LEAD IT SPECIALIST - SR. IT SPECIALIST - Cloud Identity, PKI, and AI Specialist

Southwest Research Institute
San Antonio, TX, United States
27 days ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
3 years minimum
Working hours
Regular working hours
Job source

Tech stack

Active Directory Active Directory Federation Services Artificial Intelligence Amazon Web Services Microsoft Azure Cloud Computing Identity and Access Management Public Key Infrastructure Role-Based Access Control Azure Active Directory Azure Machine Learning Enterprise Software Applications
+3 more
Cloud Platform System AI Platforms Information Technology

Job description

  • Manage and enhance internal Public Key Infrastructure (PKI), ADFS (Active Directory Federation Services), and Certificate Lifecycle Management (e.g. Keyfactor Command) to maintain secure, reliable access to enterprise resources.
  • Design and implement secure identity and access patterns for Azure and AWS services, including Azure OpenAI, Azure AI Hub/Foundry, Azure Cognitive Services, and AWS Bedrock.
  • Lead the design, configuration, and maintenance of Entra ID (Azure AD) app registrations, service principals, and RBAC models that provide controlled, auditable access to cloud and AI workloads.
  • Collaborate across IT teams (Cloud, Security, Networking, Applications, Help Desk) to resolve complex issues related to AD, Entra ID, ADFS, PKI, certificates, and cloud identity.
  • Drive best practices for identity and access management, Azure and AWS infrastructure governance, and operational scalability across cloud and on-premises environments.
  • Maintain strong change control discipline and keep supporting documentation up to date.

Daily and Monthly Responsibilities:

  • Manage and support internal PKI and certificate lifecycle processes, including: Administration of CAs, OCSP/CRL endpoints, and certificate trust chains.
  • Configuration and operation of Keyfactor Command certificate discovery, issuance, renewal, and revocation.
  • Support and maintain identity and federation services, including Active Directory (user and group management, roles, delegation), Entra ID app registrations, service principals, Conditional Access, RBAC, ADFS configuration and integration with internal and external applications.
  • Collaborate with IT teams to resolve helpdesk tickets related to: AD and Entra ID authentication and authorization issues.
  • ADFS sign-on/federation problems and claims troubleshooting.
  • Certificate deployment, trust, and lifecycle problems impacting applications and services.
  • Implement and maintain secure access for Azure and AWS AI platforms, including: App registrations and security group-based access controls for Azure OpenAI, Azure AI Hub/Foundry, and Azure Cognitive Services.
  • IAM roles, policies, and network/security configuration for AWS service.
  • Maintain documentation of identity architectures, PKI designs, AI enablement patterns, and change records for audits and future engineers, and research and propose improvements to identity, PKI, certificate lifecycle, and AI enablement, including automation and governance tooling.

Requirements

  • Requires a Bachelors degree in Information Technology or related degree field with relevant experience. In lieu of a Bachelors degree, 10 years of professional level experience, a high school education or equivalent with related certifications will be considered.
  • Related Microsoft certifications are preferred.
  • 6 years: Hands-on experience managing enterprise identity platforms, including: Active Directory domain services. Entra ID (Azure AD) app registrations, service principals, and Conditional Access. ADFS design, configuration, and support.
  • 3 years: Managing a PKI environment and certificate lifecycle, including: Internal CA infrastructure, OCSP/CRL, and certificate templates.
  • Demonstrated experience designing and securing access for Azure and/or AWS solutions, including at least some of the following: Azure OpenAI, Azure AI Hub/Foundry, Azure Cognitive Services. AWS Bedrock or similar AWS AI/ML services.
  • Strong understanding of identity and access management best practices, including: Role-based access control (RBAC) in Azure and AWS. Least-privilege design, MFA, and Conditional Access. Governance and operational scalability in cloud environments.
  • A valid/clear driver’s license is required.

Special Requirements:

Applicant selected will be subject to a government security investigation and must meet eligibility requirements for access to classified information. Applicant must be a U.S. citizen.

About the company

Our team, the Cloud Services team within the Information Technology Center, is responsible for EntraID (formerly Azure)/M365 cloud services and Active Directory for the Enterprise. The team provides support and implementation services to the entire organization’s IT infrastructure.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:34 min

Pivoting careers into specialized platform engineering roles

Xavier Portilla Edo · LIVE

2:36 min

Choosing between managed AI platforms and custom governance

Péter Farkas Péter Farkas · Europe 2026 Virtual

1:06 min

Outline of free tools for Microsoft Azure

Radu Vunvulea Radu Vunvulea · World Congress 2022

2:27 min

Introduction to WebAssembly in a cloud computing context

Edo Edo · World Congress 2024

3:03 min

Career evolution in data engineering and AI platforms

Maria Apazoglou · Coffee With Developers

2:12 min

Navigating technical clarity as a global black belt

Chris Heilmann +2 · LIVE

Videos

See all

Related articles

See all