Cloud & Hybrid Infrastructure Engineer
Alkem Laboratories Ltd. · Navi Mumbai
- Experience6–8 yrs
- SalaryNot disclosed
- Work modeonsite
- Posted24 Sept 2026
About Alkem Laboratories Ltd.
Alkem Laboratories Ltd. is hiring in Navi Mumbai in pharma biotech. This role looks for around 6+ years of experience.
Skills
- Azure Cloud Services
- AWS Cloud Services
- Microsoft Active Directory
- Microsoft Entra ID
- Hybrid Active Directory
- Entra Connect
- Cloud Sync
- Group Policy Administration
- Conditional Access
- Multi-Factor Authentication
- Single Sign-On
- Passwordless Authentication
- Privileged Identity Management
- Identity Governance & Access Management
- Windows Server Administration
- Linux Server Administration
- Virtualization Platforms
- Storage Management
- Backup and Disaster Recovery Solutions
- Infrastructure as Code
- Scripting and Automation
- FinOps
- Cloud Cost Optimization
- Observability and Monitoring Tools
- LDAP
- Kerberos
- SAML
- OAuth
- OpenID Connect
- SCIM
- ITIL Service Management Practices
The role
An infrastructure engineer at a pharmaceutical company designs and operates Azure Cloud Services, AWS Cloud Services, and Microsoft Entra ID across hybrid enterprise environments, securing identity, resilience, and cost governance. The role also applies Infrastructure as Code and disaster recovery solutions to maintain reliable corporate, manufacturing, research, and data-centre services.
Full job description
About Alkem:
Alkem Laboratories Limited is an Indian multinational pharmaceutical company headquartered in Mumbai, that manufactures and sells pharmaceutical generics, formulations and nutraceuticals in India and globally over 50 countries. We have consistently been ranked amongst the top five pharmaceutical companies in India. Our portfolio includes illustrious brands like Clavam, Pan, Pan-D, and Taxim-O, which feature amongst the top 50 pharmaceutical brands in India.
Purpose of the Role:
To own the architecture, engineering, operations, security, availability, identity services, automation, resilience, and cost governance of Alkem’s hybrid infrastructure landscape, including Azure, AWS, Microsoft Active Directory, Microsoft Entra ID, virtualization platforms, data centres, storage, backup, and disaster recovery environments.The role is responsible for delivering secure, scalable, resilient, and cost-effective infrastructure and identity services across Alkem’s corporate offices, manufacturing locations, R&D centres, data centres, and international operations.
Key Responsibilities:
Hybrid Cloud Architecture & EngineeringDesign, implement, and maintain reference architectures, standards, patterns, and governance frameworks for Azure, AWS, private cloud, and on-premise infrastructure environments.Evaluate workload placement strategies based on business requirements, performance, security, compliance, recoverability, integration, data residency, and total cost of ownership.Conduct architecture reviews for new applications, cloud migrations, infrastructure upgrades, and modernization initiatives.Maintain architecture documentation, infrastructure standards, build specifications, configuration baselines, technical diagrams, and operational runbooks.Cloud Platform Operations & GovernanceManage cloud subscriptions, accounts, landing zones, management groups, resource hierarchies, tagging structures, policies, quotas, and shared services.Implement and govern controls for identity integration, privileged access, key and secret management, cloud connectivity, monitoring, logging, vulnerability remediation, backup, and patch management.Monitor cloud service health, capacity, availability, utilization, and performance metrics.Drive cloud governance, operational excellence, and FinOps initiatives to optimize infrastructure costs.Identity & Access Infrastructure ManagementAdminister and support Microsoft Active Directory, Hybrid Active Directory, Microsoft Entra ID, and enterprise identity management platforms.Manage domain controllers, Active Directory forests, trusts, replication, DNS integration, Sites and Services, and Group Policy administration.Maintain hybrid identity services including Microsoft Entra Connect, Cloud Sync, federation services, and directory synchronization.Govern Single Sign-On (SSO), Multi-Factor Authentication (MFA), passwordless authentication, and Conditional Access policies.Manage identity lifecycle processes including user provisioning, deprovisioning, RBAC, service accounts, delegated administration, and privileged access controls.Support Privileged Identity Management (PIM), identity governance, access reviews, tiered administration, and privileged account protection.Ensure identity platform resilience through backup, disaster recovery, platform hardening, recovery testing, and replication monitoring.Support application integrations using LDAP, Kerberos, SAML, OAuth, OpenID Connect, SCIM, and modern authentication protocols.Integrate identity logs, audit trails, authentication events, and threat intelligence with enterprise SIEM and SOC platforms.Drive identity modernization and Zero Trust initiatives in collaboration with Cybersecurity, HR, application, and business stakeholders.On-Premise Infrastructure, Virtualization & StorageManage physical and virtual server infrastructure, operating systems, hypervisors, clusters, storage systems, converged infrastructure, and management platforms.Oversee provisioning, hardening, patching, performance tuning, capacity management, lifecycle refresh, decommissioning, and compliance management.Support business-critical infrastructure for SAP, manufacturing systems, databases, middleware, analytics platforms, and enterprise applications.Automation, Observability & ResilienceDrive automation initiatives using scripting, Infrastructure as Code (IaC), configuration management tools, orchestration platforms, and reusable templates.Implement automated governance, compliance checks, and operational workflows.Establish centralized monitoring, observability, log management, dashboarding, event correlation, alerting, and service health reporting.Own enterprise backup, replication, recovery infrastructure, immutable repositories, cyber recovery, and disaster recovery readiness.Conduct restoration testing, disaster recovery drills, and business continuity exercises aligned with defined recovery objectives.Security & Service ManagementImplement secure infrastructure baselines, encryption standards, privileged access controls, vulnerability management, endpoint protection, and Zero Trust security practices.Ensure infrastructure and identity telemetry is integrated with enterprise monitoring and security operations platforms.Own ITSM processes including Incident, Problem, Change, Request, Configuration, Capacity, and Availability Management.Lead major incident management, root cause analysis, preventive action planning, knowledge management, and runbook development.Manage infrastructure service providers and vendors against contractual obligations, SLAs, security requirements, and performance metrics.
Educational Qualifications:
Bachelor's Degree in Engineering, Computer Science, Information Technology, Electronics & Telecommunications, or a related discipline.Relevant cloud, infrastructure, or identity certifications will be an added advantage.
Experience:
6 to 8 years of progressive experience in enterprise infrastructure management.Minimum 5 years of experience in cloud, hybrid infrastructure, or identity platform architecture and operations.Experience in managing Azure and/or AWS cloud environments, Active Directory, Hybrid AD, Microsoft Entra ID, virtualization, storage, backup, and disaster recovery platforms.Experience supporting highly available enterprise applications and geographically distributed operations.Experience in pharmaceutical, life sciences, chemical, manufacturing, or other regulated industries will be preferred.
Technical Skills:
Strong expertise in Azure Cloud Services and AWS Cloud Services, with deep knowledge of Microsoft Active Directory, Hybrid Active Directory, and Microsoft Entra ID (Azure AD). Proficient in managing Entra Connect, Cloud Sync, Group Policy Administration, Conditional Access, Multi-Factor Authentication (MFA), Single Sign-On (SSO), Passwordless Authentication, Privileged Identity Management (PIM), and Identity Governance & Access Management. Hands-on experience with Windows and Linux Server Administration, Virtualization Platforms, Storage Management, Backup and Disaster Recovery Solutions, and enterprise infrastructure operations. Strong capabilities in Infrastructure as Code (IaC), Scripting and Automation, FinOps and Cloud Cost Optimization, and Observability & Monitoring Tools. Sound understanding of identity and authentication protocols including LDAP, Kerberos, SAML, OAuth, OpenID Connect, and SCIM, along with practical knowledge of ITIL Service Management Practices for delivering reliable, secure, and scalable IT services.