Sr. Engineer I - Privileged Access Platform Management

MKS Inc. · Gurgaon

  • Experience5–9 yrs
  • SalaryNot disclosed
  • Work modeonsite
  • Posted29 Sept 2026

About MKS Inc.

MKS Inc. is hiring in Gurgaon in semiconductors electronics. This role looks for around 5+ years of experience.

Skills

  • Privileged Access Management
  • Enterprise Single Sign-On
  • Secrets Management
  • Microsoft Entra ID
  • Active Directory
  • SAML
  • OpenID Connect
  • SCIM
  • PowerShell
  • Security Information and Event Management
  • Least Privilege
  • Just-In-Time Access
  • Identity and Access Management
  • Endpoint Security

The role

A security engineer at a semiconductor and electronics company designs and governs privileged access management, enterprise single sign-on, and secrets management, integrating identity platforms with directories, endpoint tools, and security operations. The role applies PowerShell and zero trust to deliver audited access services and strengthen security engineering practice.

Full job description

A Day in Your Life at MKS

We are seeking a handson professional to own the strategy, engineering, and lifecycle of core identity and endpoint security toolsEvidian (Authentication Manager / Enterprise SSO), Admin By Request (privileged access elevation), and 1Password (password management & secrets). As product owner and technical authority, you will ensure these platforms are securely designed, integrated, monitored, and continuously improved to meet business and regulatory needs, partnering with IAM, Endpoint, IT Ops, Enterprise Architecture, Security Operations, and Compliance to deliver reliable, audited, and userfriendly security services globally

You Will Make an Impact By

Platform Ownership & Strategy- Act as product owner for Evidian (Authentication Manager / Enterprise SSO), Admin By Request, and 1Passwordowning roadmaps, backlog, release planning, and stakeholder communication. Define architecture and configuration baselines aligned to zero trust, least privilege, and separation of duties, while maintaining platform governance across access models, workflows, policies, standards, and lifecycle management. Engineering & Integration- Design and implement integrations with enterprise directories (e.g., Azure AD/Entra ID, AD), HRIS (for joinermoverleaver), MDM/UEM (e.g., Intune), SIEM/SOAR, ticketing (ServiceNow/Jira), and secrets pipelines (CI/CD). Security & Compliance-Implement leastprivilege controls with Admin By Request (approval policies, justintime elevation, allow/deny lists, session auditing) and operate 1Password enterprise policies (domain capture, vault hygiene, phishingresistant MFA, secrets access controls, recovery processes). Operations & Service Management -Own SLAs/OLAs, incident/problem/change management, patching, upgrades, and vendor management. Provide L3 support and enable L1/L2 teams through documentation and training.

Skills You Bring

5+ years in IAM/Security Engineering or Endpoint Security, with 2+ years administering at least two of the following: Evidian (Authentication Manager / Enterprise SSO), Admin By Request (or equivalent PAM/JIT elevation), 1Password (or enterprise password/secrets managers). Strong experience with Entra ID/Azure AD & Active Directory, SSO (SAML/OIDC), and SCIM provisioning. Scripting/automation proficiency: PowerShell Hands-on with SIEM (e.g., Sentinel, Splunk, Chronicle) for log forwarding, correlation, and alerting. Solid understanding of least privilege, JIT/JEA, secrets management, and credential hygiene with Familiarity on data protection principles.

Preferred Skills

Prior ownership of Evidian (Authentication Manager / Enterprise SSO), Admin By Request at enterprise scale, and 1Password Business/Enterprise, including policies, SSO, domain capture, recovery, and secrets automation. 3+ years of engineering experience in Delinea /CyberArk. RBAC/ABAC design, SoD rulesets, entitlement modeling, and access recertifications. Knowledge of modern identity patterns (FIDO2/WebAuthn, conditional access, device trust). Certifications (nice to have): CISSP, CCSP, Azure Security Engineer (AZ500), GIAC (e.g., GCLD/GSEC), ITIL. Core Skills Technical: IAM/IGA, PAM/JIT, enterprise password/secrets management, SSO/SCIM, directory services, endpoint management, scripting/automation, log engineering. .