410,083open jobs
14,230companies
73,879added this week
Browse all
Salary
$31k – $76k per year (Estimated)
Location
In office (Bengaluru)
Seniority
Principal · 12+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match
NXP Semiconductors is a Dutch chipmaker established in 2006 when Philips spun out its semiconductor division, and it concentrates on embedded processing rather than general purpose computing. Its largest market is automotive, where it supplies radar sensors, vehicle networking, battery management and the secure processors behind keyless entry and digital car keys, alongside industrial and internet of things microcontrollers, mobile secure elements and communications infrastructure silicon. Headquartered in Eindhoven and listed on Nasdaq, it is one of the leading suppliers of near field communication and automotive processing chips in the world.

Role Overview

We are seeking a Principal Engineer - Identity & Access Management (IAM) to serve as the technical authority and architectural owner for enterprise and customer-facing authentication, authorization, and directory services. This role underpins the availability, security, and continuity of global digital platforms and business-critical environments.

This is a deeply technical, hands-on principal role requiring architectural-level expertise across Active Directory, Entra ID (Azure AD & B2C), Oracle Unified Directory (OUD), and Linux/Unix authentication systems, operating within a complex hybrid identity ecosystem.

The role is mission critical: failures in identity architecture directly translate into widespread access disruption, security exposure, productivity loss, and compliance risk. This engineer will eliminate single points of failure, strengthen directory security posture, support M&A integrations, and ensure identity services scale securely and reliably across all regions.

Key Responsibilities

IAM & Directory Services Architecture Ownership

  • Act as the principal technical owner for global IAM and directory services platforms supporting enterprise, partner, and customer-facing applications
  • Define, document, and evolve end-to-end IAM architecture, including:
    • Active Directory (enterprise-scale, hybrid, multi-region)
    • Entra ID / Azure AD (including B2C and external identities)
    • Oracle Unified Directory (OUD)
    • Linux and Unix authentication and authorization integrations
  • Establish reference architectures, engineering standards, and operational patterns for identity platforms
  • Design for high availability, fault tolerance, disaster recovery, and regional resilience

Authentication & Authorization Reliability

  • Ensure continuous availability of authentication and authorization services by proactively managing identity dependencies
  • Own directory synchronization, federation, and authentication flows across hybrid environments
  • Eliminate architectural and operational single points of failure
  • Prevent identity issues that could result in:
    • Global user access degradation
    • Business application downtime
    • Customer- and partner-facing access disruption

Security, Zero Trust & Risk Reduction

  • Make identity the primary control plane for Zero Trust initiatives
  • Enforce least privilege, strong authentication, and continuous verification
  • Design and implement RBAC, ABAC, and policy-based authorization models
  • Strengthen directory security posture by addressing:
    • Privileged access exposure
    • Legacy protocols and weak authentication mechanisms
    • Inconsistent policy enforcement and configuration drift
  • Reduce identity-based attack paths and systemic access risk

Non-Human, AI & Machine Identity Protection

  • Architect and secure non-human identities, including:
    • AI agent identities
    • Robotic Process Automation (RPA) identities
    • Service accounts, workloads, APIs, and system identities
  • Define lifecycle management, authentication, authorization, and rotation strategies for machine identities
  • Prevent credential sprawl, over-privileged access, and unmanaged secrets
  • Ensure AI and robotic identities adhere to Zero Trust, least privilege, and auditable access principles
  • Integrate non-human identity controls into enterprise IAM governance and monitoring

Integration & User Experience

  • Improve identity integration across:
    • Enterprise applications
    • Partner platforms
    • Customer-facing (B2C) ecosystems
  • Ensure seamless, low-friction authentication experiences without compromising security
  • Enable scalable access models for human and non-human identities

Mergers & Acquisitions (M&A) Support

  • Serve as the IAM technical lead for M&A initiatives
  • Assess acquired company identity architectures, directory services, and authentication models
  • Design and execute secure identity integration, consolidation, or coexistence strategies
  • Mitigate access risk during transitions while maintaining business continuity
  • Ensure acquired environments align with enterprise IAM, Zero Trust, and security standards

Continuity, Innovation & Long-Term Strategy

  • Ensure knowledge continuity and eliminate dependency on individual resources
  • Define a multi-year IAM and directory services roadmap aligned with enterprise architecture and Zero Trust maturity
  • Evaluate emerging identity technologies, protocols, and access models, including AI-driven identity use cases
  • Mentor engineers and elevate IAM engineering maturity across the organization

Required Qualifications

Experience

  • 12+ years of experience in Identity & Access Management, directory services, or security platform engineering
  • Proven experience supporting global, highly available, business-critical identity systems

Technical Expertise

  • Architectural-level expertise in:
    • Active Directory (enterprise and hybrid environments)
    • Entra ID / Azure AD, including B2C
    • Oracle Unified Directory (OUD)
    • Linux and Unix authentication mechanisms
  • Strong understanding of:
    • Authentication and authorization flows
    • Identity federation and synchronization
    • RBAC, ABAC, and policy-driven access models
    • Zero Trust and identity-centric security architecture
  • Hands-on experience with identity protocols:
    • SAML 2.0, OAuth 2.0, OpenID Connect (OIDC), Kerberos, LDAP/LDAPS, SCIM, RADIUS, SSH key-based authentication, PAM (Pluggable Authentication Modules) for Linux, certificate-based authentication (X.509), and modern API-based identity integrations, etc.
  • Experience with automation and integration:
    • PowerShell, Python, APIs, infrastructure-as-code preferred

Architectural & Leadership Skills

  • Ability to design for availability, resilience, and failure scenarios
  • Strong systems thinking and long-term technical judgment
  • Proven ability to influence architecture and strategy across teams without formal authority
  • Comfortable operating in ambiguous, high-impact environments

Preferred Qualifications

  • Experience supporting customer-facing digital platforms at global scale
  • Cloud IAM experience across Azure, AWS, and/or GCP
  • Familiarity with identity governance, privileged access, and compliance frameworks
  • Experience working with globally distributed teams, including India-based engineering support models
  • Prior experience supporting identity integration during M&A activities

Why This Role Is Critical

Identity is a Tier-0 dependency. Without a resilient, well-architected IAM foundation, failures in authentication, authorization, or machine identity control quickly become enterprise-wide risk events.

This role directly protects the organization from:

  • Identity-driven downtime and degraded user access
  • Over-privileged or unmanaged AI, robotic, and service identities
  • Increased risk during mergers, acquisitions, and integrations
  • Delays or failures in Zero Trust adoption
  • Compliance exposure and erosion of trust

This Principal Engineer ensures continuity, resilience, and long-term sustainabiliy of identity services-across humans, machines, and AI-that the business depends on every day.

More information about NXP in India...

#LI-7013
Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
410,083 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Bengaluru
$62k – $144k per year (Estimated) • Remote • Contractor • 4+ years exp • Toronto
Kotlin
Node JS
SQL
Swift
TypeScript
JavaScript
PHP
Node JS
Nest.JS
PHP
Laravel
Databases
DynamoDB
MySQL
PostgreSQL
Redis
Frontend
Bootstrap
Redux
Sass
Vue.js
React.js
Mobile
React Native
State Management
DevOps
Azure
CI/CD
Git
GitHub
Rest API
Apply
$99k – $132k per year • In office • Full-Time • Heilbronn
SQL
DevOps
Azure
Grafana
Kubernetes
Prometheus
Apply
$114k – $215k per year (Estimated) • In office • Full-Time
DevOps
AWS
Azure
GCP
Apply
In office • Full-Time • 10+ years exp • Bachelor's Degree • Riyadh
DevOps
AIOps
AWS
Azure
Datadog
Dynatrace
GCP
GitHub
Kubernetes
OpenShift
Platform Engineering
VMWare
Management
ServiceNow
Apply
In office • Full-Time • 10+ years exp • Bachelor's Degree • Riyadh
Apex
Apex
Salesforce Data Cloud
Databases
Databricks
Microsoft Fabric
Snowflake
DevOps
AWS
Azure
GCP
Marketing
Salesforce
Apply
In office • Internship • Master's Degree • Shanghai
C++
Python
DevOps
CI/CD
Git
Management
SharePoint
Apply
In office • Full-Time • 2+ years exp • Bachelor's Degree • Kaohsiung
Apply
Senior IGA Engineer 3 days ago
In office • Full-Time • 5+ years exp • Bengaluru • Hyderabad • Noida
PowerShell
Python
DevOps
IAM
Incident Management
Cybersecurity
SOC 2
Apply
$31k – $82k per year (Estimated) • In office • Full-Time • 10+ years exp • Bengaluru
AI/ML
AI Agents
DevOps
AWS
Azure
GCP
IAM
Platform Engineering
Cybersecurity
Defense in Depth
Least Privilege
Zero Trust
Apply
In office • Part-Time • Bachelor's Degree • Gratkorn
Apply
In office • Full-Time • 1+ year exp • Bachelor's Degree • Bengaluru
JavaScript
Python
Apply
Student Ops Intern 10 hours ago
In office • Internship • Bengaluru
Management
Google Sheets
Apply
In office • Internship • Bachelor's Degree • Bengaluru
AI/ML
ChatGPT
Apply
Sr. Identity Engineer 11 hours ago
In office • Bengaluru
DevOps
Azure
IAM
Cybersecurity
Least Privilege
Microsoft Entra ID
Okta
Apply
Staff Engineer 11 hours ago
$40k – $86k per year (Estimated) • In office • Bengaluru
C#
JavaScript
SQL
TypeScript
C#
ASP.NET Core
Databases
MySQL
PostgreSQL
AI/ML
ChatGPT
Claude
Copilot
Frontend
Angular
React.js
DevOps
Amazon CloudWatch
Amazon EC2
Amazon ECS
Amazon EKS
Amazon S3
AWS
AWS Lambda
Azure
CI/CD
CloudFormation
Datadog
Docker
GCP
Git
GitHub
GitLab
GitLab CI
Kubernetes
Octopus Deploy
Service Mesh
Shift-Left
Splunk
TeamCity
Terraform
Cybersecurity
Shift-Left Security
Apply
See all jobs
This is one of many
410,083 more open roles from verified company boards, updated every day.