Passion for food. Hunger for tech. We make METRO digital.
Today technology is driving the world. And at METRO.digital we are driving the technology for one of the leading international wholesalers specializing in food \- METRO. From e\-commerce to checkout, to delivery software, we work on a wide range of products to make each day a success for our customers and colleagues. With passion and ownership, we build the future of wholesale.
You are driving to create smart solutions for customers around the globe? You want to grow in a flexible environment? Let the right career opportunity find you and join us!
Solution Architect – Microsoft Entra ID, Active Directory \& CyberArk PAM
Role Summary
We are seeking an experienced Solution Architect to define and drive the identity and privileged access management (PAM) architecture across a hybrid Microsoft Entra ID and On‑Prem Active Directory environment, with deep expertise in CyberArk PAM solutions.
This role owns the end‑to‑end design, integration, and governance of identity and privileged access controls, ensuring alignment with enterprise IAM strategy, Zero Trust principles, and regulatory requirements. The architect will work closely with IAM engineers, security teams, infrastructure, application owners, and DevOps teams to deliver secure, scalable, and compliant solutions.
Key Responsibilities
Identity \& Access Architecture (Entra ID \& Active Directory)
+ Conditional Access
+ MFA and authentication strengths
+ Passwordless authentication (FIDO2, Windows Hello for Business)
Privileged Access Management (CyberArk)
+ Servers
+ Endpoints
+ Databases
+ Applications
+ SSO
+ MFA
+ Microsoft Entra ID
+ SIEM platforms
+ ITSM tools
+ CyberArk Conjur
+ CyberArk CCP
Solution Design \& Integration
+ Entra ID
+ Active Directory
+ CyberArk PAM platforms
+ On‑prem, cloud, and SaaS applications
+ SSO and federation
+ Privileged access flows
+ Secrets consumption models
Architecture, Strategy \& Governance
+ Privileged account onboarding
+ Password rotation
+ Session recording and monitoring
+ Removal of standing administrative access
+ Credential hardening
+ SOX
+ ISO
+ GDPR
Leadership \& Collaboration
+ IAM and PAM engineering teams
+ Security architecture
+ Cloud and infrastructure teams
+ Application owners
Required Skills \& Expertise
CyberArk \& PAM
Microsoft Identity
Operating Systems \& Platforms
+ Windows privilege models
+ Unix/Linux privilege models
+ Active Directory security concepts
Automation \& Integration
+ REST APIs
+ PowerShell
+ Python
Security \& Architecture
Nice to Have
+ Azure
+ AWS
+ GCP
+ Sentry
+ CDE
Graduation OR Post Graduation
Gen AI+ AWS(AWS Sagemaker , bedrock)
CG-VAK Software & Exports Ltd. · Noida, Uttar Pradesh, India
Gen AI+ AWS(AWS Sagemaker , bedrock)
CG-VAK Software & Exports Ltd. · Chennai, Tamil Nadu, India
Site Reliability Engineer
LSEG · Bengaluru, Karnataka, India