Authentication Engineer
Propertyvalue Lighthouse Technology Services
Buffalo, NY, United States
16 days ago
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Apply on www.dice.com
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Contract type
Temporary to permanent
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
6 years minimum
Compensation
$145,600.0 - $156,000.0
Working hours
Regular working hours
Job source
Tech stack
Active Directory
Application Programming Interfaces (APIs)
User Authentication
Authentication Protocols
Microsoft Azure
Multi-Factor Authentication
Identity and Access Management
Intrusion Detection and Prevention
Kerberos (Protocol)
Lightweight Directory Access Protocols (LDAP)
OAuth
OpenID
+11 more
Windows PowerShell
Azure Active Directory
Kusto Query Language
Zero Trust Network Access
Security Assertion Markup Language (SAML)
Cloud Platform System
Falcon Platform
Tools for Reporting
Restful APIs
Splunk
Api Management
Job description
Lighthouse Technology Services is partnering with our client to fill their Authentication Engineer specializing in AD and Entra position! This is a 12 month contract with potential to extend and will be hybrid in Buffalo, NY.
This role will be a W2 employee of Lighthouse Technology Services. No C2C or subcontracting arrangements will be considered.
What You’ll Be Doing:
- Design and implement strategic authentication frameworks and standards for enterprise Active Directory and Microsoft Entra ID environments
- Lead automation initiatives to modernize identity services, including Conditional Access policy development and authentication hardening
- Architect hybrid identity solutions leveraging Entra Connect, ensuring secure synchronization between on-premises AD and cloud environments
- Develop advanced PowerShell scripts and Microsoft Graph API integrations to streamline identity lifecycle management and operational processes
- Build and maintain monitoring solutions using Splunk and KQL for identity threat detection, incident investigation, and compliance reporting
- Engineer Zero Trust security controls and Privileged Access Management frameworks to protect Tier-0 administration
- Support incident management and troubleshooting for complex authentication and directory services issues
- Collaborate with cybersecurity teams to evaluate and remediate identity vulnerabilities in regulated financial services environment
- Create app registrations and service principals within Entra ID while managing certificate-based and passwordless authentication implementations
- Document technical standards, configuration patterns, and governance processes for audit and compliance requirements
Requirements
- 6+ years of hands-on experience engineering both Active Directory and Microsoft Entra ID in enterprise environments
- Proven track record of strategic identity engineering beyond operational tasks, with demonstrated ability to design standards and modernization initiatives
- Deep expertise in hybrid identity architecture including Entra Connect, Conditional Access, MFA, and authentication protocols (SAML, OAuth, OIDC)
- Advanced PowerShell scripting and automation skills, with experience in Microsoft Graph API and REST API integration
- Strong understanding of Zero Trust principles, Tier-0 security controls, and Identity Governance frameworks
- Experience with monitoring and analytics tools such as Splunk, KQL, and CrowdStrike for identity threat detection
- Solid knowledge of authentication technologies including Kerberos, LDAP/LDAPS, and certificate-based authentication
- Background working in regulated environments with compliance frameworks such as SOX, NIST, or FFIEC preferred
- Active Directory and Azure certifications highly preferred
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on www.dice.com
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
AJ
Austin Joy
over 4 years ago
DC
Daniel Cranney
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
7 months ago
CH
Chris Heilmann
The top 200 passwords of 2024 can be cracked in less than a second
almost 2 years ago
EM
Eli McGarvie
The Best X (Twitter) Accounts for Developers
about 3 years ago
MH
Michael Hunger
Everything a Developer Needs to Know About MCP with Neo4j
about 1 year ago
IK
Igor Khokhriakov
How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again
about 1 month ago