Barry Callebaut Group

Expert IAM Analyst Identity

Barry Callebaut Group  •  Onsite  •  5 hours ago
Apply
AI can make mistakes so check important info. Chat history is never stored.

Job Description

Section 1 - JOB DESCRIPTION

Barry Callebaut Digital (BC Digital) is on a mission to lead the digital revolution in the chocolate industry, and we're looking for an Expert Engineer to join our Identity & Access Management team. Identity and Access Management (IAM) is a key element of the Information Security Strategy and Framework and plays a vital role in our digital ecosystem.

As an Expert Engineer, you will be the senior hands-on Identity specialist responsible for the architecture, security, stability, modernization and continuous improvement of our enterprise Identity platforms, including Microsoft Entra ID, Active Directory, Hybrid Identity, Microsoft Defender for Identity (MDI), CyberArk, Public Key Infrastructure (PKI), and Okta.

You will serve as the highest technical escalation point for Identity & Access Management, leading complex troubleshooting, root cause analysis, platform engineering, security hardening, automation initiatives and operational excellence. You will work closely with IT Security, Enterprise Architecture, Cloud, Infrastructure and Application teams across a global footprint to deliver secure, scalable and resilient identity services that support Barry Callebaut’s Zero Trust strategy. If you are a seasoned Identity professional with deep Microsoft Identity expertise and extensive enterprise IAM experience, we invite you to join our team.

MAIN RESPONSIBILITIES & SCOPE

The candidate will:

  • Own the end-to-end enterprise Identity & Access Management platforms, including Microsoft Entra ID, Active Directory, Microsoft Entra Connect (Cloud Sync & Connect Sync), Microsoft Defender for Identity (MDI), CyberArk, PKI and Okta.
  • Act as the technical design authority for enterprise Identity & Access Management solutions, ensuring security, scalability, automation, resilience and operational excellence.
  • Design, implement and maintain Microsoft Entra ID security capabilities, including:
  • Conditional Access
  • Privileged Identity Management (PIM)
  • Access Packages
  • Lifecycle Workflows
  • Dynamic Groups
  • Authentication Methods
  • Passwordless Authentication (FIDO2, Windows Hello for Business, Passkeys)
  • Multi-Factor Authentication (MFA)
  • Design, implement and maintain hybrid identity solutions integrating Active Directory with Microsoft Entra ID.
  • Design and manage Enterprise Applications, App Registrations, Managed Identities and Service Principals within Microsoft Entra ID.
  • Lead authentication and federation integrations using SAML 2.0, OAuth 2.0, OpenID Connect (OIDC), WS-Federation and modern authentication protocols.
  • Design, implement and maintain secure identity lifecycle management processes, including provisioning, deprovisioning, access governance and identity automation.
  • Manage privileged access solutions using CyberArk following Zero Trust and Least Privilege principles.
  • Support Microsoft Defender for Identity (MDI) by investigating identity threats, strengthening detections and improving the organization’s identity security posture.
  • Support and improve the enterprise PKI environment, including certificate lifecycle management, certificate-based authentication and cryptographic best practices.
  • Develop automation using Microsoft Graph API, PowerShell, REST APIs and scripting to improve operational efficiency.
  • Drive platform modernization initiatives by evaluating and implementing new Microsoft Identity capabilities and industry best practices.
  • Define and maintain IAM standards, technical documentation, operational procedures and engineering guidelines.
  • Act as the L3/L4 technical escalation point, perform root cause analysis and implement preventive improvements.
  • Mentor junior engineers and provide technical leadership across the global IAM organization.
  • Assist in developing and executing the vision for identity management, aligning with the overall I&AM strategy
  • Act as design authority for IAM platforms, directory services, and authentication solutions.
  • Architect, design, review, and implement complex IAM and directory service solutions across on-prem, and cloud environments.
  • Lead identity lifecycle, federation, and authentication initiatives.
  • Work closely with IT Security, Enterprise Architecture, and other teams
  • Rapidly address security incidents and troubleshoot complex issues related to identity management
  • Contribute to IAM standards, procedures, and long-term platform improvements.

Scope:

  • Global role supporting users, applications, and platforms across multiple regions.
  • Key stakeholders are located in Belgium, Switzerland, India, Poland and other locations of our global footprint
  • Primary focus on Microsoft Entra ID, Active Directory; with added responsibility for CyberArk, PKI, Microsoft Defender for Idenitty and Okta.

EDUCATION, LANGUAGE, SKILLS & QUALIFICATIONS

  • Bachelor’s or Master’s degree in Information Technology, Computer Science, Information Security, Cyber Security or related field.
  • Microsoft Certified: Azure Administrator Associate (AZ-104) is mandatory.
  • Microsoft Certified: Identity and Access Administrator Associate (SC-300) is mandatory.
  • Additional Microsoft certifications such as AZ-305, SC-100, AZ-500 or SC-100 are highly preferred.
  • CyberArk Defender/Administrator certification is considered an advantage.
  • Okta Professional or Administrator certification is considered an advantage.
  • Industry-recognized certification in security (e.g., CAMS, CIAM, SC-300/900) or equivalent a highly appreciated
  • Proven track record of successfully delivery complex IAM projects in large environments
  • In-depth knowledge of industry best practices and emerging trends
  • Proficient in English

ADDITIONAL CONSIDERATIONS OR COMMENTS

  • Position in a global team with global responsibility
  • Opportunity to work in a very dynamic and diverse environment
  • Possibility to be in touch with the newest security technology advances and bring it on a large corporate environment

Section 2 - CANDIDATE PROFILE

ESSENTIAL EXPERIENCE & KNOWLEDGE / TECHNICAL OR FUNCTIONAL COMPETENCIES

  • 15+ years of experience in Identity & Access Management in enterprise environments, with strong Microsoft Entra ID experience.
  • Proven experience administering enterprise Microsoft Entra ID environments supporting more than 20000 identities.
  • Expert knowledge of Microsoft Entra ID.
  • Expert knowledge of Azure Identity and identity-related Azure services.
  • Expert knowledge of Active Directory, Hybrid Identity, Microsoft Entra Connect Sync and Cloud Sync.
  • Expert-level experience designing, implementing and troubleshooting Conditional Access policies aligned with Microsoft’s Zero Trust architecture.
  • Expert knowledge of Privileged Identity Management (PIM).
  • Strong experience with Enterprise Applications, App Registrations, Access Packages, Managed Identities and Service Principals.
  • Deep hands-on experience with SSO: SAML, OAuth, authentication policies, sign-on policies and app troubleshooting.
  • Strong expertise in MFA and secure access: configuration, enrollment issues and policy tuning.
  • Experience with passwordless authentication technologies including Windows Hello for Business, FIDO2 Security Keys and Passkeys.
  • Strong experience administering Microsoft Defender for Identity (MDI).
  • Strong experience with Microsoft Graph API, PowerShell automation, REST APIs and scripting.
  • Strong experience with CyberArk Privileged Access Management.
  • Strong knowledge of enterprise PKI, certificate lifecycle management and certificate-based authentication.
  • Working knowledge of Okta administration, federation and identity integrations.
  • Strong understanding of Microsoft’s Zero Trust Identity architecture and Identity security best practices.
  • In-depth knowledge of IAM principles, authentication, authorization, and identity governance.
  • Strong knowledge of Microsoft Entra ID, Microsoft Active Directory and CyberArk.
  • Excellent communication and collaboration skills
  • Strong problem-solving skills in complex IAM scenarios
  • Results-oriented and adaptable

LEADERSHIP COMPETENCIES & PERSONAL STYLE

The ideal candidate…

  • Exhibits a passion for digital technology and innovation, constantly seeking new and creative solutions to enhance processes, decision-making and user experiences
  • Collaborates well across diverse and globally distributed teams, with the ability to build and maintain positive relationships across different levels and functions of the organization
  • Is hands-on, pragmatic, and accountable for outcomes (availability, reliability, security posture)
  • Coaches others through structured knowledge sharing and real-case mentoring
  • Is proactive in continuous improvement: reduces repeat incidents, improves SOPs, and automates recurring tasks.
  • Communicates clearly in incidents and change execution, documents decisions and procedures consistently, with strong documentation and presentation skills.
  • Strategic thinker with the ability to translate vision into actionable plans
  • Collaborative and adaptable leadership style
  • Results-oriented and proactive in risk management
Barry Callebaut Group

About Barry Callebaut Group

With annual sales of about CHF 14.8 billion in fiscal year 2024/25, the Zurich-based Barry Callebaut Group is the world’s leading solutions provider of high-quality chocolate experiences across the full spectrum of chocolate, cocoa, cacao coatings and non-cocoa alternatives – from sourcing and processing cocoa beans to crafting premium chocolates, fillings and decorations. 

The Group operates more than 60 production facilities worldwide and employs a diverse, committed workforce of over 13,000 people. Barry Callebaut serves as a trusted partner for the entire food industry, from large-scale food manufacturers to artisanal and professional users such as chocolatiers, pastry chefs, bakers, hotels, restaurants and caterers with Callebaut® as its main global brand. 

The Barry Callebaut Group is dedicated to making sustainable chocolate the norm – helping secure the future of cocoa and improving the livelihoods of cocoa farmers. It supports the Cocoa Horizons Foundation, which aims to shape a sustainable future for cocoa and chocolate.

Industry
Food & Beverage
Company Size
5,001-10,000 employees
Headquarters
Zurich, CH
Year Founded
Unknown
Social Media