Lead IAM Engineer
Reuters
Overview
We are seeking a highly skilled and experienced Lead IAM Engineer to design, implement, administer, optimize, and support complex enterprise identity infrastructure across on‑premises and cloud environments. The role focuses on Microsoft Active Directory, Microsoft Entra ID, Entra ID Connect, identity federation, and multi‑factor authentication. Responsibilities
Design, implement, administer, and support enterprise Active Directory environments across multiple on‑premises domains and forests. Lead the design and operational management of identity federation services, including ADFS and Entra ID Federation. Administer and support Entra ID, hybrid identity solutions, and Entra ID Connect—including sync configuration, health monitoring, and troubleshooting. Support and enhance MFA solutions, Conditional Access integrations, and secure authentication workflows. Develop scalable, secure, and resilient identity architecture solutions to support business growth, mergers, integrations, and modernization initiatives. Evaluate current‑state identity platforms and recommend improvements. Contribute to roadmap planning for IAM and directory services modernization. Implement identity security best practices for Active Directory and hybrid identity environments, including hardening, least privilege, privileged access controls, and secure administrative models. Partner with IAM and security teams to support compliance, audit readiness, vulnerability remediation, and incident response efforts. Review and improve controls related to authentication, access governance, and privileged access. Serve as a senior escalation point for complex directory services, federation, and authentication issues; troubleshoot issues involving AD replication, Kerberos/NTLM authentication, DNS, Group Policy, ADFS claims and trusts, Entra ID Connect synchronization, Federation and MFA failures. Perform root cause analysis and implement long‑term corrective actions. Ensure high availability and disaster recovery readiness for identity systems. Develop and maintain automation for identity administration, provisioning support, health checks, monitoring, and reporting using PowerShell and relevant tools. Create and maintain technical documentation, engineering standards, runbooks, and design artifacts. Support operational maturity through process improvement and standardization. Work closely with architecture teams on enterprise identity initiatives. Provide technical guidance to junior engineers and operations team. Participate in project planning, implementation, and change management activities. Support acquisitions, divestitures, or business transformations involving identity integration and migration. Qualifications
Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or related field, or equivalent work experience. 10+ years of hands‑on experience in engineering and administration of Microsoft Active Directory in large enterprise environments. Strong experience with multi‑domain and multi‑forest AD environments, DNS, Group Policy, replication, trusts, and authentication protocols. Expertise in identity synchronization and federation troubleshooting. Proficiency in PowerShell scripting and automation. Experience designing and implementing secure identity solutions in enterprise environments. Strong problem‑solving, troubleshooting, and root cause analysis skills. Familiarity with security frameworks and best practices for identity infrastructure. Excellent written and verbal communication skills. Experience with enterprise IAM strategy and modernization. Experience with mergers, acquisitions, divestitures, or domain consolidations. Experience with Conditional Access and passwordless authentication. Experience with privileged access management. Experience with identity governance and access lifecycle processes. Success Metrics
Active Directory and hybrid identity services are well‑architected and operationally mature. Authentication, federation, and synchronization issues are proactively identified and resolved. Security risks are reduced through improved configuration, hardening, and access controls. Automation, documentation, and standardization improve team efficiency and reliability. Identity platforms are secure, stable, and highly available. The engineer serves as a trusted technical expert and strategic partner across IAM and infrastructure initiatives. Benefits
Hybrid work model: flexible 2–3 days per week in office with the option to work from anywhere up to 8 weeks per year. Competitive benefits package including vacation, mental health days, access to Headspace, retirement savings, and tuition reimbursement. Paid volunteer days and ESG initiatives. We are an Equal Employment Opportunity Employer and provide reasonable accommodations for qualified individuals with disabilities in accordance with applicable law.
#J-18808-Ljbffr
We are seeking a highly skilled and experienced Lead IAM Engineer to design, implement, administer, optimize, and support complex enterprise identity infrastructure across on‑premises and cloud environments. The role focuses on Microsoft Active Directory, Microsoft Entra ID, Entra ID Connect, identity federation, and multi‑factor authentication. Responsibilities
Design, implement, administer, and support enterprise Active Directory environments across multiple on‑premises domains and forests. Lead the design and operational management of identity federation services, including ADFS and Entra ID Federation. Administer and support Entra ID, hybrid identity solutions, and Entra ID Connect—including sync configuration, health monitoring, and troubleshooting. Support and enhance MFA solutions, Conditional Access integrations, and secure authentication workflows. Develop scalable, secure, and resilient identity architecture solutions to support business growth, mergers, integrations, and modernization initiatives. Evaluate current‑state identity platforms and recommend improvements. Contribute to roadmap planning for IAM and directory services modernization. Implement identity security best practices for Active Directory and hybrid identity environments, including hardening, least privilege, privileged access controls, and secure administrative models. Partner with IAM and security teams to support compliance, audit readiness, vulnerability remediation, and incident response efforts. Review and improve controls related to authentication, access governance, and privileged access. Serve as a senior escalation point for complex directory services, federation, and authentication issues; troubleshoot issues involving AD replication, Kerberos/NTLM authentication, DNS, Group Policy, ADFS claims and trusts, Entra ID Connect synchronization, Federation and MFA failures. Perform root cause analysis and implement long‑term corrective actions. Ensure high availability and disaster recovery readiness for identity systems. Develop and maintain automation for identity administration, provisioning support, health checks, monitoring, and reporting using PowerShell and relevant tools. Create and maintain technical documentation, engineering standards, runbooks, and design artifacts. Support operational maturity through process improvement and standardization. Work closely with architecture teams on enterprise identity initiatives. Provide technical guidance to junior engineers and operations team. Participate in project planning, implementation, and change management activities. Support acquisitions, divestitures, or business transformations involving identity integration and migration. Qualifications
Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or related field, or equivalent work experience. 10+ years of hands‑on experience in engineering and administration of Microsoft Active Directory in large enterprise environments. Strong experience with multi‑domain and multi‑forest AD environments, DNS, Group Policy, replication, trusts, and authentication protocols. Expertise in identity synchronization and federation troubleshooting. Proficiency in PowerShell scripting and automation. Experience designing and implementing secure identity solutions in enterprise environments. Strong problem‑solving, troubleshooting, and root cause analysis skills. Familiarity with security frameworks and best practices for identity infrastructure. Excellent written and verbal communication skills. Experience with enterprise IAM strategy and modernization. Experience with mergers, acquisitions, divestitures, or domain consolidations. Experience with Conditional Access and passwordless authentication. Experience with privileged access management. Experience with identity governance and access lifecycle processes. Success Metrics
Active Directory and hybrid identity services are well‑architected and operationally mature. Authentication, federation, and synchronization issues are proactively identified and resolved. Security risks are reduced through improved configuration, hardening, and access controls. Automation, documentation, and standardization improve team efficiency and reliability. Identity platforms are secure, stable, and highly available. The engineer serves as a trusted technical expert and strategic partner across IAM and infrastructure initiatives. Benefits
Hybrid work model: flexible 2–3 days per week in office with the option to work from anywhere up to 8 weeks per year. Competitive benefits package including vacation, mental health days, access to Headspace, retirement savings, and tuition reimbursement. Paid volunteer days and ESG initiatives. We are an Equal Employment Opportunity Employer and provide reasonable accommodations for qualified individuals with disabilities in accordance with applicable law.
#J-18808-Ljbffr
Reference: WJ-3875_13395641