Expert IAM Analyst Identity

Barry Callebaut Group · Hyderabad

  • Experience15–16 yrs
  • SalaryNot disclosed
  • Work modeonsite
  • Levelexecutive
  • Posted16 Sept 2026

About Barry Callebaut Group

Barry Callebaut Group is hiring in Hyderabad in agriculture food. This role looks for around 15+ years of experience.

Skills

  • Microsoft Entra ID
  • Active Directory
  • CyberArk
  • Microsoft Graph API
  • PowerShell
  • Microsoft Entra Connect
  • Microsoft Defender for Identity
  • Public Key Infrastructure
  • Okta
  • Conditional Access
  • Privileged Identity Management
  • SAML 2.0
  • OAuth 2.0
  • OpenID Connect
  • WS-Federation
  • Multi-Factor Authentication
  • FIDO2
  • Windows Hello for Business
  • Passkeys
  • REST APIs
  • Azure Identity
  • Identity and Access Management
  • Zero Trust
  • Identity Governance
  • Azure Administrator Associate
  • Identity and Access Administrator Associate

The role

A security architect at a food manufacturing company designs and secures enterprise identity platforms through Microsoft Entra ID, Active Directory, and CyberArk, while engineering Zero Trust access, federation, and identity automation. The role also applies Microsoft Graph API and PowerShell to modernize resilient global IAM services.

Full job description

Section 1 - JOB DESCRIPTION

Barry Callebaut Digital (BC Digital) is on a mission to lead the digital revolution in the chocolate industry, and we're looking for an Expert Engineer to join our Identity & Access Management team. Identity and Access Management (IAM) is a key element of the Information Security Strategy and Framework and plays a vital role in our digital ecosystem.

As an Expert Engineer, you will be the senior hands-on Identity specialist responsible for the architecture, security, stability, modernization and continuous improvement of our enterprise Identity platforms, including Microsoft Entra ID, Active Directory, Hybrid Identity, Microsoft Defender for Identity (MDI), CyberArk, Public Key Infrastructure (PKI), and Okta.

You will serve as the highest technical escalation point for Identity & Access Management, leading complex troubleshooting, root cause analysis, platform engineering, security hardening, automation initiatives and operational excellence. You will work closely with IT Security, Enterprise Architecture, Cloud, Infrastructure and Application teams across a global footprint to deliver secure, scalable and resilient identity services that support Barry Callebaut’s Zero Trust strategy. If you are a seasoned Identity professional with deep Microsoft Identity expertise and extensive enterprise IAM experience, we invite you to join our team.

The Candidate Will

MAIN RESPONSIBILITIES & SCOPE

Own the end-to-end enterprise Identity & Access Management platforms, including Microsoft Entra ID, Active Directory, Microsoft Entra Connect (Cloud Sync & Connect Sync), Microsoft Defender for Identity (MDI), CyberArk, PKI and Okta. Act as the technical design authority for enterprise Identity & Access Management solutions, ensuring security, scalability, automation, resilience and operational excellence. Design, implement and maintain Microsoft Entra ID security capabilities, including: Conditional Access Privileged Identity Management (PIM) Access Packages Lifecycle Workflows Dynamic Groups Authentication Methods Passwordless Authentication (FIDO2, Windows Hello for Business, Passkeys) Multi-Factor Authentication (MFA) Design, implement and maintain hybrid identity solutions integrating Active Directory with Microsoft Entra ID. Design and manage Enterprise Applications, App Registrations, Managed Identities and Service Principals within Microsoft Entra ID. Lead authentication and federation integrations using SAML 2.0, OAuth 2.0, OpenID Connect (OIDC), WS-Federation and modern authentication protocols. Design, implement and maintain secure identity lifecycle management processes, including provisioning, deprovisioning, access governance and identity automation. Manage privileged access solutions using CyberArk following Zero Trust and Least Privilege principles. Support Microsoft Defender for Identity (MDI) by investigating identity threats, strengthening detections and improving the organization’s identity security posture. Support and improve the enterprise PKI environment, including certificate lifecycle management, certificate-based authentication and cryptographic best practices. Develop automation using Microsoft Graph API, PowerShell, REST APIs and scripting to improve operational efficiency. Drive platform modernization initiatives by evaluating and implementing new Microsoft Identity capabilities and industry best practices. Define and maintain IAM standards, technical documentation, operational procedures and engineering guidelines. Act as the L3/L4 technical escalation point, perform root cause analysis and implement preventive improvements. Mentor junior engineers and provide technical leadership across the global IAM organization. Assist in developing and executing the vision for identity management, aligning with the overall I&AM strategy Act as design authority for IAM platforms, directory services, and authentication solutions. Architect, design, review, and implement complex IAM and directory service solutions across on-prem, and cloud environments. Lead identity lifecycle, federation, and authentication initiatives. Work closely with IT Security, Enterprise Architecture, and other teams Rapidly address security incidents and troubleshoot complex issues related to identity management Contribute to IAM standards, procedures, and long-term platform improvements.

Scope

Global role supporting users, applications, and platforms across multiple regions. Key stakeholders are located in Belgium, Switzerland, India, Poland and other locations of our global footprint Primary focus on Microsoft Entra ID, Active Directory; with added responsibility for CyberArk, PKI, Microsoft Defender for Idenitty and Okta.

Education, Language, Skills & Qualifications

Bachelor’s or Master’s degree in Information Technology, Computer Science, Information Security, Cyber Security or related field. Microsoft Certified: Azure Administrator Associate (AZ-104) is mandatory. Microsoft Certified: Identity and Access Administrator Associate (SC-300) is mandatory. Additional Microsoft certifications such as AZ-305, SC-100, AZ-500 or SC-100 are highly preferred. CyberArk Defender/Administrator certification is considered an advantage. Okta Professional or Administrator certification is considered an advantage. Industry-recognized certification in security (e.g., CAMS, CIAM, SC-300/900) or equivalent a highly appreciated Proven track record of successfully delivery complex IAM projects in large environments In-depth knowledge of industry best practices and emerging trends Proficient in English

Additional Considerations Or Comments

Position in a global team with global responsibility Opportunity to work in a very dynamic and diverse environment Possibility to be in touch with the newest security technology advances and bring it on a large corporate environment

Section 2 - CANDIDATE PROFILE

Essential Experience & Knowledge / Technical Or Functional Competencies

15+ years of experience in Identity & Access Management in enterprise environments, with strong Microsoft Entra ID experience. Proven experience administering enterprise Microsoft Entra ID environments supporting more than 20000 identities. Expert knowledge of Microsoft Entra ID. Expert knowledge of Azure Identity and identity-related Azure services. Expert knowledge of Active Directory, Hybrid Identity, Microsoft Entra Connect Sync and Cloud Sync. Expert-level experience designing, implementing and troubleshooting Conditional Access policies aligned with Microsoft’s Zero Trust architecture. Expert knowledge of Privileged Identity Management (PIM). Strong experience with Enterprise Applications, App Registrations, Access Packages, Managed Identities and Service Principals. Deep hands-on experience with SSO: SAML, OAuth, authentication policies, sign-on policies and app troubleshooting. Strong expertise in MFA and secure access: configuration, enrollment issues and policy tuning. Experience with passwordless authentication technologies including Windows Hello for Business, FIDO2 Security Keys and Passkeys. Strong experience administering Microsoft Defender for Identity (MDI). Strong experience with Microsoft Graph API, PowerShell automation, REST APIs and scripting. Strong experience with CyberArk Privileged Access Management. Strong knowledge of enterprise PKI, certificate lifecycle management and certificate-based authentication. Working knowledge of Okta administration, federation and identity integrations. Strong understanding of Microsoft’s Zero Trust Identity architecture and Identity security best practices. In-depth knowledge of IAM principles, authentication, authorization, and identity governance. Strong knowledge of Microsoft Entra ID, Microsoft Active Directory and CyberArk. Excellent communication and collaboration skills Strong problem-solving skills in complex IAM scenarios Results-oriented and adaptable

LEADERSHIP COMPETENCIES & PERSONAL STYLE

The ideal candidate…

Exhibits a passion for digital technology and innovation, constantly seeking new and creative solutions to enhance processes, decision-making and user experiencesCollaborates well across diverse and globally distributed teams, with the ability to build and maintain positive relationships across different levels and functions of the organizationIs hands-on, pragmatic, and accountable for outcomes (availability, reliability, security posture)Coaches others through structured knowledge sharing and real-case mentoringIs proactive in continuous improvement: reduces repeat incidents, improves SOPs, and automates recurring tasks.Communicates clearly in incidents and change execution, documents decisions and procedures consistently , with strong documentation and presentation skills .Strategic thinker with the ability to translate vision into actionable plansCollaborative and adaptable leadership styleResults-oriented and proactive in risk management

At Barry Callebaut, we are committed to Diversity & Inclusion. United by our strong values, we thrive on the diversity of who we are, where we come from, what we’ve experienced and how we think. We are committed to nurturing an inclusive environment where people can truly be themselves, grow to their full potential and feel they belong. #oneBC - Diverse People, Sustainable Growth.