Authentication Engineer

Propertyvalue Lighthouse Technology Services
Buffalo, NY, United States
16 days ago
Apply on www.dice.com
Prepare application

Role details

Contract type
Temporary to permanent
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
6 years minimum
Compensation
$145,600.0 - $156,000.0
Working hours
Regular working hours
Job source

Tech stack

Active Directory Application Programming Interfaces (APIs) User Authentication Authentication Protocols Microsoft Azure Multi-Factor Authentication Identity and Access Management Intrusion Detection and Prevention Kerberos (Protocol) Lightweight Directory Access Protocols (LDAP) OAuth OpenID
+11 more
Windows PowerShell Azure Active Directory Kusto Query Language Zero Trust Network Access Security Assertion Markup Language (SAML) Cloud Platform System Falcon Platform Tools for Reporting Restful APIs Splunk Api Management

Job description

Lighthouse Technology Services is partnering with our client to fill their Authentication Engineer specializing in AD and Entra position! This is a 12 month contract with potential to extend and will be hybrid in Buffalo, NY.

This role will be a W2 employee of Lighthouse Technology Services. No C2C or subcontracting arrangements will be considered.

What You’ll Be Doing:

  • Design and implement strategic authentication frameworks and standards for enterprise Active Directory and Microsoft Entra ID environments
  • Lead automation initiatives to modernize identity services, including Conditional Access policy development and authentication hardening
  • Architect hybrid identity solutions leveraging Entra Connect, ensuring secure synchronization between on-premises AD and cloud environments
  • Develop advanced PowerShell scripts and Microsoft Graph API integrations to streamline identity lifecycle management and operational processes
  • Build and maintain monitoring solutions using Splunk and KQL for identity threat detection, incident investigation, and compliance reporting
  • Engineer Zero Trust security controls and Privileged Access Management frameworks to protect Tier-0 administration
  • Support incident management and troubleshooting for complex authentication and directory services issues
  • Collaborate with cybersecurity teams to evaluate and remediate identity vulnerabilities in regulated financial services environment
  • Create app registrations and service principals within Entra ID while managing certificate-based and passwordless authentication implementations
  • Document technical standards, configuration patterns, and governance processes for audit and compliance requirements

Requirements

  • 6+ years of hands-on experience engineering both Active Directory and Microsoft Entra ID in enterprise environments
  • Proven track record of strategic identity engineering beyond operational tasks, with demonstrated ability to design standards and modernization initiatives
  • Deep expertise in hybrid identity architecture including Entra Connect, Conditional Access, MFA, and authentication protocols (SAML, OAuth, OIDC)
  • Advanced PowerShell scripting and automation skills, with experience in Microsoft Graph API and REST API integration
  • Strong understanding of Zero Trust principles, Tier-0 security controls, and Identity Governance frameworks
  • Experience with monitoring and analytics tools such as Splunk, KQL, and CrowdStrike for identity threat detection
  • Solid knowledge of authentication technologies including Kerberos, LDAP/LDAPS, and certificate-based authentication
  • Background working in regulated environments with compliance frameworks such as SOX, NIST, or FFIEC preferred
  • Active Directory and Azure certifications highly preferred

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:35 min

Setting up passwordless federated identity configuring OpenID Connect patterns

Marcel Lupo · LIVE

1:30 min

Operating developer-friendly identity infrastructure using Affinity Elements

Adam Larter Adam Larter · World Congress 2024

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

2:22 min

Adapting OpenID Connect for decentralized data sharing

Adam Larter Adam Larter · World Congress 2024

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

Videos

See all

Related articles

See all