About the job
As a Senior Identity & Access Management Engineer at Enpal, you will take ownership of our workforce's Identity & Access Management within Microsoft Entra ID. Your primary responsibility will be to ensure secure and scalable access through Conditional Access, a robust administrative model, and dependable identity lifecycle processes (Onboarding, Transitions, Offboarding). You will facilitate least-privilege access through RBAC, PIM/PAM, and regular access reviews, while promoting secure collaboration and sharing.
Policy Development and Governance:
Define and uphold IAM standards and guidelines for Entra ID, encompassing authentication, Conditional Access principles, privileged access, and external collaboration.
Establish and maintain the administrative model (role design, separation of duties, privileged role assignment strategy) and enforce least privilege through RBAC.
Oversee processes for access reviews, exceptions, and audit evidence related to identity controls.
IAM Engineering and Operations:
Administer and continuously enhance Microsoft Entra ID (tenant configuration, role design, groups, identity settings) as the core identity platform.
Design, implement, and manage Conditional Access policies (including rollout strategies, exclusions, and safe operations).
Develop and oversee Joiner/Mover/Leaver lifecycle processes, ensuring timely provisioning and deprovisioning while minimizing manual access management.
Manage Privileged Access controls:
Implement and maintain PIM/PAM (activation workflows, approval, time-bound access, role eligibility).
Oversee break-glass accounts and emergency access procedures (creation, secure storage, testing frequency).
Govern identity objects and special cases:
Manage guest accounts and external collaboration controls.
Oversee shared mailboxes, mail-enabled objects, and distribution groups.
Manage service/admin accounts and Microsoft 365 Groups/Security groups.
Drive operational quality through documentation, runbooks, change management, and troubleshooting of access/provisioning issues.
Collaboration and Stakeholder Engagement:
Collaborate with Corporate IT, HR, and application owners to ensure the quality of identity data and facilitate seamless onboarding and offboarding.
Provide guidance to teams on access design, RBAC models, group strategy, and reducing direct access.

