> Markdown version of [/jobs/ext/1928696-principal-identity-and-access-management-engineer](https://www.wearedevelopers.com/jobs/ext/1928696-principal-identity-and-access-management-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Principal Identity and Access Management Engineer - **Company:** U.S. Navy - **Location:** Vienna, United States - **Experience:** Expert - **Contract:** Internship / Graduate position - **Skills:** Active Directory, Active Directory Federation Services, Domain Controllers, Authentication Protocols, Microsoft Azure, Cyber Security, Identity and Access Management, Kerberos (Protocol), OpenID, Public Key Infrastructure, Windows PowerShell, Role-Based Access Control, Azure Active Directory, Zero Trust Network Access, Security Assertion Markup Language (SAML), YAML, Information Technology, Golang - **Published:** August 5, 2026 - **Apply:** https://www.dice.com/job-detail/21abe3e0-66ff-470e-a827-4cf251b6aac7 ## About the Role * Bachelor's Degree in Information Technology or the equivalent combination of education, training or experience * 7-10 years of experience in identity security engineering * Expert knowledge of identity security best practices surrounding account separation, JIT, least privilege, zero trust * Hands-on experience designing and managing Active Directory infrastructure. As evidenced by at least 1 current certification (Microsoft Certified Solutions Associate, or Microsoft Certified Solutions Expert with a focus on server infrastructure.) or the equivalent experience and training. * Solid understanding of design and implementation of modern authentication protocols, such as SAML, OIDC, FIDO, and PIV. * Strong foundational knowledge of Active Directory infrastructure, protocols and authentication patterns: Domain Controllers, Group Policy, Sites/Services Topology, Replication, Kerberos * Experience with the following: * Microsoft Entra suite including: * Conditional Access * Azure SSO leveraging SAML/OIDC, Service Principals, and Agentic Identities * Management of directory identity in Entra and M365, leveraging security policies, PIM, RBAC * Identity Governance * Defender for Identity * Strata (Maverics) Identity Orchestration or similar * Active Directory Federation Services * Active Directory Lightweight Directory Services (AD-LDS) * Microsoft Enterprise PKI leveraging OCSP * Azure AD Connect Desired Qualifications * Strong identity security mindset with a proven ability to design and operate identity solutions that prioritize security, compliance, and long-term resilience * Advanced PowerShell Scripting techniques. Knowledge of Golang and YAML. ## Description The Principal IAM Engineer is a technical resource with intermediate or master level skills in the architecture, design, configuration, and management of Active Directory, Microsoft Entra, and modern authentication services., * Identity provider administration, design and maintenance for Active Directory Federation Services, Strata Identity Orchestrator, Active Directory Lightweight Directory Services, Entra ID * Identity federation implementation (with internal/external workforce applications. * Apply engineering principles into the design and enhancement of new and existing systems. * Ensure the security and integrity of system and product solutions including compliance with Navy Federal and Information Security principles and practices. * Present clear, organized, and concise information to all audiences through a variety of media to enable effective business decisions. * Perform engineering tasks and assignments in support of business needs. * Perform engineering technology research, procurement, deployment, and configuration for new and modified systems. * Perform other duties as assigned. ## Related Videos - [CI/CD with Github Actions](https://www.wearedevelopers.com/videos/856-ci-cd-with-github-actions) - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Develop enterprise-ready applications for Microsoft Teams with Azure resources on modern web technologies](https://www.wearedevelopers.com/videos/187-develop-enterprise-ready-applications-for-microsoft-teams-with-azure-resources-on-modern-web-technologies) - [Go with the Flow: Stop the Leaks Before Your Memory's a Waterfall!](https://www.wearedevelopers.com/videos/100073-go-with-the-flow-stop-the-leaks-before-your-memory-s-a-waterfall) - [Delegating the chores of authenticating users to Keycloak](https://www.wearedevelopers.com/videos/1558-delegating-the-chores-of-authenticating-users-to-keycloak) - [Retooling and refactoring - an investment in people.](https://www.wearedevelopers.com/videos/371-retooling-and-refactoring-an-investment-in-people) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The Best X (Twitter) Accounts for Developers](https://www.wearedevelopers.com/magazine/294-the-best-x-twitter-accounts-for-developers) - [Dev Digest 210: AI Agents Are Go! Is MCP Dead? LLMs Crack Anonymity](https://www.wearedevelopers.com/magazine/709-dev-digest-210-ai-agents-are-go-is-mcp-dead-llms-crack-anonymity) - [Everything a Developer Needs to Know About MCP with Neo4j](https://www.wearedevelopers.com/magazine/604-everything-a-developer-needs-to-know-about-mcp-with-neo4j) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)