privileged access exposure
    • Legacy protocols and weak authentication mechanisms
    • Inconsistent policy enforcement and configuration drift
  • Reduce identity-based attack paths and systemic access risk

Non-Human, AI & Machine Identity Protection

  • Architect and secure non-human identities, including:
    • AI agent identities
    • Robotic Process Automation (RPA) identities
    • Service accounts, workloads, APIs, and system identities
  • Define lifecycle management, authentication, authorization, and rotation strategies for machine identities
  • Prevent credential sprawl, over-privileged access, and unmanaged secrets
  • Ensure AI and robotic identities adhere to Zero Trust, least privilege, and auditable access principles
  • Integrate non-human identity controls into enterprise IAM governance and monitoring

Integration & User Experience

  • Improve identity integration across:
    • Enterprise applications
    • Partner platforms
    • Customer-facing (B2C) ecosystems
  • Ensure seamless, low-friction authentication experiences without compromising security
  • Enable scalable access models for human and non-human identities

Mergers & Acquisitions (M&A) Support

  • Serve as the IAM technical lead for M&A initiatives
  • Assess acquired company identity architectures, directory services, and authentication models
  • Design and execute secure identity integration, consolidation, or coexistence strategies
  • Mitigate access risk during transitions while maintaining business continuity
  • Ensure acquired environments align with enterprise IAM, Zero Trust, and security standards

Continuity, Innovation & Long-Term Strategy

  • Ensure knowledge continuity and eliminate dependency on individual resources
  • Define a multi-year IAM and directory services roadmap aligned with enterprise architecture and Zero Trust maturity
  • Evaluate emerging identity technologies, protocols, and access models, including AI-driven identity use cases
  • Mentor engineers and elevate IAM engineering maturity across the organization

Required Qualifications

Experience

  • 12+ years of experience in Identity & Access Management, directory services, or security platform engineering
  • Proven experience supporting global, highly available, business-critical identity systems

Technical Expertise

  • Architectural-level expertise in:
    • Active Directory (enterprise and hybrid environments)
    • Entra ID / Azure AD, including B2C
    • Oracle Unified Directory (OUD)
    • Linux and Unix authentication mechanisms
  • Strong understanding of:
    • Authentication and authorization flows
    • Identity federation and synchronization
    • RBAC, ABAC, and policy-driven access models
    • Zero Trust and identity-centric security architecture
  • Hands-on experience with identity protocols:
    • SAML 2.0, OAuth 2.0, OpenID Connect (OIDC), Kerberos, LDAP/LDAPS, SCIM, RADIUS, SSH key-based authentication, PAM (Pluggable Authentication Modules) for Linux, certificate-based authentication (X.509), and modern API-based identity integrations, etc.
  • Experience with automation and integration:
    • PowerShell, Python, APIs, infrastructure-as-code preferred

Architectural & Leadership Skills

  • Ability to design for availability, resilience, and failure scenarios
  • Strong systems thinking and long-term technical judgment
  • Proven ability to influence architecture and strategy across teams without formal authority
  • Comfortable operating in ambiguous, high-impact environments

Preferred Qualifications

  • Experience supporting customer-facing digital platforms at global scale
  • Cloud IAM experience across Azure, AWS, and/or GCP
  • Familiarity with identity governance, privileged access, and compliance frameworks
  • Experience working with globally distributed teams, including India-based engineering support models
  • Prior experience supporting identity integration during M&A activities

Why This Role Is Critical

Identity is a Tier-0 dependency. Without a resilient, well-architected IAM foundation, failures in authentication, authorization, or machine identity control quickly become enterprise-wide risk events.

This role directly protects the organization from:

  • Identity-driven downtime and degraded user access
  • Over-privileged or unmanaged AI, robotic, and service identities
  • Increased risk during mergers, acquisitions, and integrations
  • Delays or failures in Zero Trust adoption
  • Compliance exposure and erosion of trust

This Principal Engineer ensures continuity, resilience, and long-term sustainabiliy of identity services—across humans, machines, and AI—that the business depends on every day.

More information about NXP in India...

#LI-7013

Skills Required

  • 12+ years of experience in Identity and Access Management, directory services, or security platform engineering
  • Experience supporting global, highly available, business-critical identity systems
  • Architectural-level expertise with enterprise and hybrid Active Directory environments
  • Architectural-level expertise with Entra ID or Azure AD, including B2C
  • Architectural-level expertise with Oracle Unified Directory
  • Architectural-level expertise with Linux and Unix authentication mechanisms
  • Understanding of authentication and authorization flows, identity federation, and synchronization
  • Understanding of RBAC, ABAC, and policy-driven access models
  • Understanding of Zero Trust and identity-centric security architecture
  • Hands-on experience with SAML 2.0, OAuth 2.0, OpenID Connect, Kerberos, LDAP/LDAPS, SCIM, RADIUS, SSH key-based authentication, PAM, X.509, and API-based identity integrations
  • Ability to design for availability, resilience, disaster recovery, and failure scenarios
  • Ability to influence architecture and strategy across teams without formal authority
  • Strong systems thinking and long-term technical judgment
  • Experience with PowerShell, Python, APIs, and infrastructure-as-code
  • Experience supporting customer-facing digital platforms at global scale
  • Cloud IAM experience across Azure, AWS, and/or GCP
  • Familiarity with identity governance, privileged access, and compliance frameworks
  • Experience working with globally distributed teams, including India-based engineering support models
  • Experience supporting identity integration during mergers and acquisitions
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Eindhoven
21,993 Employees
Year Founded: 2006

What We Do

NXP Semiconductors N.V. (NASDAQ: NXPI) enables a smarter, safer and more sustainable world through innovation. As a world leader in secure connectivity solutions for embedded applications, NXP is pushing boundaries in the automotive, industrial & IoT, mobile, and communication infrastructure markets. Built on more than 60 years of combined experience and expertise, the company has approximately 34,500 employees in more than 30 countries and posted revenue of $13.21 billion in 2022. Find out more at www.nxp.com. Privacy Policy: https://www.nxp.com/company/about-nxp/privacy-policy-for-social-media-pages:PRIVACY-POLICY-SOCIAL-MEDIA

Similar Jobs

Capital One Logo Capital One

Manager, Product Management

Fintech • Machine Learning • Payments • Software • Financial Services
Hybrid
Bengaluru, Bengaluru Urban, Karnataka, IND
55000 Employees

Capital One Logo Capital One

Manager, Corporate Communications

Fintech • Machine Learning • Payments • Software • Financial Services
Hybrid
Bengaluru, Bengaluru Urban, Karnataka, IND
55000 Employees

Optum Logo Optum

Software Engineer

Artificial Intelligence • Big Data • Healthtech • Information Technology • Machine Learning • Software • Analytics
In-Office
Bengaluru, Bengaluru Urban, Karnataka, IND
160000 Employees

Ericsson Logo Ericsson

Window Exchange Expert

Cloud • Information Technology • Internet of Things • Machine Learning • Software • Cybersecurity • Infrastructure as a Service (IaaS)
In-Office
Bangalore, Bengaluru Urban, Karnataka, IND
88000 Employees

Similar Companies Hiring

ARB Interactive Thumbnail
Gaming • Mobile • Software
Miami, Florida
190 Employees
Granted Thumbnail
Artificial Intelligence • Healthtech • Insurance • Mobile • Financial Services
New York, New York
23 Employees
Amalgamated Sugar Thumbnail
Food • Greentech • Agriculture • Industrial • Manufacturing
Boise, Idaho
768 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account