Sr. Identity Security Engineer Active Directory & Entra ID
Job Summary
Do you enjoy solving complex identity challenges and building secure, reliable identity services that enable the business?
Join our Identity and Access Management team, where you will engineer and support enterprise identity capabilities across Active Directory, Microsoft Entra ID, hybrid identity, privileged access, and non-human identities. You will collaborate with security, cloud, IT, and application teams to improve identity platforms, strengthen access controls, and implement secure patterns for applications, services, and emerging AI-enabled systems.
In this role, you will apply strong hands-on engineering skills to enhance the security, reliability, and governance of core identity services while using automation and repeatable practices to make those services more consistent, scalable, and resilient.
Responsibilities
- Engineer, configure, and improve core identity platforms and capabilities, including Active Directory, Microsoft Entra ID, hybrid identity, and non-human identities.
- Implement and support authentication, authorization, privileged access, and identity governance controls across human and non-human identities.
- Contribute to the security, resilience, and recoverability of enterprise identity services through platform hardening, monitoring, operational readiness, troubleshooting, and recovery exercises.
- Build and maintain automation, scripts, documentation, and repeatable engineering processes that improve consistency, reliability, and operational efficiency.
- Partner with senior engineers and cross-functional teams to implement identity patterns and guardrails for applications, services, AI-enabled systems, and automation platforms.
- Provide technical guidance to project teams, participate in design reviews, and help resolve complex identity platform issues.
- Participate in operational support, incident response, root-cause analysis, and continuous improvement for identity services.
Minimum Qualifications
- A bachelor's degree and 6 years of professional work experience (or a master's degree and 3 years of professional work experience, or a PhD degree, or equivalent experience) is required.
- Expertise with active directory
Additional Qualifications
A successful candidate will have experience in many of the following areas:
- Enterprise identity platforms, including Active Directory, Microsoft Entra ID, hybrid identity, federation, provisioning, and authentication technologies.
- Identity security practices, including privileged access, administrative tiering, identity threat detection and response, recovery planning, and platform hardening.
- Workload and non-human identities, including service principals, managed identities, certificates, secrets, application permissions, and federated credentials.
- IAM engineering and automation, including PowerShell or other scripting languages, APIs, configuration-as-code, Git-based workflows, and CI/CD practices.
- Application identity and permission governance, including app registrations, delegated and application permissions, consent models, and least-privilege access design.
- Troubleshooting complex identity, authentication, synchronization, and authorization issues across hybrid environments.
- Working knowledge of security and regulatory frameworks such as NIST, ISO 27001, and similar standards.
- Interest in emerging identity patterns supporting AI-enabled systems, automation platforms, and agentic workflows.