Identity Engineer
Milliman
Skill Required
Key highlights
- Remote India-based role, preferably aligned to New Delhi/NCR
- 3+ years of experience required
- Hands-on experience with Okta, Microsoft Entra ID, Active Directory, or Auth0 required
- Bachelor’s degree or equivalent professional experience required
Role overview
The Identity Engineer supports Milliman’s global Identity & Access Management (IAM) service by engineering, operating, and improving standardized identity capabilities for a decentralized global firm. The role involves hands-on engineering, operational support, automation, and stakeholder guidance across platforms like Okta, Microsoft Entra ID, Active Directory, and Auth0. The engineer collaborates with teams across Infrastructure, Operations, Cloud Services, and Information Security to reduce risk, improve reliability, and mature Milliman’s global identity operating model. This is a remote India-based role, preferably aligned to the New Delhi/NCR area, with occasional in-office participation and flexibility for global collaboration.
Responsibilities
- Engineer and operate Milliman’s centralized workforce identity services, including Okta Workforce Identity, Microsoft Entra ID, Active Directory, MFA, SSO, lifecycle management, and identity integrations.
- Support Milliman’s decentralized IT model by enabling delegated administration for Practice IT teams while maintaining consistent identity standards, guardrails, auditability, and least-privilege access.
- Configure, test, and support SSO and federation integrations for SaaS, internal, cloud, and practice-managed applications using SAML, OIDC/OAuth, SCIM, and related protocols.
- Maintain and improve identity lifecycle processes for onboarding, offboarding, leave, name changes, group and role assignment, license assignment, and account reconciliation across HR, Okta, AD, and Entra ID.
- Administer and improve Entra ID capabilities including enterprise applications, app registrations, service principals, managed identities, Conditional Access, privileged roles, and hybrid identity synchronization.
- Establish and maintain standards, implementation patterns, runbooks, and support documentation for IAM services used across Milliman practices.
- Enable Practice IT and product teams to manage approved resources through delegated administration models for Okta, Entra ID, Active Directory, and Auth0 where appropriate.
- Support service catalog requests, ticket categorization, operational metrics, and knowledge articles that improve intake, routing, reporting, and transparency for identity work.
- Provide consultative guidance to internal IT teams on identity integration patterns, access control expectations, MFA requirements, account types, and operational readiness.
- Implement identity controls aligned to Milliman standards, including unique user identity, MFA, centralized authentication, least privilege, secure service account patterns, and audit readiness.
- Support privileged access improvements, including role governance, emergency access procedures, privileged account lifecycle controls, and future just-in-time access capabilities.
- Monitor, troubleshoot, and remediate identity-related issues such as provisioning failures, sync errors, authentication problems, stale access, misconfigured applications, and account access incidents.
- Enforce least-privilege access principles, just-in-time (JIT) provisioning, and privileged session monitoring across critical enterprise systems.
- Contribute to incident reviews, root-cause analysis, operational resilience improvements, and continuity procedures for identity-dependent services.
- Partner with Information Security and audit stakeholders to provide evidence, improve access review practices, and support compliance obligations.
- Automate repetitive identity tasks using PowerShell, APIs, workflows, and infrastructure-as-code approaches where practical.
- Advance current and anticipated IAM initiatives such as Okta-to-Entra federation, Okta provisioning automation, group and role automation, passwordless authentication, client identity governance, Auth0 enterprise administration, and identity threat visibility.
- Evaluate new identity features and vendor capabilities, document recommendations, and help translate roadmap goals into practical implementation plans.
- Champion Zero Trust identity principles including continuous verification, device trust posture assessment, and risk-based Conditional Access policy design.
Requirements
- Bachelor’s degree in Computer Science, Information Systems, or related field; B.Tech/B.E., MCA, M.Sc., or equivalent professional experience also considered.
- 3+ years of experience in identity, infrastructure, cloud, or systems engineering roles.
- Hands-on experience administering at least two core identity platforms such as Okta, Microsoft Entra ID, Active Directory, Auth0, or equivalent technologies.
- Okta Workforce Identity administration, application integration, MFA, lifecycle management, workflows, and group-based assignment.
- Microsoft Entra ID administration, Conditional Access, enterprise applications, app registrations, PIM concepts, B2B, service principals, and hybrid identity.
- Active Directory administration in multi-domain or delegated environments, including groups, OUs, GPOs, DNS dependencies, and synchronization.
- Auth0 or other client identity platforms, including tenant administration, organizations, enterprise connections, and delegated access models.
- Identity protocols and standards including SAML, OIDC/OAuth, SCIM, LDAP, Kerberos, and modern authentication patterns.
- Automation using PowerShell, REST APIs, Microsoft Graph, Okta APIs, workflow automation, or similar tooling.
- Operational support practices including ticket handling, change enablement, runbooks, incident response, and stakeholder communications.
- Clear written and verbal communication for global stakeholders, including documented handoffs, runbooks, status updates, and practical follow-through across time zones.
- Strong troubleshooting skills across identity, authentication, directory, network, endpoint, and application integration layers.
- Ability to communicate clearly with technical and non-technical stakeholders, including Practice IT administrators, project teams, security teams, and service owners.
- Ability to work effectively from India with global teams through asynchronous communication, documented procedures, operational handoffs, and reliable follow-through.
- Demonstrated ownership, sound judgment, documentation discipline, and ability to improve operational processes over time.
Nice to have
- Experience in a global professional services, financial services, consulting, or similarly decentralized IT environment.
- Experience supporting shared services, delegated administration, or federated operating models across multiple business units or practices.
- Experience working with colleagues, stakeholders, or customers across India, the U.S., and other global regions.
- Exposure to identity governance, access reviews, privileged access management, passwordless authentication, identity threat detection, or Zero Trust initiatives.
- Experience with ITSM platforms, service catalog design, ticket taxonomy, operational reporting, and continuous improvement.
- Okta Certified Professional or Okta Certified Administrator.
- Microsoft Certified: Identity and Access Administrator Associate (SC-300).
- Microsoft Certified: Azure Administrator Associate (AZ-104).
- Relevant vendor certifications for PAM, IGA, cloud, or automation platforms.
Additional details
- This role reports to the Manager of Infrastructure and Cloud Services.
- The position requires collaboration with distributed teams across time zones, clear written handoffs, and some schedule flexibility for global meetings, planned changes, operational escalations, and occasional identity-related incidents.
- While the role is primarily remote, occasional in-office participation may be expected for business needs such as U.S. leadership visits, local IT team gatherings, planning sessions, team workshops, or similar collaboration events.