Sr. Cyber Security Engineer
Bayer · Bengaluru
- Experience8–9 yrs
- SalaryNot disclosed
- Work modeonsite
- Levelexecutive
- Posted17 Sept 2026
About Bayer
Bayer is hiring in Bengaluru in pharma biotech. This role looks for around 8+ years of experience.
Skills
- Active Directory
- Entra ID
- hybrid identity architectures
- PowerShell
- Zero Trust
- Conditional Access
- Identity Protection
- Privileged Identity Management
- Azure AD Connect
- ADFS
- certificate infrastructures
- modern authentication
- cloud security
- identity security
The role
A security engineer at a global life sciences company designs and operates Active Directory, Entra ID, and hybrid identity architectures, securing authentication and access control through Zero Trust patterns. The role also applies PowerShell and intelligent automation to identity operations and incident remediation.
Full job description
At Bayer we’re visionaries, driven to solve the world’s toughest challenges and striving for a world where ,Health for all, Hunger for none’ is no longer a dream, but a real possibility. We’re doing it with energy, curiosity and sheer dedication, always learning from unique perspectives of those around us, expanding our thinking, growing our capabilities and redefining ‘impossible’. There are so many reasons to join us. If you’re hungry to build a varied and meaningful career in a community of brilliant and diverse minds to make a real difference, there’s only one choice.
Sr. Cyber Security Engineer
POSITION PURPOSE:
The Cyber Security Engineer for Active Directory & Entra ID is a key technical authority responsible for designing, engineering, and operating Bayer’s global directory and authentication platforms. This role supports the transformation and modernization of our hybrid identity landscape, ensuring secure, scalable, and compliant identity foundations for the enterprise. The role contributes to architectural decisions, incident and problem management at the highest technical tier, complex troubleshooting, and innovation through automation and Agentic ‑ AI – supported operations. As a senior expert, you will guide engineering direction, mentor junior engineers, and support major global programs impacting identity, authentication, and access control.
YOUR TASKS AND RESPONSIBILITIES:
Strategic & Architectural Responsibilities
Serve as a senior subject ‑ matter expert for Active Directory, Entra ID, and hybrid identity components across Bayer. Lead architectural design, strategy development, modernization, lifecycle management, and future ‑ state planning for directory and authentication services. Define and enforce directory security baselines, Zero Trust design patterns, privileged access governance, and identity ‑ related risk mitigation measures. Provide expert input into large ‑ scale programs (e.g., cloud modernization, mergers & acquisitions, carve ‑ outs, workplace platform evolutions).
Operational & Engineering Responsibilities
Lead complex troubleshooting and root ‑ cause analysis for AD, Entra ID, conditional access, and authentication flows. Drive stability and service performance through engineering improvements, proactive monitoring, hardening, and automation. Provide senior ‑ level guidance to L2/L3 operational teams and act as final technical escalation point for major incidents.
Agentic AI & Automation Integration
Drive the integration of Agentic AI to enhance troubleshooting, prediction, decision support, and remediation across authentication services. Design and validate AI ‑ assisted operational workflows, runbooks, and automated actions to support reliable and efficient platform operations. Identify automation opportunities to improve monitoring, self ‑ healing, provisioning, and lifecycle management processes. Ensure that AI ‑ supported workflows follow Bayer ’ s security, privacy, and compliance frameworks.
Service & Process Excellence
Lead service improvement initiatives, architecture reviews, operational readiness assessments, and global change implementations. Create, improve, and maintain technical documentation, engineering standards, operational procedures, and runbooks. Support regulatory and audit needs (e.g., GxP, ICS, internal audits) by ensuring identity controls, logging, and procedures are compliant. Coordinate with service management on KPIs, SLAs, problem management, and continuous improvement.
Collaboration & Stakeholder Management
Work closely with global IAM squads, Workplace Services, Cloud Engineering, IT Security Architecture, and external partners. Act as a senior advisor to application teams, platform owners, and business IT functions on directory design, integration, and authentication patterns. Represent IAM in cross ‑ functional engineering councils, design reviews, and security governance forums. Mentor junior engineers and contribute to capability growth across the IAM organization.
WHO YOU ARE:
Required
8+ years hands ‑ on experience with Active Directory, Entra ID, and hybrid identity architectures. Deep knowledge of AD internals: FSMO roles, replication, GPO architecture, DNS integration, schema management, trusts, multi ‑ domain environments. Strong experience with Entra ID: Conditional Access, Identity Protection, PIM, enterprise applications, app registrations, authentication policies. Expertise in AAD Connect / Cloud Sync, ADFS or other federation platforms, certificate infrastructures, and modern authentication flows. Advanced PowerShell skills and ability to automate large ‑ scale identity operations. Proven experience managing major incidents, complex problem solving, and engineering ‑ level service ownership. Solid understanding of Zero Trust, identity security and cloud security patterns. Excellent communication skills and ability to work effectively with global, cross ‑ functional teams.
Preferred
Experience with infrastructure ‑ as ‑ code, CI/CD pipelines, Azure automation, or DevOps toolchains. Experience with Agentic AI platforms, AI ‑ assisted operations, and intelligent automation. Familiarity with AWS identity integrations, enterprise networking concepts, and certificate ‑ based authentication scenarios. Experience in regulated environments (SOX, GxP) or large enterprise IT environments.
Ever feel burnt out by bureaucracy? Us too. That's why we're changing the way we work- for higher productivity, faster innovation, and better results. We call it Dynamic Shared Ownership (DSO). Learn more about what DSO will mean for you in your new role here
https://www.bayer.com/enfstrategyfstrategy
Bayer does not charge any fees whatsoever for recruitment process. Please do not entertain such demand for payment by any individuals / entities in connection with recruitment with any Bayer Group entity(ies) worldwide under any pretext.
Please don’t rely upon any unsolicited email from email addresses not ending with domain name “bayer.com” or job advertisements referring you to an email address that does not end with “bayer.com”. For checking the authenticity of such emails or advertisement you may approach us at HRSUPPORT_INDIA@BAYER.COM.
YOUR APPLICATION
Bayer is an equal opportunity employer that strongly values fairness and respect at work. We welcome applications from all individuals, regardless of race, religion, gender, age, physical characteristics, disability, sexual orientation etc. We are committed to treating all applicants fairly and avoiding discrimination.
Location: India : Karnataka : Bangalore
Division: Enabling Functions
Reference Code: 876336
Contact Us
022-25311234