> Markdown version of [/jobs/ext/1809467-senior-iam-engineer-entra-id](https://www.wearedevelopers.com/jobs/ext/1809467-senior-iam-engineer-entra-id). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior IAM Engineer - Entra ID - **Company:** Charles Schwab Inc. - **Location:** Southlake, TX, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Active Directory, Software System Penetration Testing, Cyber Security, Domain Name System (DNS), Identity and Access Management, Intrusion Detection and Prevention, OAuth, OpenID, Public Key Infrastructure, Windows PowerShell, Role-Based Access Control, Azure Active Directory, Zero Trust Network Access, Security Assertion Markup Language (SAML), Cloud Platform System, Okta, Cyberark, CIS Benchmarks, SailPoint, Terraform, Devsecops - **Published:** July 16, 2026 - **Apply:** https://dejobs.org/x/x/5049EAD79A3A4E63AF8390F7FE0132B9/job/ ## About the Role * 8+ years of experience in Identity & Access Management, architecture or engineering. * Deep expertise in: * Microsoft Entra ID (Azure AD), Conditional Access, Identity Protection, Entra Governance * Active Directory design, replication, DNS, GPO, PKI, delegation models * SSO protocols: OAuth2 , OIDC , SAML , WS-Fed * Identity lifecycle automation and provisioning * Zero Trust architecture principles * Strong knowledge of MFA, passwordless, risk-based policies, and authentication flows. * Experience securing hybrid identity using Entra Connect, federation services, and cloud-only patterns. * Expertise building Terraform IaC resources and guardrails for identity services through reusable modules and automated CI/CD pipelines. * Proficiency with PowerShell or automation frameworks. * Strong understanding of IAM risk management, audit requirements, and regulatory standards., * Microsoft certifications: SC-300 , SC-100 , AZ-305 , or equivalent. * Experience with: * Privileged Access Workstations (PAW) * Microsoft Identity Manager (MIM) or other ILM solutions * Conditional Access advanced configurations and automation * Enterprise-scale identity consolidation and domain migration projects * Modern IAM stacks (SailPoint, CyberArk, Okta) * Background security architecture, threat modeling, or penetration testing related to identity systems. ## Description We are seeking a highly experienced Senior IAM Engineer with strong architecture responsibility and deep expertise in Microsoft Entra ID , Active Directory , and modern Identity & Access Management (IAM) principles. This role operates in a large-scale, highly regulated enterprise environment and is responsible for driving enterprise-wide identity architecture, designing zero-trust-aligned access controls, modernizing hybrid identity environments, and delivering secure, scalable, and compliant identity solutions., Identity Architecture & Strategy * Design, implement, and maintain end-to-end Identity & Access Management architectures using Microsoft Entra ID and Active Directory. * Establish a long-term identity strategy aligned with business, security, and regulatory requirements. * Architect secure hybrid identity models including Entra Connect , cloud sync strategies, and identity lifecycle automation. * Drive adoption of Zero Trust identity principles , including continuous evaluation and least-privilege access. Microsoft Entra ID Expertise * Lead design and optimization of Conditional Access policies , authentication flows, MFA, passwordless strategies (FIDO2, Windows Hello Business), and identity protection. * Architect, standardize, and provide oversight for Entra ID Governance capabilities-PIM, access reviews, entitlement management, custom roles, and segregation of duties. * Oversee configuration of Entra applications, service principals, federations, SCIM provisioning, and SSO integrations (SAML/OIDC/OAuth2). Active Directory (AD) & Hybrid Identity * Design secure, resilient, and scalable Active Directory forests, domains, GPO structures , and privileged access boundaries. * Lead initiatives to modernize AD security posture (tiered administration models, privileged access isolation, delegated administration, and secure baselines). * Implement AD hardening, lifecycle management, group governance, and remediation of legacy dependencies. IAM Governance & Security * Develop identity standards, patterns, security baselines, and governance frameworks. * Ensure compliance with regulatory requirements such as SOX, HIPAA, GDPR, ISO 27001 , and internal audit controls. * Provide guidance for RBAC/ABAC models, identity lifecycle management, privileged access governance, and application onboarding. * Design identity controls that are auditable, measurable, and automatable, supporting internal risk assessments and regulatory compliance. * Collaborate with cloud platform and DevSecOps teams to integrate identity controls into cloud landing zones, CI/CD pipelines, and enterprise architectures. * Partner with security operations to integrate identity telemetry, threat detection, and incident response workflows. Cross-Functional Collaboration * Work closely with Security Engineering, Application Owners, Cloud Platform Engineering & Architecture, and Infrastructure teams. * Provide architectural direction during acquisition integration, cloud migrations, and modernization projects. * Deliver architecture diagrams, roadmaps, threat models, and solution documentation. Thought Leadership * Drive IAM as a shared enterprise platform, balancing security, user experience, and operational resiliency. * Stay current with identity trends, Entra roadmap updates, and emerging threats. * Recommend continuous improvement opportunities across authentication, authorization, and identity governance. * Mentor engineers and guide best practices on identity design and operations. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Delegating the chores of authenticating users to Keycloak](https://www.wearedevelopers.com/videos/1558-delegating-the-chores-of-authenticating-users-to-keycloak) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The Best X (Twitter) Accounts for Developers](https://www.wearedevelopers.com/magazine/294-the-best-x-twitter-accounts-for-developers) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Everything a Developer Needs to Know About MCP with Neo4j](https://www.wearedevelopers.com/magazine/604-everything-a-developer-needs-to-know-about-mcp-with-neo4j) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers)