Principal Identity and Access Management Engineer

U.S. Navy
Vienna, United States
7 days ago

Role details

Contract type
Internship / Graduate position
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
7 years minimum
Working hours
Shift work
Job source

Tech stack

Active Directory Active Directory Federation Services Domain Controllers Authentication Protocols Microsoft Azure Cyber Security Identity and Access Management Kerberos (Protocol) OpenID Public Key Infrastructure Windows PowerShell Role-Based Access Control
+6 more
Azure Active Directory Zero Trust Network Access Security Assertion Markup Language (SAML) YAML Information Technology Golang

Job description

The Principal IAM Engineer is a technical resource with intermediate or master level skills in the architecture, design, configuration, and management of Active Directory, Microsoft Entra, and modern authentication services., * Identity provider administration, design and maintenance for Active Directory Federation Services, Strata Identity Orchestrator, Active Directory Lightweight Directory Services, Entra ID

  • Identity federation implementation (with internal/external workforce applications.
  • Apply engineering principles into the design and enhancement of new and existing systems.
  • Ensure the security and integrity of system and product solutions including compliance with Navy Federal and Information Security principles and practices.
  • Present clear, organized, and concise information to all audiences through a variety of media to enable effective business decisions.
  • Perform engineering tasks and assignments in support of business needs.
  • Perform engineering technology research, procurement, deployment, and configuration for new and modified systems.
  • Perform other duties as assigned.

Requirements

  • Bachelor’s Degree in Information Technology or the equivalent combination of education, training or experience
  • 7-10 years of experience in identity security engineering
  • Expert knowledge of identity security best practices surrounding account separation, JIT, least privilege, zero trust
  • Hands-on experience designing and managing Active Directory infrastructure. As evidenced by at least 1 current certification (Microsoft Certified Solutions Associate, or Microsoft Certified Solutions Expert with a focus on server infrastructure.) or the equivalent experience and training.
  • Solid understanding of design and implementation of modern authentication protocols, such as SAML, OIDC, FIDO, and PIV.
  • Strong foundational knowledge of Active Directory infrastructure, protocols and authentication patterns: Domain Controllers, Group Policy, Sites/Services Topology, Replication, Kerberos
  • Experience with the following:
  • Microsoft Entra suite including:
  • Conditional Access
  • Azure SSO leveraging SAML/OIDC, Service Principals, and Agentic Identities
  • Management of directory identity in Entra and M365, leveraging security policies, PIM, RBAC
  • Identity Governance
  • Defender for Identity
  • Strata (Maverics) Identity Orchestration or similar
  • Active Directory Federation Services
  • Active Directory Lightweight Directory Services (AD-LDS)
  • Microsoft Enterprise PKI leveraging OCSP
  • Azure AD Connect

Desired Qualifications

  • Strong identity security mindset with a proven ability to design and operate identity solutions that prioritize security, compliance, and long-term resilience
  • Advanced PowerShell Scripting techniques. Knowledge of Golang and YAML.

About the company

Navy Federal provides much more than a job. We provide a meaningful career experience, including a culture that is energized, engaged and committed; and fierce appreciation for our teams, who are rewarded with highly competitive pay and generous benefits and perks.

Our approach to careers is simple yet powerful: Make our mission your passion.

FORTUNE 100 Best Companies to Work For 2026

Yello and WayUp Top 100 Internship Programs 2025

Computerworld Best Places to Work in IT 2026

Most Loved Workplace - America’s Top Most Loved Workplaces 2025

2025 PEOPLE Companies That Care

Newsweek Most Trustworthy Companies in America 2026

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:35 min

Setting up passwordless federated identity configuring OpenID Connect patterns

Marcel Lupo · LIVE

1:35 min

Centralizing configuration logic with native YAML block references

Matthieu Vincent Matthieu Vincent · Europe 2026 Virtual

1:08 min

Building solutions with open source GoLang infrastructure tools

Jad Wahab · LIVE

1:30 min

Operating developer-friendly identity infrastructure using Affinity Elements

Adam Larter Adam Larter · WWC 2024

2:00 min

Introduction to YAML syntax and basic formatting

Chris Ayers · LIVE

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · WWC 2022

Videos

See all

Related articles

See all