SENIOR CLOUD IDENTITY ENGINEER (M/F/D)
Redcare-pharmacy
Full-timesenior
Job description
<p><strong>About your tasks</strong></p><ul><li><strong>Design and scale Microsoft Entra ID Governance</strong> by implementing Access Reviews, defining governance processes together with business stakeholders and building script-based automation to roll out governance capabilities consistently across a decentralized Microsoft Entra environment.</li><li><strong>Engineer secure workload identity services</strong> by automating the lifecycle of Service Principals, certificates, secrets and federated credentials, integrating directly with Azure Key Vault and ensuring every solution follows <strong>Least Privilege</strong> principles from day one.</li><li><strong>Design and implement modern self-service capabilities</strong> for Service Principals, Entra Groups and delegated administration, enabling engineering teams to work independently without unnecessary ownership or excessive permissions.</li><li><strong>Review and optimize Azure RBAC, Entra RBAC, application permissions, Microsoft Graph permissions and OAuth consent models</strong> to continuously reduce excessive privileges, strengthen identity governance and improve Redcare’s cloud identity security posture.</li><li><strong>Build identity monitoring and detection capabilities to proactively identify expiring credentials, permission misuse and guardrail violations</strong> using <strong>Microsoft Sentinel, Azure Monitor, Log Analytics and Kusto Query Language (KQL).</strong></li><li>Support the automation of Joiner, Mover and Leaver processes with HRIS as single source of truth for identity</li></ul>
<p><strong>About you</strong></p><ul><li>You bring <strong>hands-on experience</strong> designing and automating cloud identity solutions with <strong>Microsoft Entra, Administrative Units, Microsoft Entra ID Governance, Microsoft Graph Permissions, Azure, Microsoft 365 and Power Platform</strong> in complex cloud environments.</li><li>You enjoy engineering <strong>secure, scalable identity platforms</strong> and designing <strong>Zero Trust</strong> and <strong>Least Privilege</strong> architectures while balancing <strong>developer experience</strong> with enterprise security requirements. You naturally think in <strong>automation, APIs, governance and secure-by-design</strong> rather than manual administration.</li><li>You challenge unnecessary permissions and advocate for <strong>modern identity governance</strong>, <strong>Permission Misuse Detection</strong> and <strong>continuous improvement</strong> to build secure, scalable cloud environments.</li><li>You are curious about <strong>emerging identity technologies</strong>, enjoy experimenting with new ideas, <strong>sharing your knowledge</strong> and <strong>presenting technical concepts</strong> to colleagues and stakeholders. You collaborate across teams to continuously improve the way cloud identity is designed, governed, secured and automated.</li></ul>
<p><strong>About your benefits:</strong></p><p>In order to provide you with the best possible support for your individual needs - whether it‘s living a healthy life, having enough time for your family, or developing your skills - we offer a wide range of different, site-specific benefits.</p><ul><li>Welcome days: We want you to feel at home with us from the very first day. Therefore, we welcome you with our comprehensive onboarding program.</li><li>Remote working: While this is a remote position based in Germany, it may require occasional on-site collaboration at our offices in Berlin or Cologne, depending on business and team requirements.<em> </em>For our remote working employees we grant you 500,00 € to set up your office space from home. To create an environment for you and how you work best.</li><li>Anchor days: As per your remote contract there will be some occasions to travel to office for anchor days, this is fully reimbursed including any travelling costs or hotel expenses.</li><li>Personal development: Grow! We support and encourage your individual development through various in- and external trainings.</li><li>Employee referral program: Because you know best who fits in with us, successful recommendations are rewarded with a bonus.</li></ul>
Skills
Microsoft Entra ID GovernanceMicrosoft EntraAdministrative UnitsMicrosoft Graph PermissionsAzureMicrosoft 365Power PlatformAzure RBACEntra RBACOAuth consent modelsMicrosoft SentinelAzure MonitorLog AnalyticsKusto Query Language (KQL)HRISAPIsAutomation