Principal Engineer – Identity Governance & Administration (IGA)
NXP Semiconductors · Bangalore
onsitefull-time10+ years
posted 15h
Role Overview We are seeking a Principal Engineer – Identity & Access Management (IAM) to serve as the technical authority and architectural owner for enterprise and customer-facing authentication, authorization, and directory services. This role underpins the availability, security, and continuity of global digital platforms and business-critical environments. This is a deeply technical, hands-on principal role requiring architectural-level expertise across Active Directory, Entra ID (Azure AD & B2C), Oracle Unified Directory (OUD), and Linux/Unix authentication systems , operating within a complex hybrid identity ecosystem. The role is mission critical : failures in identity architecture directly translate into widespread access disruption, security exposure, productivity loss, and compliance risk . This engineer will eliminate single points of failure, strengthen directory security posture, support M&A integrations, and ensure identity services scale securely and reliably across all regions. Key Responsibilities IAM & Directory Services Architecture Ownership Act as the principal technical owner for global IAM and directory services platforms supporting enterprise, partner, and customer-facing applications Define, document, and evolve end-to-end IAM architecture , including: Active Directory (enterprise-scale, hybrid, multi-region) Entra ID / Azure AD (including B2C and external identities) Oracle Unified Directory (OUD) Linux and Unix authentication and authorization integrations Establish reference architectures, engineering standards, and operational patterns for identity platforms Design for high availability, fault tolerance, disaster recovery, and regional resilience Authentication & Authorization Reliability Ensure continuous availability of authentication and authorization services by proactively managing identity dependencies Own directory synchronization, federation, and authentication flows across hybrid environments Eliminate architectural and operational single points of failure Prevent identity issues that could result in: Global user access degradation Business application downtime Customer- and partner-facing access disruption Security, Zero Trust & Risk Reduction Make identity the primary control plane for Zero Trust initiatives Enforce least privilege, strong authentication, and continuous verification Design and implement RBAC, ABAC, and policy-based authorization models Strengthen directory security posture by addressing: Privileged access exposure Legacy protocols and weak authentication mechanisms Inconsistent policy enforcement and configuration drift Reduce identity-based attack paths and systemic access risk Non-Human, AI & Machine Identity Protection Architect and secure non-human identities , including: AI agent identities Robotic Process Automation (RPA) identities Service accounts, workloads, APIs, and system identities Define lifecycle management, authentication, authorization, and rotation strategies for machine identities Prevent credential sprawl, over-privileged access, and unmanaged secrets Ensure AI and robotic identities adhere to Zero Trust, least privilege, and auditable access principles Integrate non-human identity controls into enterprise IAM governance and monitoring Integration & User Experience Improve identity integration across: Enterprise applications Partner platforms Customer-facing (B2C) ecosystems Ensure seamless, low-friction authentication experiences without compromising security Enable scalable access models for human and non-human identities Mergers & Acquisitions (M&A) Support Serve as the IAM technical lead for M&A initiatives Assess acquired company identity architectures, directory services, and authentication models Design and execute secure identity integration, consolidation, or coexistence strategies Mitigate access risk during transitions while maintaining business continuity Ensure acquired environments align with enterprise IAM, Zero Trust, and security sta