Identity & Access Architect - Hybrid & Growth

Rib Software
Madrid, Spain
4 days ago
Apply on www.buscojobs.com.es
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Shift work
Languages
English, Spanish

Tech stack

Microsoft Windows Active Directory Microsoft Azure Cyber Security Identity and Access Management OpenID Windows PowerShell Role-Based Access Control Azure Active Directory Security Assertion Markup Language (SAML) Server Administration Working Model 2D
+2 more
Data Logging Office365

Job description

As an Identity & Directory Services Engineer (m/f/d), you are responsible for the stable, secure, and standardized operation of our identity and directory services.You manage Active Directory (AD DS), Microsoft Entra ID (including hybrid scenarios/synchronization), and Group Policies (GPOs), and you further develop global standards for identities and access models.You ensure that our organization can operate securely, efficiently, and in a future?proof manner, making you a key component of our IT security and productivity strategy.Key Responsibilities Operation and continuous development of AD DS, Entra ID, and Hybrid Identity (stability, troubleshooting, standards) GPO management: design, hardening, maintenance, and structured rollout of policies Identity lifecycle (Join/Move/Leave): provisioning and deprovisioning, groups/roles/permissions, including regular reviews Security & compliance: implementation of least privilege, separate admin accounts, MFA, and traceable logging Automation & documentation (e.G., PowerShell/Graph) and close collaboration with Security, Infrastructure, HR/People, and application owners Essential Requirements Several years of experience with Active Directory and GPOs (design, hardening, troubleshooting) Hands?on experience with Microsoft Entra ID (users/groups/roles, RBAC, access models) Solid understanding of Identity & Access Management (lifecycle, permission and role concepts, least privilege) Good knowledge of server and Azure administration Experience in the Microsoft 365 / O365 environment Structured, solution?oriented working style Very good Spanish (minimum C1) and good English (minimum B2) Advantageous Experience with Privileged Access Management (PAM) and SSO fundamentals (SAML/OIDC) Experience working in global teams or matrix organizations and with standardizing identity data Benefits Structured start: individual onboarding, organized networking.Goodies: life cover and health insurance and Company Share Ownership Program (WESOP).Modern working model: trust?based working hours, flexible working hours, possibility of hybrid working.Career development/prospects: team or role?based development/training, individual development/training, national and international career prospects within the RIB Group or Schneider Electric.RIB podrá exigir a todos los candidatos seleccionados que superen un control de experiencia y antecedentes antes de empezar a trabajar.La verificación de precedentes se llevará a cabo de acuerdo con las leyes locales y puede, sujeto a dichas leyes, incluir prueba de nivel educativo, verificación de historial de empleo, prueba de autorización de trabajo, antecedentes penales, verificación de identidad, verificación de crédito.Ciertos puestos que tratan con datos personales sensibles y/o de terceros pueden implicar la comprobación de criterios adicionales.RIB es una empresa que ofrece igualdad de oportunidades.Somos y estamos comprometidos a ser un empleador ejemplar con una cultura inclusiva, desarrollando un entorno de trabajo en el que todos nuestros empleados son tratados con dignidad y respeto.Valoramos la diversidad y la experiencia que personas de diferentes orígenes aportan a nuestro negocio.#J-*****-Ljbffr

Requirements

You manage Active Directory (AD DS), Microsoft Entra ID (including hybrid scenarios/synchronization), and Group Policies (GPOs), and you further develop global standards for identities and access models. You ensure that our organization can operate securely, efficiently, and in a future?proof manner, making you a key component of our IT security and productivity strategy. Key Responsibilities Operation and continuous development of AD DS, Entra ID, and Hybrid Identity (stability, troubleshooting, standards) GPO management: design, hardening, maintenance, and structured rollout of policies Identity lifecycle (Join/Move/Leave): provisioning and deprovisioning, groups/roles/permissions, including regular reviews Security & compliance: implementation of least privilege, separate admin accounts, MFA, and traceable logging Automation & documentation (e.G., PowerShell/Graph) and close collaboration with Security, Infrastructure, HR/People, and application owners Essential Requirements Several years of experience with Active Directory and GPOs (design, hardening, troubleshooting) Hands?on experience with Microsoft Entra ID (users/groups/roles, RBAC, access models) Solid understanding of Identity & Access Management (lifecycle, permission and role concepts, least privilege) Good knowledge of server and Azure administration Experience in the Microsoft 365 / O365 environment Structured, solution?oriented working style Very good Spanish (minimum C1) and good English (minimum B2) Advantageous Experience with Privileged Access Management (PAM) and SSO fundamentals (SAML/OIDC) Experience working in global teams or matrix organizations and with standardizing identity data Benefits Structured start: individual onboarding, organized networking.

Benefits & conditions

Goodies: life cover and health insurance and Company Share Ownership Program (WESOP). Modern working model: trust?based working hours, flexible working hours, possibility of hybrid working. Career development/prospects: team or role?based development/training, individual development/training, national and international career prospects within the RIB Group or Schneider Electric. RIB podrá exigir a todos los candidatos seleccionados que superen un control de experiencia y antecedentes antes de empezar a trabajar. La verificación de precedentes se llevará a cabo de acuerdo con las leyes locales y puede, sujeto a dichas leyes, incluir prueba de nivel educativo, verificación de historial de empleo, prueba de autorización de trabajo, antecedentes penales, verificación de identidad, verificación de crédito. Ciertos puestos que tratan con datos personales sensibles y/o de terceros pueden implicar la comprobación de criterios adicionales. RIB es una empresa que ofrece igualdad de oportunidades. Somos y estamos comprometidos a ser un empleador ejemplar con una cultura inclusiva, desarrollando un entorno de trabajo en el que todos nuestros empleados son tratados con dignidad y respeto. Valoramos la diversidad y la experiencia que personas de diferentes orígenes aportan a nuestro negocio. #J-*****-Ljbffr

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.buscojobs.com.es
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:10 min

Exposing sensitive information through partial search logs

Dennis Schulz Dennis Schulz +1 · World Congress 2026 Europe

4:35 min

Setting up passwordless federated identity configuring OpenID Connect patterns

Marcel Lupo · LIVE

1:30 min

Operating developer-friendly identity infrastructure using Affinity Elements

Adam Larter Adam Larter · World Congress 2024

1:56 min

Discovering incidents using logs, metrics, and traces

Nele Uhlemann · World Congress 2023

2:52 min

Implementing IAM with Keycloak and OpenID Connect

Thomas Südbröcker · LIVE

2:08 min

Managing complex structures and corporate guidelines

Alexandra Petri · World Congress 2023

Videos

See all

Related articles

See all