Navy Federal Credit Union currently does not provide sponsorship for this role. Applicants must be authorized to work in the United States without the need for current or future sponsorship. The Principal IAM Engineer is a technical resource with intermediate or master level skills in the architecture, design, configuration, and management of Active Directory, Microsoft Entra, and modern authentication services. Your success with attaining and performing the required skills and abilities will be enhanced if they consist of the following: Identity provider administration, design and maintenance for Active Directory Federation Services, Strata Identity Orchestrator, Active Directory Lightweight Directory Services, Entra ID Identity federation implementation (with internal/external workforce applications. Apply engineering principles into the design and enhancement of new and existing systems. Ensure the security and integrity of system and product solutions including compliance with Navy Federal and Information Security principles and practices. Present clear, organized, and concise information to all audiences through a variety of media to enable effective business decisions. Perform engineering tasks and assignments in support of business needs. Perform engineering technology research, procurement, deployment, and configuration for new and modified systems. Perform other duties as assigned. Bachelor’s Degree in Information Technology or the equivalent combination of education, training or experience 7-10 years of experience in identity security engineering Expert knowledge of identity security best practices surrounding account separation, JIT, least privilege, zero trust Hands-on experience designing and managing Active Directory infrastructure. As evidenced by at least 1 current certification (Microsoft Certified Solutions Associate, or Microsoft Certified Solutions Expert with a focus on server infrastructure.) or the equivalent experience and training. Solid understanding of design and implementation of modern authentication protocols, such as SAML, OIDC, FIDO, and PIV. Strong foundational knowledge of Active Directory infrastructure, protocols and authentication patterns: Domain Controllers, Group Policy, Sites/Services Topology, Replication, Kerberos Experience with the following: Microsoft Entra suite including: Conditional Access Azure SSO leveraging SAML/OIDC, Service Principals, and Agentic Identities Management of directory identity in Entra and M365, leveraging security policies, PIM, RBAC Identity Governance Defender for Identity Strata (Maverics) Identity Orchestration or similar Active Directory Federation Services Active Directory Lightweight Directory Services (AD-LDS) Microsoft Enterprise PKI leveraging OCSP Azure AD Connect Desired Qualifications Strong identity security mindset with a proven ability to design and operate identity solutions that prioritize security, compliance, and long-term resilience Advanced PowerShell Scripting techniques. Knowledge of Golang and YAML. Additional Information Hours: Monday - Friday, 8:00AM - 4:30PM ( Operations will include 24x7 on-call systems support) Location: 820 Follin Lane, Vienna, VA 22180 5510 Heritage Oaks Drive, Pensacola, FL 32526 141 Security Drive, Winchester, VA 22602 9999 Willow Creek Road San Diego, CA 92131
Mobile Device Management Engineer (Puerto Rico)
Globalhr
Principal Product Management Engineer - Identity Engineering
Cisco
Director, Software Engineering - Order Management
Crateandbarrel
Senior Software Engineer, Order Management
Crateandbarrel
Lead Information Security Engineer - Vulnerability Management
Fifththird
Principal Product Management Engineer - Identity Engineering
Cisco