NexTbil Tech
NexTbil Tech
201 – 500 Employees
ConsultingLogisticsMarketing
NexTbil Tech is an international technology company building high-performing iGaming platforms and digital products. Its engineering work spans scalable software and services across DevOps, data analytics, artificial intelligence, and blockchain development using Solidity and EVM technologies. The company works through agile methods and cross-functional teams, with a focus on developing technical talent and creating opportunities for engineers and product professionals in a remote, globally oriented hiring environment.

IAM Architect – Azure & Microsoft Entra ID (Hybrid)

Design and govern identity security architecture for Azure, Microsoft Entra ID, Microsoft 365, and hybrid environments. Lead Zero Trust, least-privilege, privileged access, and resilient authentication initiatives.

Description

  • Design and evolve enterprise IAM security architecture across Microsoft Azure, Microsoft Entra ID, Microsoft 365 integrations, and hybrid identity environments
  • Architect and oversee Entra ID capabilities, including Conditional Access, MFA, Identity Protection, Privileged Identity Management, Access Reviews, Entitlement Management, and lifecycle workflows
  • Establish Zero Trust and least-privilege access models for users, administrators, service principals, managed identities, applications, groups, and Azure resources
  • Lead authentication and authorization architecture using SAML, OAuth 2.0, OpenID Connect, SCIM, federation, SSO, and application integration patterns
  • Govern Azure application registrations, enterprise applications, API permissions, consent controls, secrets, certificates, service principals, and workload identities
  • Design privileged access safeguards, just-in-time elevation, approval processes, break-glass account controls, privileged access reviews, and administrative role protections
  • Create identity security standards, reference architectures, design patterns, roadmaps, and controls aligned with organizational policy, regulations, and audit requirements
  • Collaborate with security engineering, cloud platform, infrastructure, application, GRC, SOC, and business stakeholders
  • Support identity risk assessments, control validation, incident response, and remediation for compromised accounts, excessive privileges, risky sign-ins, application misconfigurations, and governance gaps

Requirements

  • Bachelor’s degree in cybersecurity, information technology, computer science, engineering, or a related field; equivalent professional experience may be accepted
  • At least five years of experience in cybersecurity, IAM, cloud security, security architecture, or infrastructure security
  • Substantial practical experience with Microsoft identity platforms
  • Advanced knowledge of Microsoft Entra ID, Azure RBAC, Conditional Access, MFA, Identity Protection, Privileged Identity Management, Access Reviews, Entitlement Management, and identity lifecycle governance
  • Strong understanding of Active Directory, hybrid identity, Entra Connect or Cloud Sync, federation, directory synchronization, Microsoft 365 identity dependencies, and enterprise authentication
  • Experience designing SSO and application integrations with SAML, OAuth 2.0, OpenID Connect, SCIM, APIs, service principals, managed identities, and governed application registrations
  • Ability to convert business, regulatory, and security needs into identity architectures, control standards, implementation roadmaps, and operational guardrails
  • Strong written and verbal communication skills
  • Experience with audits, compliance activities, control testing, access certification, identity risk remediation, and evidence preparation in regulated or compliance-focused environments
  • Microsoft certifications are preferred, including Cybersecurity Architect Expert, Azure Solutions Architect Expert, Azure Security Engineer Associate, Identity and Access Administrator Associate, or Microsoft 365 Enterprise Administrator Expert
  • Security certifications such as CISSP, CISM, CCSP, or equivalent credentials are preferred
  • Experience with Microsoft Sentinel, Microsoft Defender for Cloud, Defender for Identity, Defender for Cloud Apps, Azure Key Vault, and identity monitoring or detection use cases
  • Experience automating IAM and Azure security controls with PowerShell, Microsoft Graph API, Azure CLI, Terraform, Bicep, ARM templates, or CI/CD pipelines
  • Knowledge of Zero Trust architecture, the NIST Cybersecurity Framework, ISO 27001, CIS benchmarks, least privilege, separation of duties, and privileged access governance
  • Exposure to AWS IAM or Google Cloud IAM is beneficial

Benefits

  • Competitive salary package with performance-based bonuses
  • Flexible work arrangements, including remote and hybrid options
  • Comprehensive health insurance coverage
  • Wellness programs and resources supporting physical and mental well-being
  • Professional training programs
  • Mentorship opportunities
  • Defined career development pathways
  • Diverse, inclusive, collaborative, and growth-oriented work environment
  • Regular team-building activities and social events

Related Jobs

SPERTON - Where Great People Meet

Sales Executive, Elevators and Car Parking Systems

SPERTON - Where Great People Meet
51 – 200 Employees

Drive elevator and car parking system sales across Mumbai’s Western Region. Build client and dealer relationships, and manage deals from initial enquiry through project execution.

Open