Principal Identity System Engineer

Sanford Health
United States
5 days ago
Apply on dejobs.org
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
8 years minimum
Compensation
$102,960.0 - $169,520.0
Working hours
Regular working hours
Job source

Tech stack

Active Directory Authentication Protocols Cloud Computing Security CompTIA Security+ Cyber Security Identity and Access Management OpenID Public Key Infrastructure Zero Trust Network Access Security Assertion Markup Language (SAML) Information Technology

Job description

The Principle Identity Systems Engineer is responsible for setting strategy and designing secure enterprise identity and access management infrastructure that enables reliable authentication, authorization, and access management across hybrid environments. Engineers in this family ensure that users, systems, and applications are authenticated, authorized, and protected in alignment with security standards, regulatory requirements, and business needs. The Principal Identity Systems Engineer is a senior technical leader responsible for setting the vision and driving enterprise-wide strategies for identity platforms across on-premises and cloud environments. This role defines and champions the IAM roadmap, establishes architectural standards for hybrid identity, Zero Trust, and cloud integrations, and collaborates closely with executives, architects, and security leadership to ensure alignment with business objectives and regulatory requirements. The Principal Identity Systems Engineer leads modernization efforts around Active Directory, Entra ID, PKI, and authentication services while evaluating emerging technologies to strengthen enterprise identity security. Core responsibilities include architecting domain and forest structures, overseeing hybrid identity synchronization, enforcing secure authentication protocols, and automating access governance, provisioning, and privileged access management. This role also monitors and enhances KRIs to proactively identify risks, conducts expert-level troubleshooting and root cause analysis, and provides guidance on audit and compliance initiatives. In addition, the Principal Identity Systems Engineer mentors senior and lead engineers, develops standards and playbooks, and represents identity services as a strategic enabler of secure, scalable business operations. Balancing deep technical execution with enterprise strategy, this position ensures the identity ecosystem is resilient, future-ready, and integral to the organization’s long-term security posture.

Requirements

This role requires deep technical expertise in Active Directory, Entra ID, authentication protocols, Identity Governance Administration (IGA), Privileged Access Management (PAM) and PKI with a strong focus on information security, compliance, strong problem-solving skills, a security-first mindset, and least-privilege enforcement. The Principal Identity Systems Engineer ensures the organization’s identity platforms are resilient, scalable, and secure to support business operations and protect sensitive data. The Principal Identity Systems Engineer will work closely with cross-functional IT, application, and security teams to ensure alignment with business objectives, regulatory requirements, and industry best practices., Bachelor’s degree required, in lieu of education, leadership may consider an Associate’s Degree plus 3 years of applicable experience in computer science or related field.

Minimum of 8 years applicable work experience required. Including but not limited to:

  • Supporting Active Directory, Domain Services, Hybrid Identities, & Entra ID
  • Implementing SSO/MFA workflows using SAML 2.0 and/or OIDC
  • Maintaining Public Key Infrastructure (PKI)
  • Supporting Identity Lifecycle & Access Governance workflows and technical integrations
  • Implementation of information security standards and procedures including HIPAA and PCI
  • Expert knowledge of Cloud security principles

One or more security certifications (CISSP, CISA, CISM, Security+, CEH, etc.) are required

Benefits & conditions

Sanford offers an attractive benefits package for qualifying full-time and part-time employees. Depending on eligibility, a variety of benefits include health insurance, dental insurance, vision insurance, life insurance, a 401(k) retirement plan, work/life balance benefits, and a generous time off package to maintain a healthy home-work balance. For more information about Total Rewards, visit https://sanfordcareers.com/benefits .

About the company

Sanford Health, the largest rural health system in the United States, is dedicated to transforming the health care experience and providing access to world-class health care in America’s heartland.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on dejobs.org
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:35 min

Setting up passwordless federated identity configuring OpenID Connect patterns

Marcel Lupo · LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

1:45 min

Evolution from manual setups to automated monolith deployments

Axel Barbier · World Congress 2023

5:21 min

Protecting infrastructure with the shared responsibility model

Mustafa Toroman · World Congress 2023

2:22 min

Adapting OpenID Connect for decentralized data sharing

Adam Larter Adam Larter · World Congress 2024

2:52 min

Implementing IAM with Keycloak and OpenID Connect

Thomas Südbröcker · LIVE

Videos

See all

Related articles

See all