About Redcare Pharmacy
As Europe’s No. 1 e-pharmacy, Redcare Pharmacy is powered by passionate teams and cutting-edge innovation. We strive to create a healthy, collaborative work environment where every employee feels valued and inspired to contribute to our vision: “Until every human has their health.” If you’re seeking a career that offers purpose and aligns with your values, join us and start your #Redcareer today.
About the role
We are looking for a Senior Cloud Identity Engineer to help shape the future of identity engineering in our Microsoft Cloud environment. You will build secure, scalable and highly automated identity solutions that empower decentralized teams to innovate independently while operating within clear governance, Zero Trust principles and Least Privilege guardrails.
As part of our Cloud & Security team, you will help define the future of identity across Azure, Data, ERP and AI platforms, driving modern approaches for human, workload and AI-driven identities. From Identity Blueprints and agent identities to enterprise-wide governance, you will have the opportunity to influence strategic cloud security initiatives and establish identity as the foundation of a secure, scalable and AI-ready cloud platform.
About the tech stack
Core technologies
You will work with a modern Microsoft Cloud identity ecosystem, leveraging technologies such as Microsoft Entra, Microsoft Graph API, Microsoft Entra ID Governance (including Access Reviews), Azure, Azure RBAC, Entra RBAC, Azure Policy, Azure Key Vault, Managed Identities, Enterprise Applications, App Registrations, Service Principals, Certificate Lifecycle Management, Administrative Units, Conditional Access, Identity Protection, Workload Identity Federation, Microsoft Sentinel, Azure Monitor, Log Analytics, Kusto Query Language (KQL), Microsoft 365, Active Directory (Core Services), OAuth 2.0 and OpenID Connect.
You will help design secure identity architectures with a strong focus on Least Privilege, Azure Policy, Guardrails and Governance, as well as Permission Misuse Detection & Identity Monitoring.
Automation is a key part of this role, using PowerShell and Bash, alongside Microsoft Graph API, Azure Functions or Logic Apps, to build secure, scalable identity solutions and governance processes that follow Zero Trust and the Least Privilege principle across Azure and Microsoft Entra services.
Nice to have
As we continue to evolve our cloud identity platform for AI-driven and autonomous workloads, experience with modern AI-assisted engineering tools (e.g. GitHub Copilot, Claude Code, Codex or similar AI coding assistants) as well as Microsoft technologies such as Entra Agent ID, Identity Blueprints and Microsoft 365 Agents / Copilot is considered a plus.
Job DescriptionAbout your tasks
- Design and scale Microsoft Entra ID Governance by implementing Access Reviews, defining governance processes together with business stakeholders and building script-based automation to roll out governance capabilities consistently across a decentralized Microsoft Entra environment.
- Engineer secure workload identity services by automating the lifecycle of Service Principals, certificates, secrets and federated credentials, integrating directly with Azure Key Vault and ensuring every solution follows Least Privilege principles from day one.
- Design and implement modern self-service capabilities for Service Principals, Entra Groups and delegated administration, enabling engineering teams to work independently without unnecessary ownership or excessive permissions.
- Review and optimize Azure RBAC, Entra RBAC, application permissions, Microsoft Graph permissions and OAuth consent models to continuously reduce excessive privileges, strengthen identity governance and improve Redcare’s cloud identity security posture.
- Build identity monitoring and detection capabilities to proactively identify expiring credentials, permission misuse and guardrail violations using Microsoft Sentinel, Azure Monitor, Log Analytics and Kusto Query Language (KQL).
- Support the automation of Joiner, Mover and Leaver processes with HRIS as single source of truth for identity
About you
- You bring hands-on experience designing and automating cloud identity solutions with Microsoft Entra, Administrative Units, Microsoft Entra ID Governance, Microsoft Graph Permissions, Azure, Microsoft 365 and Power Platform in complex cloud environments.
- You enjoy engineering secure, scalable identity platforms and designing Zero Trust and Least Privilege architectures while balancing developer experience with enterprise security requirements. You naturally think in automation, APIs, governance and secure-by-design rather than manual administration.
- You challenge unnecessary permissions and advocate for modern identity governance, Permission Misuse Detection and continuous improvement to build secure, scalable cloud environments.
- You are curious about emerging identity technologies, enjoy experimenting with new ideas, sharing your knowledge and presenting technical concepts to colleagues and stakeholders. You collaborate across teams to continuously improve the way cloud identity is designed, governed, secured and automated.
About your benefits:
In order to provide you with the best possible support for your individual needs - whether it‘s living a healthy life, having enough time for your family, or developing your skills - we offer a wide range of different, site-specific benefits.
- Welcome days: We want you to feel at home with us from the very first day. Therefore, we welcome you with our comprehensive onboarding program.
- Remote space: For our remote working employees we grant you 500,00 € to set up your office space from home. To create an environment for you and how you work best.
- Anchor days: As per your remote contract there will be some occasions to travel to office for anchor days, this is fully reimbursed including any travelling costs or hotel expenses.
- Personal development: Grow! We support and encourage your individual development through various in- and external trainings.
- Employee referral program: Because you know best who fits in with us, successful recommendations are rewarded with a bonus.
Skills Required
- Hands-on experience with Microsoft Entra, Administrative Units and Microsoft Entra ID Governance
- Experience with Microsoft Graph API and Microsoft Graph permissions
- Designing and operating Azure including Azure RBAC, Azure Policy and Azure Key Vault
- Workload identity management: Service Principals, App Registrations, Managed Identities, certificate and secret lifecycle automation
- Knowledge of Conditional Access, Identity Protection and Workload Identity Federation
- Build identity monitoring and detection using Microsoft Sentinel, Azure Monitor, Log Analytics and Kusto Query Language (KQL)
- Scripting and automation skills (PowerShell and Bash) and experience with Azure Functions or Logic Apps
- Experience designing Zero Trust and Least Privilege identity architectures and governance
- Experience integrating identity lifecycle with HRIS (Joiner/Mover/Leaver processes)
- Familiarity with Microsoft 365 and Active Directory core services in cloud contexts
- Experience with AI-assisted engineering tools (GitHub Copilot, Claude Code, Codex) and Entra Agent ID, Identity Blueprints, Microsoft 365 Agents/Copilot
What We Do
As Redcare Pharmacy - formerly known as Shop Apotheke Europe - we put care at the heart of everything we do, guiding people through their health to help turn bad days into better ones. We are Europe’s people-first pharmacy. Start your #Redcareer now! Let's grow together. We are an international company that is currently active in seven countries in Europe and is growing rapidly. Our headquarters as well as on of our distribution centre are located in Sevenum in the Netherlands near the German border. Our other distribution centre is in Milan, Italy. In total, we have locations in Cologne, Berlin, Munich, Tongeren, Warsaw, Milan, Lille and Eindhoven. We are always looking for new colleagues - people who not only get involved in our international team, but who want to actively take on responsibility and who want to grow together with us as a strong partner









