368,530open jobs
9,432companies
50,439added this week
Browse all
Salary
$35k – $82k per year (Estimated)
Location
In office (Pune)
Seniority
Architect · 10+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match
Workday is a leading provider of cloud-based enterprise software specializing in human capital management, financial management, and spend management. Founded in 2005, the company offers a unified platform that integrates artificial intelligence to help organizations streamline HR processes and optimize financial planning. Global corporations, educational institutions, and government agencies widely rely on its scalable solutions to manage workforce operations and operational data in real time.

Your work days are brighter here.

We’re obsessed with making hard work pay off, for our people, our customers, and the world around us. As a Fortune 500 company and a leading AI platform for managing people, money, and agents, we’re shaping the future of work so teams can reach their potential and focus on what matters most. The minute you join, you’ll feel it. Not just in the products we build, but in how we show up for each other. Our culture is rooted in integrity, empathy, and shared enthusiasm. We’re in this together, tackling big challenges with bold ideas and genuine care. We look for curious minds and courageous collaborators who bring sun-drenched optimism and drive. Whether you're building smarter solutions, supporting customers, or creating a space where everyone belongs, you’ll do meaningful work with Workmates who’ve got your back. In return, we’ll give you the trust to take risks, the tools to grow, the skills to develop and the support of a company invested in you for the long haul. So, if you want to inspire a brighter work day for everyone, including yourself, you’ve found a match in Workday, and we hope to be a match for you too.

About the Team

The Identity and Access management team manages the identity suite including Okta, Delinea, AD, Entra ID and KeyFactor. Team manages employees, customers and partners identity in IAM system.

About the Role

We are seeking a skilled Active Directory (AD), Microsoft Entra ID (formerly Azure Active Directory), and Public Key Infrastructure (PKI) Architect to design, implement, operate, secure, and continuously improve our enterprise identity and certificate services. This role will own engineering activities across on-premises and cloud identity platforms, with a strong focus on availability, security, automation, governance, and a seamless user experience.

The ideal candidate brings deep hands-on expertise in Windows Active Directory, Entra ID, hybrid identity, authentication and authorization protocols, certificate lifecycle management, and identity-related incident resolution. They will partner with infrastructure, security, application, endpoint, and service-management teams to deliver resilient, scalable identity services.

Key Responsibilities

Active Directory and Hybrid Identity Engineering

  • Design, deploy, configure, and maintain enterprise Active Directory Domain Services, including forests, domains, sites, organizational units, trusts, DNS integration, Group Policy, replication, and domain controller lifecycle management.
  • Engineer and support hybrid identity integration between on-premises AD and Microsoft Entra ID, including Microsoft Entra Connect Sync or Cloud Sync, password hash synchronization, pass-through authentication, federation where applicable, and seamless single sign-on.
  • Develop and maintain logical AD designs, delegation models, administrative tiering, privileged access controls, naming standards, and lifecycle processes.
  • Monitor and troubleshoot AD replication, DNS, authentication, domain controller health, Group Policy processing, directory synchronization, and identity-related service degradation.
  • Plan and execute upgrades, migrations, consolidations, domain controller replacements, disaster-recovery testing, and capacity improvements with minimal business disruption.
  • Implement secure configuration baselines and hardening controls aligned to organizational standards and recognized security practices.

Microsoft Entra ID / Azure AD Engineering

  • Administer and engineer Microsoft Entra ID capabilities, including users, groups, administrative roles, enterprise applications, app registrations, service principals, managed identities, and directory settings.
  • Design and operate identity access patterns for cloud and hybrid applications using SSO, SAML, OAuth 2.0, OpenID Connect, SCIM provisioning, and modern authentication.
  • Implement and maintain Conditional Access policies, multifactor authentication, passwordless authentication, authentication methods, self-service password reset, Identity Protection, and risk-based access controls.
  • Support privileged identity management processes, role activation, access reviews, entitlement management, and least-privilege access models.
  • Partner with application owners to onboard applications to Entra ID, resolve authentication and provisioning issues, and improve the security posture of enterprise applications.
  • Manage directory synchronization and identity lifecycle workflows, including joiner, mover, leaver, group management, and access-provisioning integrations.
  • Evaluate and implement relevant Microsoft Entra capabilities to enhance identity security, governance, and operational efficiency.

PKI and Certificate Services Engineering

  • Design, deploy, administer, and support enterprise PKI services, including Microsoft Active Directory Certificate Services (AD CS), certification authorities, certificate templates, enrollment policies, CRL and AIA distribution points, OCSP, and key archival/recovery where required.
  • Manage the complete certificate lifecycle for internal and public certificates: request, issuance, renewal, revocation, discovery, inventory, monitoring, and retirement.
  • Engineer certificate-based authentication and encryption solutions for users, devices, servers, applications, network infrastructure, and services.
  • Configure and support auto-enrollment, certificate template permissions, certificate policies, enrollment agents, and secure key-management practices.
  • Maintain root and subordinate CA hierarchy, offline root CA procedures, CA backup and recovery processes, HSM integrations where applicable, and documented key-ceremony controls.
  • Resolve certificate-chain, trust, revocation, TLS/SSL, smart-card, device, application, and network authentication issues.
  • Establish proactive certificate-expiry monitoring and automation to reduce service interruption risk.

Security, Automation, and Operational Excellence

  • Identify identity and PKI risks, lead remediation activities, and support security audits, vulnerability management, compliance assessments, and incident investigations.
  • Analyze identity, authentication, directory, and certificate logs to investigate incidents and provide root-cause analysis and corrective actions.
  • Build and maintain automation using PowerShell, Microsoft Graph API, REST APIs, and other appropriate tooling for administration, reporting, provisioning, compliance checks, and operational tasks.
  • Develop operational dashboards, health checks, alerting, and reporting for AD, Entra ID, synchronization services, authentication, and certificate infrastructure.
  • Produce and maintain high-quality architecture diagrams, technical standards, runbooks, knowledge articles, implementation plans, and recovery procedures.
  • Participate in on-call support, major incident response, change management, problem management, and post-incident reviews as required.
  • Collaborate with cybersecurity, cloud engineering, endpoint engineering, network, application, and service-management teams to deliver integrated solutions.

About You

Required Skills & Qualifications

  • Active Directory (AD DS): Multi-forest/multi-domain topologies, Group Policy Architecture, Trust relationships, Sites & Services, Kerberos/NTLM authentication flows, and AD security hardening (Tiered Administration model).
  • Microsoft Entra ID (Azure AD): Advanced Conditional Access, Entra Connect/Cloud Sync, Entra ID Protection, PIM, Workload Identities, B2B/B2C, and Microsoft Graph.
  • Keyfactor Ecosystem: Deep hands-on experience with Keyfactor Command, Orchestrators, Certificate Managers, and Keyfactor API integration.
  • PKI & Cryptography: Deep understanding of Public Key Infrastructure principles, X.509 certificates, CRL/OCSP validation, CA hierarchy design, SSH key governance, and HSM management.
  • Automation & Scripting: Expert level in PowerShell, Python, or Bash, alongside RESTful API integration for identity and PKI orchestration.
  • Protocol Mastery: Deep knowledge of SAML, OAuth, OIDC, Kerberos, LDAP, SCEP, EST, ACME, and TLS/SSL.
  • Experience: 10+ years in Enterprise IAM/Infrastructure Engineering, with at least 5+ years in a dedicated Lead or Solution Architect capacity.
  • Communication: Ability to articulate complex cryptographic and identity concepts to C-level executives, security teams, and application developers.
  • Strategic Problem Solving: Proven track record of executing large-scale PKI transitions and AD/Entra ID modernizations in complex, global environments.

Preferred Certifications

  • Keyfactor Certifications: Keyfactor Certified Professional / Engineer.
  • Microsoft Certifications: Microsoft Certified: Identity and Access Administrator Associate (SC-300). Microsoft Certified: Cybersecurity Architect Expert (SC-100). Azure Solutions Architect Expert (AZ-305).
  • Industry Security Certifications: CISSP, CISM, or Certified PKI Professional (CPKIP).

Our Approach to Flexible Work

With Flex Work, we’re combining the best of both worlds: in-person time and remote. Our approach enables our teams to deepen connections, maintain a strong community, and do their best work. We know that flexibility can take shape in many ways, so rather than a number of required days in-office each week, we simply spend at least half (50%) of our time each quarter in the office or in the field with our customers, prospects, and partners (depending on role). This means you'll have the freedom to create a flexible schedule that caters to your business, team, and personal needs, while being intentional to make the most of time spent together. Those in our remote "home office" roles also have the opportunity to come together in our offices for important moments that matter.

Workday is committed to providing reasonable accommodations for qualified individuals during our application process, in order to perform one or more essential functions of their job, as well as regarding the use of AI tools for employment decision-making to any degree. Please see below for more details including how to request an accommodation as a qualified veteran, due to a disability or for religious reasons, or as otherwise provided under applicable law.

Workday prohibits taking adverse action against any candidate or employee for reporting a possible violation of this policy, requesting one or more work accommodations, exercising a privacy right, or cooperating in an investigation in accordance with applicable law. Any employee who retaliates against a candidate or employee for doing so may be subject to disciplinary action, up to and including termination of employment, to the fullest extent allowable under applicable law.

If you require a reasonable accommodation, you may email [email protected], as far in advance as possible.

Are you being referred to one of our roles? If so, ask your connection at Workday about our Employee Referral process!

At Workday, we value our candidates’ privacy and data security. Workday will never ask candidates to apply to jobs through websites that are not Workday Careers.

Please be aware of sites that may ask for you to input your data in connection with a job posting that appears to be from Workday but is not.

In addition, Workday will never ask candidates to pay a recruiting fee, or pay for consulting or coaching services, in order to apply for a job at Workday.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
368,530 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Pune
$148k – $267k per year (Estimated) • Equity • Remote/Hybrid • Full-Time • 5+ years exp • Sunnyvale • Boston • Austin • Toronto • New York
AI/ML
AI Agents
Claude
Claude Code
Lovable
Replit
Cybersecurity
BeyondTrust
Crowdstrike
CyberArk
Delinea
Microsoft Entra ID
Okta
PCI DSS
SOC 2
Threat Modeling
Apply
$40k – $86k per year (Estimated) • Remote/Hybrid • Full-Time • Élancourt
Bash
PowerShell
Python
SQL
Databases
MySQL
PostgreSQL
Redis
DevOps
Amazon CloudWatch
Ansible
AWS
Azure
CentOS Stream
CI/CD
Debian
Docker
GCP
GitLab
GitLab CI
Grafana
Hyper-V
IAM
Jenkins
Kubernetes
Nagios
Prometheus
Proxmox VE
Terraform
Ubuntu
VMWare
Windows Server
Zabbix
Apply
$93k – $126k per year • Remote • Full-Time • 5+ years exp • Bachelor's Degree • United States
Node JS
SQL
TypeScript
JavaScript
Databases
MS SQL
Oracle
Mobile
JUnit
DevOps
AWS
Azure
CI/CD
GCP
Git
GitLab
GitLab CI
Jenkins
Management
Jira
QA
JMeter
Playwright
Postman
Rest-Assured
TestNG
Apply
$195k – $264k per year • In office • Full-Time • 15+ years exp • Master's Degree • United States
Python
AI/ML
Amazon SageMaker
Keras
Kubeflow
MLFlow
PyTorch
Scikit-learn
TensorFlow
Vertex AI
XGBoost
DevOps
AWS
Azure
CI/CD
CloudFormation
Docker
GCP
Kubernetes
Terraform
Cybersecurity
FedRAMP
NIST 800-53
Apply
$68k – $142k per year (Estimated) • In office • Full-Time • 10+ years exp • Bachelor's Degree • Marseille
AI/ML
Knowledge Graph
DevOps
AWS
Azure
GCP
Management
ServiceNow
Apply
$36k – $65k per year (Estimated) • In office • Full-Time • 7+ years exp • Bachelor's Degree • Pune
Apply
$152k – $228k per year • Equity • In office • Full-Time • 8+ years exp • Bachelor's Degree • Atlanta • Boulder • Reston
Cybersecurity
Exabeam
MITRE ATT&CK
Apply
$232k – $348k per year • Equity • In office • Full-Time • 8+ years exp • Bachelor's Degree • Pleasanton
SQL
AI/ML
AI Agents
Hallucination
LLM
Knowledge Graph
LLM Guardrails
DevOps
Platform Engineering
Apply
$122k – $254k per year (Estimated) • Equity • In office • Full-Time • 8+ years exp • Bachelor's Degree • Vancouver • Toronto
Python
TypeScript
Python
Celery
Django
FastAPI
Databases
Apache Kafka
PostgreSQL
Redis
AI/ML
LangChain
LlamaIndex
AI Agents
LLM
DevOps
ArgoCD
AWS
Datadog
Docker
GCP
GitOps
Grafana
Helm
Kubernetes
OpenTelemetry
Prometheus
Rest API
Terraform
Azure
Cybersecurity
SonarQube
QA
Sentry
Apply
$82k – $122k per year • Equity • In office • Full-Time • 3+ years exp • Bachelor's Degree • Dublin
Python
AI/ML
AI Agents
DevOps
AWS
GCP
Rest API
IAM
Cybersecurity
Microsoft Entra ID
Okta
Zero Trust
Least Privilege
Apply
$13k – $29k per year (Estimated) • Remote/Hybrid • Full-Time • Bachelor's Degree • Pune
JavaScript
Apex
Apex
MuleSoft
AI/ML
AI Agents
Edge AI
DevOps
AWS
Azure
Management
Draw.io
Marketing
Salesforce
Apply
$11k – $42k per year (Estimated) • In office • Full-Time • 4+ years exp • Bachelor's Degree • Pune
ABAP
Apply
Data Architect 2 hours ago
$38k – $91k per year (Estimated) • In office • Full-Time • 3+ years exp • Bengaluru • Pune
Node JS
Python
SQL
JavaScript
Databases
Databricks
MongoDB
Redis
Apply
$23k – $62k per year (Estimated) • In office • Full-Time • 3+ years exp • Navi Mumbai • Pune
Python
Apply
$27k – $71k per year (Estimated) • In office • Full-Time • 7+ years exp • Pune
C#
C++
Java
Python
DevOps
Azure
CI/CD
Git
QA
Pytest
Apply
See all jobs
This is one of many
368,530 more open roles from verified company boards, updated every day.