Senior Engineer, Identity Access Management
The Identity & Access Management (IAM) Engineer is responsible for supporting, administering, engineering, and continuously improving enterprise identity and access management services. This role works as part of the Digital Identity & Access team to deliver secure, reliable, and efficient identity services across the organization. The IAM Engineer will support identity lifecycle management, authentication, Single Sign-On (SSO), Multi-Factor Authentication (MFA), Conditional Access, application integrations, certificates, and related identity technologies. The successful candidate will combine strong technical capabilities with disciplined operational practices, documentation, change management, and collaboration across Technology and Information Security teams. This is a hybrid role and work hours are 2pm – 11pm IST.
Responsibilities:
Identity & Access Management
Support the administration and engineering of enterprise identity and access management platforms and services.
Configure and maintain Single Sign-On (SSO), Multi-Factor Authentication (MFA), authentication policies, and Conditional Access controls.
Support Microsoft Entra ID and Active Directory identity services.
Support identity lifecycle processes including user provisioning, modification, deprovisioning, and access changes.
Troubleshoot complex authentication, authorization, and access-related issues.
Support application onboarding and integration with enterprise identity platforms using technologies and standards such as SAML, OAuth, OpenID Connect, and related authentication protocols.
Support identity federation and authentication integrations with SaaS, cloud, and internally developed applications.
Assist with the administration and support of Auth0 and other enterprise authentication platforms.
Support role-based access control and group-based access management.
Identity Security & Governance
Partner with Information Security to implement and maintain identity security standards and controls.
Support periodic access reviews, certifications, audit requests, and compliance activities.
Assist with the implementation and maintenance of appropriate separation-of-duties controls.
Identify excessive, inappropriate, or outdated access and work with appropriate stakeholders to remediate identified issues.
Support privileged identity and access management processes where applicable.
Assist with investigation and remediation of identity-related security events.
Ensure identity configurations and processes align with organizational security standards and established governance requirements.
PKI & Certificate Management
Support enterprise Public Key Infrastructure (PKI) and certificate-management processes.
Monitor certificate expiration and coordinate certificate renewals to prevent service disruption.
Assist application and technology teams with certificate requests, renewals, deployment, and troubleshooting.
Maintain accurate documentation and visibility into enterprise certificates and associated ownership.
Engineering & Automation
Identify opportunities to automate repetitive IAM activities and improve operational efficiency.
Develop and maintain scripts and automation supporting identity administration, reporting, provisioning, and operational processes.
Support integrations between IAM platforms, enterprise applications, HR systems, and other technology services.
Participate in identity-platform upgrades, enhancements, migrations, and modernization initiatives.
Contribute to the development and maintenance of IAM architecture, standards, technical documentation, and operational procedures.
Service Management & Operations
Manage IAM incidents, requests, problems, and changes in accordance with established service-management processes.
Develop implementation, testing, validation, rollback, and communication plans for production changes.
Ensure changes are appropriately documented, reviewed, approved, and communicated prior to implementation.
Maintain accurate and timely visibility into assigned work, projects, changes, risks, and commitments.
Develop and maintain technical documentation, standard operating procedures, knowledge articles, and support runbooks.
Participate in troubleshooting and resolution of major incidents involving identity or authentication services.
Identify recurring issues and contribute to root-cause analysis and permanent corrective actions.
Collaboration & Customer Experience
Partner with Digital Workplace, Information Security, Infrastructure, Application Development, Enterprise Systems, HR, Service Management, and other technology teams.
Provide technical guidance to application owners integrating applications with enterprise identity services.
Communicate technical issues, risks, dependencies, and recommendations clearly to both technical and non-technical stakeholders.
Balance security requirements with the need to provide reliable and intuitive authentication and access experiences for practitioners.
Demonstrate a collaborative, accountable, and service-oriented approach to delivering identity services.
Essential traits:
3–5+ years of experience supporting or engineering enterprise Identity & Access Management technologies.
Hands-on experience with Microsoft Entra ID and Active Directory.
Experience implementing or supporting Single Sign-On (SSO), Multi-Factor Authentication (MFA), and Conditional Access.
Experience integrating enterprise applications using SAML, OAuth 2.0, OpenID Connect, or similar authentication standards.
Experience troubleshooting complex authentication and access-related issues.
Understanding of identity lifecycle management, including provisioning, deprovisioning, access changes, and role/group management.
Working knowledge of identity security principles, least privilege, role-based access control, and separation of duties.
Experience working within formal change, incident, request, and problem-management processes.
Strong documentation and organizational skills.
Ability to work collaboratively across technical teams and communicate effectively with stakeholders.
About Kroll
In a world of disruption and increasingly complex business challenges, our professionals bring truth into focus with the Kroll Lens. Our sharp analytical skills, paired with the latest technology, allow us to give our clients clarity—not just answering all areas of business. We value the diverse backgrounds and perspectives that enable us to think globally. As part of One team, One Kroll, you will contribute to a supportive and collaborative work environment that empowers you to excel.
Kroll is the premier global valuation and corporate finance advisor with expertise in complex valuation, disputes and investigations, M&A, restructuring, and compliance and regulatory consulting. Our professionals balance analytical skills, deep market insight and independence to help our clients make sound decisions. As an organization, we think globally—and encourage our people to do the same.
Kroll is committed to equal opportunity and diversity, and recruits people based on merit.
In order to be considered for a position, you must formally apply via careers.kroll.com
#LI-AT1
#LI-Hybrid
Skills Required
- 3-5+ years of experience supporting or engineering enterprise Identity and Access Management technologies
- Hands-on experience with Microsoft Entra ID and Active Directory
- Experience implementing or supporting Single Sign-On, Multi-Factor Authentication, and Conditional Access
- Experience integrating enterprise applications using SAML, OAuth 2.0, OpenID Connect, or similar authentication standards
- Experience troubleshooting complex authentication and access-related issues
- Understanding of identity lifecycle management, including provisioning, deprovisioning, access changes, and role/group management
- Working knowledge of least privilege, role-based access control, and separation of duties
- Experience working within formal change, incident, request, and problem-management processes
- Strong documentation and organizational skills
- Ability to collaborate across technical teams and communicate effectively with stakeholders
Kroll Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Kroll and has not been reviewed or approved by Kroll.
-
Healthcare Strength — Medical, dental, and vision coverage with HSA/FSA options are part of the U.S. package, alongside life and AD&D. Breadth across core health benefits is positioned as competitive for a large advisory firm.
-
Retirement Support — A 401(k) plan with company match is a core element of the package. Retirement support is consistently highlighted as competitive within total rewards.
-
Leave & Time Off Breadth — Paid holidays, sick leave, and PTO are included, with generous time off and parental/family leave for U.S. roles. Some roles also offer hybrid/WFH flexibility that complements time-off usability.
Kroll Insights
What We Do
Kroll is the world’s premier provider of services and digital products related to valuation, governance, risk and transparency. We work with clients across diverse sectors in the areas of valuation, expert services, investigations, cyber security, corporate finance, restructuring, legal and business solutions, data analytics and regulatory compliance. Our firm has nearly 5,000 professionals in 30 countries and territories around the world. For more information, visit www.kroll.com.







