- Experience
- Any
- Salary
- —
- Openings
- 1
- Posted
- 19 മണിക്കൂർ മുൻപ്
- Work mode
- Work from home
- Resume
- Required to apply
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
About Redcare Pharmacy
Redcare Pharmacy is Europe's leading e-pharmacy, driven by dedicated teams and innovative technology. We foster a collaborative and supportive environment where every employee is respected and motivated to contribute to our vision: “Until every human has their health.” Join us for a career with purpose and aligned values.
Role Overview
We are seeking a Senior Cloud Identity Engineer to help pioneer identity engineering within our Microsoft Cloud infrastructure. The role focuses on creating secure, scalable, and automated identity solutions that enable decentralized teams to innovate freely while adhering to governance frameworks based on Zero Trust and Least Privilege principles.
You will be an integral part of our Cloud & Security team, influencing identity strategies across Azure, Data, ERP, and AI platforms. This involves shaping identity blueprints, managing agent identities, and enforcing enterprise-wide governance to lay the foundation of a secure, scalable, AI-ready cloud environment.
Technical Environment
The core environment includes Microsoft Entra, Microsoft Graph API, Entra ID Governance with Access Reviews, Azure, Azure RBAC, Entra RBAC, Azure Policy, Azure Key Vault, Managed Identities, Enterprise Applications, App Registrations, Service Principals, Certificate Lifecycle Management, Administrative Units, Conditional Access, Identity Protection, Workload Identity Federation, Microsoft Sentinel, Azure Monitor, Log Analytics with KQL, Microsoft 365, Active Directory core services, OAuth 2.0, and OpenID Connect.
The role emphasizes designing secure identity architectures with a focus on Least Privilege, Azure Policy, guardrails, governance, detecting permission misuse, and identity monitoring.
Automation is essential, utilizing PowerShell, Bash, Microsoft Graph API, Azure Functions, and Logic Apps to deliver secure, scalable identity governance aligned with Zero Trust and Least Privilege models across Azure and Microsoft Entra platforms.
Experience with AI-assisted programming tools (GitHub Copilot, Claude Code, Codex) and advanced Microsoft technologies such as Entra Agent ID, Identity Blueprints, and Microsoft 365 Agents / Copilot is advantageous as we evolve towards AI-driven and autonomous workloads.
Key Responsibilities
- Architect and expand Microsoft Entra ID Governance by deploying Access Reviews, establishing governance processes in collaboration with business teams, and automating governance rollouts consistently throughout a distributed Microsoft Entra setup.
- Develop secure workload identity services by automating the lifecycle of service principals, certificates, secrets, and federated credentials with integration to Azure Key Vault, ensuring adherence to Least Privilege from inception.
- Create modern self-service solutions for managing service principals, Entra Groups, and delegated administration to empower engineering teams with independent operation while minimizing excessive permissions.
- Continuously analyze and enhance Azure RBAC, Entra RBAC, application permissions, Microsoft Graph permissions, and OAuth consent frameworks to minimize privilege excess, strengthen governance, and elevate cloud identity security.
- Construct systems for identity monitoring and anomaly detection to proactively catch expiring credentials, permission misuse, and violations of governance using Microsoft Sentinel, Azure Monitor, Log Analytics, and Kusto Query Language.
- Assist in automating user lifecycle processes, such as joiner, mover, and leaver events, with HRIS as the authoritative identity source.
Candidate Profile
- Proven hands-on experience designing and automating cloud identity architectures using Microsoft Entra, Administrative Units, Entra ID Governance, Microsoft Graph Permissions, Azure cloud, Microsoft 365, and Power Platform within complex cloud environments.
- Passionate about building secure, scalable platforms that adhere to Zero Trust and Least Privilege frameworks while maintaining a balanced developer experience and enterprise-grade security.
- Advocate for reducing unnecessary permissions, promoting modern identity governance, detecting permission misuse, and pursuing continuous enhancement of cloud identity setups.
- Enthusiastic about emerging identity technologies, open to experimentation, committed to knowledge sharing, and able to clearly communicate technical concepts to diverse teams and stakeholders.
- Collaborates across teams to refine design, governance, security, and automation strategies for cloud identity.
Additional Information
We provide extensive support tailored to your needs, whether related to health, family time, or professional growth, including location-specific benefits:
- Comprehensive onboarding with welcome days to assist your smooth integration from day one.
- Remote work with occasional mandatory onsite presence at Berlin or Cologne offices as business needs dictate. A home office setup allowance of 500.00 € is provided for remote employees to create an optimal workspace.
- Anchor days with fully reimbursed travel and accommodation costs for required office visits.
- Dedicated personal development support through internal and external training programs.
- Employee referral incentives to reward successful candidate recommendations.
Level
Senior