Principal IAM Engineer - Directory Services

syneoshealth· 3074 Syneos Health d.o.o. Beograd
Apply Now ↗
📍 SRB-Belgrade-HybridFull time

About this role

Principal IAM Engineer - Directory Services

Syneos Health® is a leading fully-integrated life sciences services organization built to accelerate customer success. We partner with innovators at every point across the drug development and commercialization continuum, helping them navigate complexity, anticipate change and accelerate progress.
 
Every day we perform better because of how we work together, as one team, each the best at what we do. We bring together talented experts across a broad spectrum of business critical corporate functions. Every role plays an essential part in enabling our customers to achieve their goals. Our teams are agile, collaborative, and committed to delivering—for each other, for our customers, and ultimately for the people who rely on the services we support.
Discover what your 25,000 future colleagues already know:
 
Why Syneos Health
• We are passionate about developing our people, through career development and progression; supportive and engaged line management; technical and therapeutic area training; peer recognition and total rewards program.
• We are committed to building an inclusive culture – where you can authentically be yourself. Central to this is our purpose – Driven to Deliver – which captures the passion of our colleagues to show up each day and shape solutions that have the ability to dramatically impact someone’s life. 
• We are continuously building the company we all want to work for and our customers want to work with. Why? Because we know that when we bring together smart colleagues from across the world, we can shape the future of healthcare, driving impact for customers and defining the pace of patient progress. 

Job Responsibilities

JOB RESPONSIBILITIES


  • Lead the engineering, administration, security, and modernization of Active Directory, Entra ID, Azure AD services, LDAP directories, and hybrid identity infrastructure.
  • Design and implement directory security controls, including AD hardening, Group Policy management, CIS benchmark compliance, privileged access controls, and identity-related vulnerability remediation.
  • Develop and maintain IAM automation, integrations, and operational tooling using PowerShell, Microsoft Graph, PowerBI, KQL, SQL, REST APIs, and Azure DevOps.
  • Build reporting and auditing solutions to support access reviews, compliance monitoring, account governance, and executive reporting using SQL and PowerBI.
  • Participate in the design, governance, and lifecycle management of non-human identities (NHI), including service accounts, application identities, certificates, secrets, and machine-to-machine authentication.
  • Troubleshoot and resolve complex AD, Entra ID, authentication/authorization, and identity governance issues using data-driven root cause analysis.
  • Support audit, compliance, and regulatory requirements through evidence collection, control validation, and access certifications.
  • Create and maintain architecture diagrams, standards, runbooks, operational procedures, and technical documentation.
  • Serve as a senior technical leader and escalation point for directory services, identity governance, NHI, automation, and access management initiatives.
  • Provide guidance and mentorship to junior engineers and foster the advancement of technical skills across the team. Promote a culture of continuous improvement and knowledge sharing.

QUALIFICATION REQUIREMENTS


  • Bachelor’s degree in computer science, Cybersecurity, Engineering, or related field.
  • At least 8+ years of experience in IAM, Directory Services, Infrastructure, and/or Security Engineering, including administration and support of enterprise identity platforms.
  • Strong hands-on experience with Active Directory, Entra ID, Azure AD, hybrid identity architecture, identity governance, authentication, authorization, and access management.
  • Considerable knowledge of Active Directory security, Group Policy management, CIS benchmark remediation, identity-related vulnerability management, and security logging.
  • Experience managing Non-Human Identities (NHI), including service accounts, application identities, certificates, secrets, credential rotation, and lifecycle governance.
  • Expertise in developing automation, integrations, and operational tooling using PowerShell, Microsoft Graph, SQL, KQL, REST APIs, JSON, Azure Automation, Logic Apps, Power BI, and Azure DevOps.
  • Ability to design and develop reporting, auditing, and analytics solutions for access governance, compliance monitoring, account lifecycle management, and identity security operations.
  • Experience integrating identity platforms with enterprise systems such as Saviynt IGA, ServiceNow, Workday, Microsoft 365, and cloud services.
  • Solid understanding of Zero Trust, least privilege, identity governance, privileged access, authentication, authorization, audit controls, and regulatory compliance requirements.
  • Familiarity with PAM platforms and privileged account management processes preferred.
  • Knowledge of regulated environments, including healthcare, life sciences, or CRO organizations preferred.
  • Proven ability to lead technical initiatives, mentor engineers, create operational documentation, and communicate effectively with technical and business stakeholders.
  • Self-directed and able to manage individual projects or work as part of a larger team.
  • Excellent written and verbal communications; Solid written and oral presentation skills.

Get to know Syneos Health

Over the past 5 years, we have worked with 94% of all Novel FDA Approved Drugs, 95% of EMA Authorized Products and over 200 Studies across 73,000 Sites and 675,000+ Trial patients.

No matter what your role is, you’ll take the initiative and challenge the status quo with us in a highly competitive and ever-changing environment. Learn more about Syneos Health.
 

http://www.syneoshealth.com

Additional Information

Tasks, duties, and responsibilities as listed in this job description are not exhaustive.  The Company, at its sole discretion and with no prior notice, may assign other tasks, duties, and job responsibilities. Equivalent experience, skills, and/or education will also be considered so qualifications of incumbents may differ from those listed in the Job Description. The Company, at its sole discretion, will determine what constitutes as equivalent to the qualifications described above.   Further, nothing contained herein should be construed to create an employment contract.  Occasionally, required skills/experiences for jobs are expressed in brief terms. Any language contained herein is intended to fully comply with all obligations imposed by the legislation of each country in which it operates, including the implementation of the EU Equality Directive, in relation to the recruitment and employment of its employees.  The Company is committed to compliance with the Americans with Disabilities Act, including the provision of reasonable accommodations, when appropriate, to assist employees or applicants to perform the essential functions of the job.

Frequently Asked Questions

Is the salary disclosed for the Principal IAM Engineer - Directory Services position at syneoshealth?
The salary for this Principal IAM Engineer - Directory Services role at syneoshealth is not publicly listed. Click "Apply Now" to learn more about the compensation package on their official careers page.
Where is the Principal IAM Engineer - Directory Services position at syneoshealth located?
This Principal IAM Engineer - Directory Services role at syneoshealth is based in SRB-Belgrade-Hybrid. The position is listed as on-site or hybrid. Check the full job description or apply directly to confirm the work arrangement.
Is the Principal IAM Engineer - Directory Services role at syneoshealth full-time or part-time?
This is listed as a Full time position. It is posted as a Principal IAM Engineer - Directory Services role in the 3074 Syneos Health d.o.o. Beograd department at syneoshealth.
Which team or department does the Principal IAM Engineer - Directory Services at syneoshealth belong to?
This Principal IAM Engineer - Directory Services position is part of the 3074 Syneos Health d.o.o. Beograd department at syneoshealth. See the full job description for more information about the team structure and responsibilities.
How do I apply for the Principal IAM Engineer - Directory Services position at syneoshealth?
Click the "Apply Now" button on this page. You will be redirected to syneoshealth's official application portal hosted on workday where you can submit your application directly.
When was the Principal IAM Engineer - Directory Services job at syneoshealth posted?
This Principal IAM Engineer - Directory Services position at syneoshealth was posted on Sep 28, 2026. Apply as soon as possible — early applications are often reviewed first.
Principal IAM Engineer - Directory Services
syneoshealth
Apply for this role ↗

You'll be redirected to syneoshealth's official application page on Workday.