Principal Identity and Access Management Engineer
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+6 more
Job description
The Principal IAM Engineer is a technical resource with intermediate or master level skills in the architecture, design, configuration, and management of Active Directory, Microsoft Entra, and modern authentication services., * Identity provider administration, design and maintenance for Active Directory Federation Services, Strata Identity Orchestrator, Active Directory Lightweight Directory Services, Entra ID
- Identity federation implementation (with internal/external workforce applications.
- Apply engineering principles into the design and enhancement of new and existing systems.
- Ensure the security and integrity of system and product solutions including compliance with Navy Federal and Information Security principles and practices.
- Present clear, organized, and concise information to all audiences through a variety of media to enable effective business decisions.
- Perform engineering tasks and assignments in support of business needs.
- Perform engineering technology research, procurement, deployment, and configuration for new and modified systems.
- Perform other duties as assigned.
Requirements
- Bachelor’s Degree in Information Technology or the equivalent combination of education, training or experience
- 7-10 years of experience in identity security engineering
- Expert knowledge of identity security best practices surrounding account separation, JIT, least privilege, zero trust
- Hands-on experience designing and managing Active Directory infrastructure. As evidenced by at least 1 current certification (Microsoft Certified Solutions Associate, or Microsoft Certified Solutions Expert with a focus on server infrastructure.) or the equivalent experience and training.
- Solid understanding of design and implementation of modern authentication protocols, such as SAML, OIDC, FIDO, and PIV.
- Strong foundational knowledge of Active Directory infrastructure, protocols and authentication patterns: Domain Controllers, Group Policy, Sites/Services Topology, Replication, Kerberos
- Experience with the following:
- Microsoft Entra suite including:
- Conditional Access
- Azure SSO leveraging SAML/OIDC, Service Principals, and Agentic Identities
- Management of directory identity in Entra and M365, leveraging security policies, PIM, RBAC
- Identity Governance
- Defender for Identity
- Strata (Maverics) Identity Orchestration or similar
- Active Directory Federation Services
- Active Directory Lightweight Directory Services (AD-LDS)
- Microsoft Enterprise PKI leveraging OCSP
- Azure AD Connect
Desired Qualifications
- Strong identity security mindset with a proven ability to design and operate identity solutions that prioritize security, compliance, and long-term resilience
- Advanced PowerShell Scripting techniques. Knowledge of Golang and YAML.
About the company
Navy Federal provides much more than a job. We provide a meaningful career experience, including a culture that is energized, engaged and committed; and fierce appreciation for our teams, who are rewarded with highly competitive pay and generous benefits and perks.
Our approach to careers is simple yet powerful: Make our mission your passion.
FORTUNE 100 Best Companies to Work For 2026
Yello and WayUp Top 100 Internship Programs 2025
Computerworld Best Places to Work in IT 2026
Most Loved Workplace - America’s Top Most Loved Workplaces 2025
2025 PEOPLE Companies That Care
Newsweek Most Trustworthy Companies in America 2026
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on www.dice.comGood distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
The Best X (Twitter) Accounts for Developers
Dev Digest 210: AI Agents Are Go! Is MCP Dead? LLMs Crack Anonymity
Everything a Developer Needs to Know About MCP with Neo4j