Location
Hyderabad, Telangana, IN
About the Role
Job Description – Principal IAM Engineer (Active Directory & BeyondTrust)
Role Overview
The Principal IAM Engineer is a senior, hands-on technical authority responsible for end-to-end engineering ownership, design decisions, and technical governance of enterprise Identity and Access Management (IAM) platforms, with deep expertise in Active Directory (AD) and BeyondTrust (PAM/EPM).
This role acts as the highest-level technical escalation (L4) for IAM engineering, drives architecture standards, and ensures IAM platforms are secure, scalable, resilient, and audit-ready across on-prem, hybrid, and cloud environments.
Key Responsibilities
Active Directory – Principal Engineering Ownership
• Own architecture, design authority, and technical standards for Active Directory.
• Design and govern AD forest/domain architecture, trust models, OU strategies, and delegation.
• Lead Domain Controller lifecycle management including build, hardening, patching, and health.
• Design and approve Group Policy (GPO) strategies aligned with security and compliance.
• Troubleshoot complex replication, DNS, authentication, and Kerberos issues.
• Lead AD modernization and technical debt reduction initiatives.
BeyondTrust – Privileged Access & Endpoint Privilege Engineering
• Act as technical authority for BeyondTrust PAM / EPM platforms.
• Design least-privilege enforcement and endpoint elevation policies.
• Define enterprise privilege use cases, guardrails, and exception handling.
• Ensure auditability and monitoring of privileged access activities.
Architecture, Standards & Governance
• Define IAM engineering standards, reference architectures, and patterns.
• Review and approve high-risk IAM designs and integrations.
• Align IAM platforms to Zero Trust and identity-centric security models.
• Drive roadmap, upgrades, and continuous improvement initiatives.
Operational Excellence
• Serve as L4 escalation point for complex IAM issues.
• Lead root cause analysis for critical incidents.
• Ensure SOPs, runbooks, and design artifacts are maintained.
Mentorship & Technical Leadership
• Mentor IAM engineers and leads through design and technical reviews.
• Act as trusted advisor to security, infrastructure, and application teams.
Required Skills & Experience
• 12+ years of experience in IAM or security engineering.
• Expert-level hands-on experience with Active Directory.
• Strong expertise in BeyondTrust PAM / EPM.
• Advanced PowerShell scripting skills.
• Experience in large, regulated enterprise environments.
Good to Have
• Experience with Microsoft Entra ID / Azure AD.
• Exposure to SailPoint or other IGA platforms.
• Knowledge of ISO 27001, SOX, HITRUST, or SOC 2 environments.
• Zero Trust architecture familiarity.
Role Level Clarification
• Principal-level individual contributor
• Technical authority role (non-people manager)
Ideal Candidate
Someone who has progressed from hands-on AD/PAM engineer to architectural decision-maker in a regulated enterprise (financial services, healthcare, or Fortune 500), with a track record of modernizing legacy IAM infrastructure and mentoring technical teams.
Estimated Salary Range(medium confidence)
₹24 L – ₹36 L per year
Likely Interview Questions
- 1.Walk us through your most complex Active Directory forest redesign—what architectural decisions did you make, and how did you handle migration risk in a regulated environment?
🔒 4 more questions locked — unlock with Professional + run a full mock interview
🔒 Strengths to highlight + red flags locked.
SAGE
Mock interview coach
Rehearse the 5 most-likely questions for this role with live AI feedback.
SPAR
Resume tailoring
Rewrite your resume to lead with what this hiring panel cares about.
REACH
Warm intro outreach
Find the hiring manager + 2nd-degree intros and draft the messages.
More Accounting & Audit Roles
View all →Chief Manager/Joint Assistant Vice President - Mutual Fund Operations
Virtuous Advisors and Resources Pvt. ltd. · Mumbai
Posted 2 days ago
Chief Finance Officer
SM IT SERVICES · Mumbai
Posted 4 days ago
CFO - Finance Controller
Macro Resources Pvt Ltd · Kolkata
Posted 1 week ago
Head of Financial Reporting and Audit
Citco Group Limited · All India, Thane
Posted 1 month ago
90% of leadership roles never appear on job boards
Join HireIQ to access confidential opportunities, AI-powered matching, and direct connections to hiring decision-makers.
Join the Talent Network