Principal Engineer – Identity & Access Management (IAM) Directory Services
Job Summary
Role Overview
We are seeking aPrincipal Engineer Identity & Access Management (IAM)to serve as thetechnical authority and architectural ownerfor enterprise and customer-facing authentication authorization and directory services. This role underpins theavailability security and continuityof global digital platforms and business-critical environments.
This is adeeply technical hands-on principal rolerequiring architectural-level expertise acrossActive Directory Entra ID (Azure AD & B2C) Oracle Unified Directory (OUD) and Linux/Unix authentication systems operating within a complex hybrid identity ecosystem.
The role ismission critical: failures in identity architecture directly translate intowidespread access disruption security exposure productivity loss and compliance risk. This engineer will eliminate single points of failure strengthen directory security posture support M&A integrations and ensure identity services scale securely and reliably across all regions.
Key Responsibilities
IAM & Directory Services Architecture Ownership
- Act as theprincipal technical ownerfor global IAM and directory services platforms supporting enterprise partner and customer-facing applications
- Define document and evolveend-to-end IAM architecture including:
- Active Directory (enterprise-scale hybrid multi-region)
- Entra ID / Azure AD (including B2C and external identities)
- Oracle Unified Directory (OUD)
- Linux and Unix authentication and authorization integrations
- Establishreference architectures engineering standards and operational patternsfor identity platforms
- Design forhigh availability fault tolerance disaster recovery and regional resilience
Authentication & Authorization Reliability
- Ensurecontinuous availabilityof authentication and authorization services by proactively managing identity dependencies
- Own directory synchronization federation and authentication flows across hybrid environments
- Eliminate architectural and operational single points of failure
- Prevent identity issues that could result in:
- Global user access degradation
- Business application downtime
- Customer- and partner-facing access disruption
Security Zero Trust & Risk Reduction
- Make identity theprimary control planefor Zero Trust initiatives
- Enforceleast privilege strong authentication and continuous verification
- Design and implementRBAC ABAC and policy-based authorization models
- Strengthen directory security posture by addressing:
- Privileged access exposure
- Legacy protocols and weak authentication mechanisms
- Inconsistent policy enforcement and configuration drift
- Reduce identity-based attack paths and systemic access risk
Non-Human AI & Machine Identity Protection
- Architect and securenon-human identities including:
- AI agent identities
- Robotic Process Automation (RPA) identities
- Service accounts workloads APIs and system identities
- Define lifecycle management authentication authorization and rotation strategies for machine identities
- Prevent credential sprawl over-privileged access and unmanaged secrets
- Ensure AI and robotic identities adhere toZero Trust least privilege and auditable access principles
- Integrate non-human identity controls into enterprise IAM governance and monitoring
Integration & User Experience
- Improve identity integration across:
- Enterprise applications
- Partner platforms
- Customer-facing (B2C) ecosystems
- Ensure seamless low-friction authentication experiences without compromising security
- Enable scalable access models for human and non-human identities
Mergers & Acquisitions (M&A) Support
- Serve as theIAM technical leadfor M&A initiatives
- Assess acquired company identity architectures directory services and authentication models
- Design and execute secure identity integration consolidation or coexistence strategies
- Mitigate access risk during transitions while maintaining business continuity
- Ensure acquired environments align with enterprise IAM Zero Trust and security standards
Continuity Innovation & Long-Term Strategy
- Ensureknowledge continuityand eliminate dependency on individual resources
- Define amulti-year IAM and directory services roadmapaligned with enterprise architecture and Zero Trust maturity
- Evaluate emerging identity technologies protocols and access models including AI-driven identity use cases
- Mentor engineers and elevate IAM engineering maturity across the organization
Required Qualifications
Experience
- 12 yearsof experience in Identity & Access Management directory services or security platform engineering
- Proven experience supportingglobal highly available business-critical identity systems
Technical Expertise
- Architectural-level expertise in:
- Active Directory (enterprise and hybrid environments)
- Entra ID / Azure AD including B2C
- Oracle Unified Directory (OUD)
- Linux and Unix authentication mechanisms
- Strong understanding of:
- Authentication and authorization flows
- Identity federation and synchronization
- RBAC ABAC and policy-driven access models
- Zero Trust and identity-centric security architecture
- Hands-on experience with identity protocols:
- SAML 2.0 OAuth 2.0 OpenID Connect (OIDC) Kerberos LDAP/LDAPS SCIM RADIUS SSH key-based authentication PAM (Pluggable Authentication Modules) for Linux certificate-based authentication (X.509) and modern API-based identity integrations etc.
- Experience with automation and integration:
- PowerShell Python APIs infrastructure-as-code preferred
Architectural & Leadership Skills
- Ability to design foravailability resilience and failure scenarios
- Strong systems thinking and long-term technical judgment
- Proven ability to influence architecture and strategy across teams without formal authority
- Comfortable operating inambiguous high-impact environments
Preferred Qualifications
- Experience supportingcustomer-facing digital platformsat global scale
- Cloud IAM experience across Azure AWS and/or GCP
- Familiarity with identity governance privileged access and compliance frameworks
- Experience working with globally distributed teams including India-based engineering support models
- Prior experience supporting identity integration during M&A activities
Why This Role Is Critical
Identity is aTier-0 dependency. Without a resilient well-architected IAM foundation failures in authentication authorization or machine identity control quickly becomeenterprise-wide risk events.
This role directly protects the organization from:
- Identity-driven downtime and degraded user access
- Over-privileged or unmanaged AI robotic and service identities
- Increased risk during mergers acquisitions and integrations
- Delays or failures in Zero Trust adoption
- Compliance exposure and erosion of trust
This Principal Engineer ensurescontinuity resilience and long-term sustainabiliyof identity servicesacross humans machines and AIthat the business depends on every day.
#LI-7013Required Experience:
Director
About Company
NXP is a global semiconductor company creating solutions that enable secure connections for a smarter world.