Position : Azure IGA Architect / Identity Governance & Administration (IGA) / SSO – Microsoft Stack
Location : Hyderabad (Remote)
Job Type : Fulltime
Job Description
Summary
The Azure IGA Architect is responsible for designing, implementing, and optimizing enterprise-grade identity governance and single sign-on solutions across Microsoft platforms. This role ensures secure, scalable, and automated identity lifecycle management by leveraging Azure Active Directory (Entra ID), Microsoft IGA capabilities, and integration with external applications. The architect collaborates with security, cloud, infrastructure, and application teams to drive modern identity strategies and enforce Zero Trust principles.
Key Responsibilities
Identity Governance & Administration (IGA)
- Architect and implement Azure AD / Entra ID Identity Governance solutions, including :
- Access Reviews
- Entitlement Management (Access Packages)
- Privileged Identity Management (PIM)
- Lifecycle Workflows
- Define and automate Joiner–Mover–Leaver (JML) processes.
- Integrate Microsoft Entra with HR systems (Workday, SAP SuccessFactors, Oracle HCM).
- Build provisioning / deprovisioning workflows using SCIM, Graph API, and custom connectors.
- Develop RBAC models, role mining, and access standardization across enterprise apps.
- Ensure compliance with SOX, HIPAA, PCI, ISO27001, and internal IAM governance policies.
SSO & Authentication
Architect and configure Single Sign-On (SSO) for cloud and on-prem applications using :SAML 2.0OAuth2.0 / OIDCWS-FederationIntegrate apps with Microsoft Entra Enterprise Apps, Conditional Access, and MFA.Optimize user authentication flows with Passwordless, FIDO2, and Certificate-based auth.Drive Zero Trust adoption across identity, endpoints, and applications.Azure AD / Entra ID Architecture
Design and manage multi-tenant or hybrid identity environments.Implement Conditional Access, Identity Protection, and Identity Secure Score improvements.Develop governance models for B2B and B2C identities (optional based on org).Design directory synchronization strategies using Azure AD Connect / Cloud Sync.Technical Leadership & Delivery
Lead technical workshops, requirement gathering, and architecture sessions.Produce architecture diagrams, HLD / LLD, security assessments, and deployment plans.Guide engineering teams for implementation, testing, and migration.Perform troubleshooting and advanced diagnostics for identity issues.Provide roadmap planning for Entra ID, IGA modernization, and SSO optimization.Required Skills & Experience
7–12+ years in Identity & Access Management (IAM), with at least 4 years in Microsoft Entra ID.Expertise in :Azure AD / Microsoft Entra IDIdentity Governance (IGA)SSO / Federation standardsAzure AD PIM, Access Reviews, Lifecycle WorkflowsHands-on experience integrating HR systems and SaaS apps via SCIM or Graph API.Strong PowerShell and automation experience.Deep understanding of Zero Trust, RBAC, identity lifecycle, and security best practices.Experience working in enterprise environments with regulatory controls.Preferred Qualifications
Microsoft Certifications :SC-300 , AZ-305 , AZ-104 , MS-100 / 101Experience with :MIM (Microsoft Identity Manager)SailPoint, Saviynt, or other enterprise IGA platformsCyberArk, BeyondTrust, or cloud PAM toolsExperience with CI / CD pipelines and Infrastructure-as-Code (ARM, Bicep, Terraform).Soft Skills
Strong communication and stakeholder management skills.Ability to lead cross-functional teams and influence architectural decisions.Excellent documentation and presentation capabilities.