All jobs

AD, Azure AD and PKI Architect

Workday2w ago
IND.PuneHybridFull-time
  • Your work days are brighter here. We’re obsessed with making hard work pay off, for our people, our customers
  • the world around us. As a Fortune 500 company and a leading AI platform for managing people, money
  • agents, we’re shaping the future of work so teams can reach their potential and focus on what matters most. The minute you join, you’ll feel it. Not just in the products we build, but in how we show up for each other. Our culture is rooted in integrity, empathy
  • shared enthusiasm. We’re in this together, tackling big challenges with bold ideas and genuine care. We look for curious minds and courageous collaborators who bring sun-drenched optimism and drive. Whether you're building smarter solutions, supporting customers
  • creating a space where everyone belongs, you’ll do meaningful work with Workmates who’ve got your back. In return, we’ll give you the trust to take risks, the tools to grow, the skills to develop and the support of a company invested in you for the long haul. So, if you want to inspire a brighter work day for everyone, including yourself, you’ve found a match in Workday
  • we hope to be a match for you too. About the Team The Identity and Access management team manages the identity suite including Okta, Delinea, AD, Entra ID and KeyFactor. Team manages employees, customers and partners identity in IAM system. About the Role We are seeking a skilled Active Directory (AD), Microsoft Entra ID (formerly Azure Active Directory)
  • Public Key Infrastructure (PKI) Architect to design, implement, operate, secure
  • continuously improve our enterprise identity and certificate services. This role will own engineering activities across on-premises and cloud identity platforms, with a strong focus on availability, security, automation, governance
  • a seamless user experience. The ideal candidate brings deep hands-on expertise in Windows Active Directory, Entra ID, hybrid identity, authentication and authorization protocols, certificate lifecycle management
  • identity-related incident resolution. They will partner with infrastructure, security, application, endpoint
  • service-management teams to deliver resilient, scalable identity services. Key Responsibilities Active Directory and Hybrid Identity Engineering Design, deploy, configure
  • maintain enterprise Active Directory Domain Services, including forests, domains, sites, organizational units, trusts, DNS integration, Group Policy, replication
  • domain controller lifecycle management. Engineer and support hybrid identity integration between on-premises AD and Microsoft Entra ID, including Microsoft Entra Connect Sync or Cloud Sync, password hash synchronization, pass-through authentication, federation where applicable
  • seamless single sign-on. Develop and maintain logical AD designs, delegation models, administrative tiering, privileged access controls, naming standards
  • lifecycle processes. Monitor and troubleshoot AD replication, DNS, authentication, domain controller health, Group Policy processing, directory synchronization
  • identity-related service degradation. Plan and execute upgrades, migrations, consolidations, domain controller replacements, disaster-recovery testing
  • capacity improvements with minimal business disruption. Implement secure configuration baselines and hardening controls aligned to organizational standards and recognized security practices. Microsoft Entra ID / Azure AD Engineering Administer and engineer Microsoft Entra ID capabilities, including users, groups, administrative roles, enterprise applications, app registrations, service principals, managed identities
  • directory settings. Design and operate identity access patterns for cloud and hybrid applications using SSO, SAML, OAuth 2.0, OpenID Connect, SCIM provisioning
  • modern authentication. Implement and maintain Conditional Access policies, multifactor authentication, passwordless authentication, authentication methods, self-service password reset, Identity Protection
  • risk-based access controls. Support privileged identity management processes, role activation, access reviews, entitlement management
  • least-privilege access models. Partner with application owners to onboard applications to Entra ID, resolve authentication and provisioning issues
  • improve the security posture of enterprise applications. Manage directory synchronization and identity lifecycle workflows, including joiner, mover, leaver, group management
  • access-provisioning integrations. Evaluate and implement relevant Microsoft Entra capabilities to enhance identity security, governance
  • operational efficiency. PKI and Certificate Services Engineering Design, deploy, administer
  • support enterprise PKI services, including Microsoft Active Directory Certificate Services (AD CS), certification authorities, certificate templates, enrollment policies, CRL and AIA distribution points, OCSP
  • key archival/recovery where required. Manage the complete certificate lifecycle for internal and public certificates: request, issuance, renewal, revocation, discovery, inventory, monitoring
  • retirement. Engineer certificate-based authentication and encryption solutions for users, devices, servers, applications, network infrastructure
  • services. Configure and support auto-enrollment, certificate template permissions, certificate policies, enrollment agents
  • secure key-management practices. Maintain root and subordinate CA hierarchy, offline root CA procedures, CA backup and recovery processes, HSM integrations where applicable
  • documented key-ceremony controls. Resolve certificate-chain, trust, revocation, TLS/SSL, smart-card, device, application
  • network authentication issues. Establish proactive certificate-expiry monitoring and automation to reduce service interruption risk. Security, Automation
  • Operational Excellence Identify identity and PKI risks, lead remediation activities
  • support security audits, vulnerability management, compliance assessments
  • incident investigations. Analyze identity, authentication, directory
  • certificate logs to investigate incidents and provide root-cause analysis and corrective actions. Build and maintain automation using PowerShell, Microsoft Graph API, REST APIs
  • other appropriate tooling for administration, reporting, provisioning, compliance checks
  • operational tasks. Develop operational dashboards, health checks, alerting
  • reporting for AD, Entra ID, synchronization services, authentication
  • certificate infrastructure. Produce and maintain high-quality architecture diagrams, technical standards, runbooks, knowledge articles, implementation plans
  • recovery procedures. Participate in on-call support, major incident response, change management, problem management
  • post-incident reviews as required. Collaborate with cybersecurity, cloud engineering, endpoint engineering, network, application
  • service-management teams to deliver integrated solutions. About You Required Skills & Qualifications Active Directory (AD DS): Multi-forest/multi-domain topologies, Group Policy Architecture, Trust relationships, Sites & Services, Kerberos/NTLM authentication flows
  • AD security hardening (Tiered Administration model). Microsoft Entra ID (Azure AD): Advanced Conditional Access, Entra Connect/Cloud Sync, Entra ID Protection, PIM, Workload Identities, B2B/B2C
  • Microsoft Graph. Keyfactor Ecosystem: Deep hands-on experience with Keyfactor Command , Orchestrators, Certificate Managers
  • Keyfactor API integration. PKI & Cryptography: Deep understanding of Public Key Infrastructure principles, X.509 certificates, CRL/OCSP validation, CA hierarchy design, SSH key governance
  • HSM management. Automation & Scripting: Expert level in PowerShell , Python
  • Bash, alongside RESTful API integration for identity and PKI orchestration. Protocol Mastery: Deep knowledge of SAML, OAuth, OIDC, Kerberos, LDAP, SCEP, EST, ACME
  • TLS/SSL. Experience: 10 + years in Enterprise IAM/Infrastructure Engineering, with at least 5 + years in a dedicated Lead or Solution Architect capacity. Communication: Ability to articulate complex cryptographic and identity concepts to C-level executives, security teams
  • application developers. Strategic Problem Solving: Proven track record of executing large-scale PKI transitions and AD/Entra ID modernizations in complex, global environments. Preferred Certifications
  • Keyfactor Certifications: Keyfactor Certified Professional / Engineer.
  • Microsoft Certifications: Microsoft Certified: Identity and Access Administrator Associate (SC-300). Microsoft Certified: Cybersecurity Architect Expert (SC-100). Azure Solutions Architect Expert (AZ-305).
  • Industry Security Certifications: CISSP, CISM
  • Certified PKI Professional (CPKIP). Our Approach to Flexible Work With Flex Work, we’re combining the best of both worlds: in-person time and remote. Our approach enables our teams to deepen connections, maintain a strong community
  • do their best work. We know that flexibility can take shape in many ways, so rather than a number of required days in-office each week, we simply spend at least half (50%) of our time each quarter in the office or in the field with our customers, prospects
  • partners (depending on role). This means you'll have the freedom to create a flexible schedule that caters to your business, team
  • being intentional to make the most of time spent together. Those in our remote "home office" roles also have the opportunity to come together in our offices for important moments that matter. Workday is committed to providing reasonable accommodations for qualified individuals during our application process, in order to perform one or more essential functions of their job, as well as regarding the use of AI tools for employment decision-making to any degree. Please see below for more details including how to request an accommodation as a qualified veteran, due to a disability or for religious reasons
  • as otherwise provided under applicable law. Workday prohibits taking adverse action against any candidate or employee for reporting a possible violation of this policy, requesting one or more work accommodations, exercising a privacy right
  • cooperating in an investigation in accordance with applicable law. Any employee who retaliates against a candidate or employee for doing so may be subject to disciplinary action, up to and including termination of employment, to the fullest extent allowable under applicable law. If you require a reasonable accommodation, you may email accommodations@workday.com , as far in advance as possible. Are you being referred to one of our roles? If so, ask your connection at Workday about our Employee Referral process! At Workday, we value our candidates’ privacy and data security. Workday will never ask candidates to apply to jobs through websites that are not Workday Careers. Please be aware of sites that may ask for you to input your data in connection with a job posting that appears to be from Workday but is not. In addition, Workday will never ask candidates to pay a recruiting fee
  • pay for consulting or coaching services, in order to apply for a job at Workday.

Required skills

PythonRESTAzureSecurity
Posted on JobRush — the end-to-end AI job-search platform.