Join Deloitte as a Security Engineer - Entra PIM and help clients strengthen privileged access controls across Microsoft Entra ID and Azure environments. In this role, you will support the implementation, validation, and governance of privileged identity management capabilities while helping teams improve security, control, and operational effectiveness. The ideal candidate brings hands-on experience in identity and access management, Microsoft cloud administration, and privileged access governance.
Work you'll do
As a Security Engineer - Entra PIM on the Cyber Risk Services—IAM team, you will be responsible for:
- Supporting configuration and validation of Microsoft Entra Privileged Identity Management (PIM) for Entra roles and Azure resource roles
- Executing testing for eligible assignments, activation settings, approvals, notifications, and audit evidence requirements
- Supporting access reviews, privileged access clean-up activities, and role owner validation processes
- Preparing technical documentation, test results, process decisions, and operational procedures for project and client use
- Collaborating with client stakeholders and technical teams to gather requirements, complete assigned activities, and escalate issues as needed
The team
The cyber risk services—IAM practice helps organizations in designing, developing, and implementing industry-leading IAM solutions to protect their information and confidential data, as well as help them build their businesses and supporting technologies to be more secure, vigilant, and resilient. The cyber risk services—IAM team delivers service to clients through following key areas of IAM:
- Application Onboarding
- Lifecycle Manager
- Compliance Manager
- Password Management
- Automated Provisioning
- Roles Management
- ITSM tools Integration
- Advanced Authentication Methods •Strategy and Road Map
Location: HYD/BLR/CHN/PUN
Shift Timings: 11 AM - 8 PM
Qualifications
Required:
- 2+ years of experience in identity and access management, security operations, cloud administration, or technology consulting
- Experience with Microsoft Entra ID and privileged access administration
- Experience supporting configuration and validation of Privileged Identity Management (PIM) for Entra roles and Azure resource roles, including eligible assignments, activation settings, approvals, and notifications
- Experience using PowerShell or Microsoft Graph for Entra administration or reporting
- Experience with least privilege, role-based access control, multifactor authentication, Conditional Access, and privileged access governance
- Experience supporting access reviews, privileged access clean-up, role owner validation, and technical documentation activities
- Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related field; alternatively, equivalent professional experience
Preferred:
- Microsoft Certified: Identity and Access Administrator Associate (SC-300)
- Experience with Microsoft Entra ID Protection, authentication strengths, lifecycle workflows, entitlement management, or access reviews
- Experience with Azure role-based access control (RBAC), management groups, subscriptions, and resource groups
- Experience with single sign-on (SSO), enterprise applications, app registrations, Security Assertion Markup Language (SAML), OpenID Connect (OIDC), System for Cross-domain Identity Management (SCIM), or federation
- Experience with security or compliance frameworks such as Zero Trust, National Institute of Standards and Technology (NIST), Sarbanes-Oxley (SOX), or General Data Protection Regulation (GDPR)