About Persistent
We are an AI-led, platform-driven Digital Engineering and Enterprise Modernization partner, combining deep technical expertise and industry experience to help our clients anticipate what's next. Our offerings and proven solutions create a unique competitive advantage for our clients by giving them the power to see beyond and rise above. We work with many industry-leading organizations across the world, including 20 Fortune 50 companies and 4 of the 5 top banks in both the US and India, and numerous innovators across the healthcare ecosystem.
Our disruptor's mindset, commitment to client success, and agility to thrive in the dynamic environment have enabled us to sustain our growth momentum. Persistent has been recognized across top industry platforms for innovation, leadership, and inclusion. We reported $1,654.4M FY26 revenue with 17.4% Y-o-Y growth. We have delivered 24 sequential quarters of growth with $436.0M in Q4 FY26 revenue, up 3.2% Q-o-Q and 16.2% Y-o-Y growth. Our 27,500+ global team members, located in 18 countries, have been instrumental in helping the market leaders transform their industries. We have been recognized as the Fastest Growing IT Services Brand Globally in the 2026 Brand Finance IT Services 25 Report. We named a Leader in the Everest Group Private Equity (PE) Services PEAK Matrix® Assessment 2026 and Software Product Engineering PEAK Matrix® Assessment 2026.
About Position
We are looking for a skilled Azure Entra ID Application Onboarding Engineer to onboard and integrate enterprise applications into Single Sign-On (SSO) using Azure Entra ID. The role requires strong hands-on experience with modern authentication protocols, scripting, conditional access, and application security. The engineer will work closely with application owners, security teams, and infrastructure teams to ensure secure, scalable, and compliant identity integrations.
Role: Dev Lead
Location: Pune
Experience: Between 5 to 8 Years
Job Type: Full Time Employment
What You'll Do
- Onboard SaaS, custom, and legacy applications to Azure Entra ID Single Sign-On (SSO) using SAML 2.0, OAuth 2.0, and OpenID Connect (OIDC)
- Design and configure secure authentication and authorization flows between Azure Entra ID and applications
- Define and manage claims/attribute mapping (attribute contracts) for SAML and OIDC integrations
- Implement and support Conditional Access Policies, including MFA, device compliance, and risk-based access
- Perform certificate and secret lifecycle management, including SAML signing cert renewals and app secret rotations
- Troubleshoot SSO issues using browser traces, token inspection, Azure sign-in logs, and application logs
- Work with application user stores and authorization models to ensure correct user identification and access
- Implement and support SCIM-based user provisioning and deprovisioning
- Automate repetitive identity tasks using PowerShell scripting
- Collaborate with application teams on deployment best practices (DNS, SSL, redirect URIs, session handling)
- Support change, incident, and request management processes using ServiceNow
- Create and maintain technical documentation and user communication for identity changes and integrations
Expertise You'll Bring
- Strong understanding of SSO concepts and protocols:SAML 2.0
- OpenID Connect (OIDC)
- OAuth 2.0
- Hands-on experience onboarding applications to Azure Entra ID (Azure AD)
- Solid knowledge of authentication vs authorization concepts
- Experience with claims transformation and attribute mapping
- Working knowledge of Active Directory (users, groups, attributes)
- Experience with Conditional Access Policies and MFA configurations
- Proficiency in PowerShell scripting for automation and reporting
- Understanding of certificate management and renewal processes
- Experience troubleshooting web applications and SSO issues
- Familiarity with Exchange Online authentication dependencies
- Knowledge of SCIM for automated provisioning
- Experience using Azures SAML attribute mapper (including preview features)
- Hands-on experience implementing SCIM integrations with SaaS or custom endpoints
- Experience working within ServiceNow-based change and onboarding workflows
- Exposure to Azure AD sign-in logs, audit logs, and security monitoring
- Experience drafting or updating end-user and application-owner communications
- Understanding of application hosting, DNS, SSL/TLS, and session/cookie management
- Strong communication and stakeholder management skills
- Ability to work independently on onboarding requests end-to-end
- Attention to security, compliance, and standardization
- Strong documentation and knowledge sharing mindset
Education: Bachelor's or Master's degree in Computer Science, Engineering, or a related field.
Benefits
- Competitive salary and benefits package
- Culture focused on talent development with quarterly growth opportunities and company-sponsored higher education and certifications
- Opportunity to work with cutting-edge technologies
- Employee engagement initiatives such as project parties, flexible work hours, and Long Service awards
- Annual health check-ups
- Insurance coverage: group term life, personal accident, and Mediclaim hospitalization for self, spouse, two children, and parents
Values-Driven, People-Centric & Inclusive Work Environment
Persistent is dedicated to fostering diversity and inclusion in the workplace. We invite applications from all qualified individuals, including those with disabilities, and regardless of gender or gender preference. We welcome diverse candidates from all backgrounds.
- We support hybrid work and flexible hours to fit diverse lifestyles.
- Our office is accessibility-friendly, with ergonomic setups and assistive technologies to support employees with physical disabilities.
- If you are a person with disabilities and have specific requirements, please inform us during the application process or at any time during your employment
Let's unleash your full potential at Persistent -
persistent.com/careers
Persistent is an Equal Opportunity Employer and prohibits discrimination and harassment of any kind.
Oauth,OpenID Connect,Azure AD