> Markdown version of [/jobs/ext/1167774-sr-information-security-engineer-iam](https://www.wearedevelopers.com/jobs/ext/1167774-sr-information-security-engineer-iam). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Sr Information Security Engineer - IAM - **Company:** O'Reilly Automotive Stores, Inc - **Location:** Springfield, MO, United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Microsoft Access, Active Directory, Application Programming Interfaces (APIs), Automated Storage and Retrieval Systems, User Authentication, Authentication Protocols, Cyber Security, Identity and Access Management, Intrusion Detection Systems, Lightweight Directory Access Protocols (LDAP), OAuth, OpenID, Windows PowerShell, Azure Active Directory, Security Assertion Markup Language (SAML), Security Information and Event Management, Enterprise Software Applications, Okta, Microsoft Power Automate, Enterprise Integration, Api Design - **Published:** July 3, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=c0c7e011e9fd23c1 ## About the Role Required: * Experience with enterprise scale identity migrations * Familiarity with Okta, Active Directory, Open LDAP or other like identity providers.Active Directory experience is required. * Deep knowledge of modern authentication protocols including but not limited to OIDC/OAuth2, SAML, WSFED, etc. * Familiarity with modern authorization, session, and token handling patterns including but not limited to claims-based authorization, back-channel logout, token introspection, token refinement, etc. * Strong knowledge of Entra ID specifically including but not limited to the features listed below: Preferred: * Retail Industry Experience with a strong understanding of store operations, merchandising, and omnichannel commerce. * Auto Parts Industry Knowledge, including familiarity with aftermarket supply chains, inventory management, and distribution networks. * Familiarity with Master Data Management (MDM) principles, architectures, and implementations. * Experience with international, multi-lingual product catalog solutions and localization strategies. * Experience with retail POS solutions and Commerce CMS platforms. * Experience with Warehouse Automation & Material Handling Solutions O'Reilly Auto Parts has a proven track record of growth and stability. O'Reilly is full of successful career stories and believes in a strong promote-from-within philosophy, encouraging you to grow your career along with the organization. ## Description The Senior IAM Engineer is a hands-on technical role focused on the implementation, integration, and operation of enterprise identity solutions. This role is responsible for delivering and supporting Microsoft Entra ID services, including the migration of existing identity platforms and applications to modern authentication models. Working closely with IAM Architecture and Security teams the engineer executes identity initiatives across cloud and on-premise environments, builds and maintains authentication and provisioning integrations while ensuring secure, reliable identity services that support the organization's operation and security objectives., * Execute identity platform initiatives including migrations from legacy identity providers to Entra ID. * Configure and maintain cross-tenant identity scenarios including Multi-Tenant collaboration, B2B, and External ID * Implement and support IAM solutions aligned with defined enterprise architecture, focusing on Microsoft Entra ID and hybrid identity environments. * Configure and maintain core Entra ID capabilities: SSO, MFA, Conditional Access, Passwordless authentication, B2B access, Identity protection policies and risk-based controls. * Integrate applications using modern authentication protocols: OIDC, OAuth2, SAML * Configure and Manage: Enterprise Applications, App Registrations, API permissions and consent. * Implement and maintain identity provisioning solutions using: SCIM, API-Based Provisioning, Event-Drive or Scheduled workflows. * Support and enhance identity lifecycle processes: Joiner / Mover / Leaver, Access Requests and Approvals, Role and Group-Based access assignment * Develop Automation and Integration solutions using Powershell, Microsoft Graph API, and Logic Apps or equivalent tooling. * Build reusable scripts and processes to standardize IAM operations. * Support adoption of managed identities and service principals for application and workload authentication. * Implement and support identity security controls aligned with organizational and regulatory requirements. * Diagnose and resolve issues related to authentication failures, provisioning errors, directory synchronization issues, access and authorization problems. * Provide technical input and feedback to improve IAM implementations and operational processes. * Provide hands-on technical mentorship and implementation guidance where appropriate at all levels. Core Identity and Directory Services * Core Services (user/group/device) * Federated Identities * Custom attributes and schema extensions * Dynamic Groups * Directory role strategies for enterprise delegation Authentication and Access Control * SSO * Conditional Access * Passwordless Authentication * B2B Identity Protection and Risk * User Risk Detection * Sign-in Risk Detection * Using Risk with Conditional Access * Risk Remediation Policies * Supporting SIEM/SOAR integration * Logs and Forensics Identity Governance and Administration * Access Reviews * Access Request Workflows * Time-Bound Access * Identity and Access Lifecycle (Mover/Joiner/Leaver) * Augmentation with Logic Apps and other automation technologies. Application Access and SSO * OIDC, OAuth2, SAML * Enterprise Applications * Application Registrations * API permissions and consent * Application Proxy * Token Configuration and Claims Refinement Provisioning and Lifecycle * Guest Users * Cross Tenant access * External IDs ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [APIs and Architecture for scaling omnichannel payments](https://www.wearedevelopers.com/videos/90-apis-and-architecture-for-scaling-omnichannel-payments) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) - [Delegating the chores of authenticating users to Keycloak](https://www.wearedevelopers.com/videos/1558-delegating-the-chores-of-authenticating-users-to-keycloak) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Now is the time for industrialized software development](https://www.wearedevelopers.com/magazine/601-now-is-the-time-for-industrialized-software-development) - [Find a Developer Job: 12 Best Job Sites For Developers](https://www.wearedevelopers.com/magazine/165-find-a-developer-job-12-best-job-sites-for-developers)