Entra ID Authentication Administrator

Lawrence Livermore National Laboratory
Livermore, CA, United States
about 1 month ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Compensation
$125,310.0 - $185,640.0
Working hours
Regular working hours

Tech stack

User Authentication Computer Engineering Multi-Factor Authentication Monitoring of Systems Identity and Access Management Automation of Marketing System Center Operations Management Microsoft Operating Systems Windows Servers Nagios OAuth OpenID
+6 more
Windows PowerShell Azure Active Directory Security Assertion Markup Language (SAML) Enterprise Software Applications Information Technology Splunk

Job description

We have an opening for an Entra ID Authentication administrator. You will configure, maintain and support SAML and OAuth based authentication for enterprise applications. This position is in the Information Technology Solutions Division (ITSD) within the Computing Directorate, in support of the Livermore Information Technology (LivIT) Program.

This position may offer a hybrid schedule, which includes the flexibility to work from home one or more days per week, after a probationary period. The specifics of the hybrid schedule, including the exact number of days required in the office and virtual work options, may vary based on the needs of the team and the organization .

This position will be filled at either level based on knowledge and related experience as assessed by the hiring team. Additional job responsibilities (outlined below) will be assigned if hired at the higher level.

You will

  • Work with other engineers and administrators operating and maintaining critical enterprise services.
  • You will interface directly with end users and work with the application and engineering teams in the performance of root cause analysis of reported problems.
  • Design, implement and support Microsoft Entra ID authentication services
  • Recommend, justify, and implement improvements to services and systems using an accepted change control methodology.
  • Design and deliver creative solutions and resolve problems in a timely and proactive manner while collaborating within a diverse group.
  • Ensure service level agreements are met and the highest levels of service reliability are maintained.
  • Use scripting and automation to develop solutions to common problems and reduce operational overhead.
  • Support critical systems off-hours as needed and part of a regular 24/7 on-call rotation.
  • Perform other duties as assigned.

Additional job responsibilities, at the 393.2 level

  • Manage multiple complex parallel tasks and priorities of customers and stakeholders, ensuring deadlines are met, while leveraging team member skills.
  • Leverage technology and develop procedures to improve authentication service delivery.

Requirements

  • Ability to secure and maintain a U.S. DOE Q-level security clearance which requires U.S. citizenship.
  • Bachelor’s degree in Computer Science, Computer Engineering or related field, or the equivalent combination of education and related experience.
  • Broad and in-depth experience operating and supporting Entra ID in an enterprise setting.
  • Ability to work in a dynamic, technical team environment with competing priorities, tight deadlines and high pressure associated with operating a critical, complex system.
  • Broad and in-depth experience administering application authentication integration using SAML and OAuth/OIDC in Entra ID.
  • Proficient written and verbal communication and strong interpersonal skills, ability to interact with all levels of management and staff as well as outside vendors, contractors, service providers and consultants.
  • Ability to work off-hours and on-call and to respond to service alerts from various monitoring systems (intermittently, either as-needed or as part of a rotation).
  • Proficient in managing users, groups, applications, and hybrid identity (Entra Connect)
  • Experience with Conditional Access, Multi-Factor Authentication (MFA), Privileged Identity Management (PIM), and/or Certificate-Based Authentication (CBA)., * Significant experience collaborating with external teams and organizations supporting authentication related services.
  • Significant knowledge and experience with PowerShell or similar automation platforms to administer Microsoft systems and services.
  • Highly advanced ability to provide innovative approaches and apply new technologies to broadly defined tasks and projects.

Qualifications We Desire

  • Broad experience with monitoring platforms such as SCOM, Splunk or Nagios.
  • Broad and in-depth experience administering Windows server environments including deployment, patching, monitoring, backup or repairing.
  • Broad experience with cloud platforms.
  • Experience implementing NIST 800-63 levels of assurance.

Benefits & conditions

$125,310 - $185,640 annually

$125,310 - $153,444 annually for 393.1

$151,620 - $185,640 annually for 393.2, * Included in 2026 Best Places to Work by Glassdoor!

  • Flexible Benefits Package
  • 401(k)
  • Relocation Assistance
  • Education Reimbursement Program
  • Flexible schedules (*depending on project needs)
  • Our values - visit https://www.llnl.gov/inclusion/our-values

About the company

Join us and make YOUR mark on the World!

Lawrence Livermore National Laboratory (LLNL) has turned bold ideas into world-changing impact advancing science and technology to strengthen U.S. security and promote global stability.

Our mission spans four critical national security areas nuclear deterrence, threat preparedness, energy security, and multi-domain defense empowering teams to take on the toughest challenges of today and tomorrow. With a culture built on innovation and operational excellence, LLNL is a place where your expertise can make a real impact.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.clearancejobs.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:35 min

Setting up passwordless federated identity configuring OpenID Connect patterns

Marcel Lupo · LIVE

1:52 min

Identifying environments that require strict credential management

Moritz Johner · WWC 2023

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · WWC Europe 2026

2:22 min

Adapting OpenID Connect for decentralized data sharing

Adam Larter Adam Larter · WWC 2024

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · WWC Europe 2026

Videos

See all

Related articles

See all