> Markdown version of [/jobs/ext/3014747-identity-access-architect-hybrid-growth](https://www.wearedevelopers.com/jobs/ext/3014747-identity-access-architect-hybrid-growth). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Identity & Access Architect - Hybrid & Growth - **Company:** Rib Software - **Location:** Madrid, Spain - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Active Directory, Microsoft Azure, Cyber Security, Identity and Access Management, OpenID, Windows PowerShell, Role-Based Access Control, Azure Active Directory, Security Assertion Markup Language (SAML), Server Administration, Working Model 2D, Data Logging, Office365 - **Published:** September 20, 2026 - **Apply:** https://www.buscojobs.com.es/identity-access-architect-hybrid-growth-en-madrid-ID-371942093 ## About the Role You manage Active Directory (AD DS), Microsoft Entra ID (including hybrid scenarios/synchronization), and Group Policies (GPOs), and you further develop global standards for identities and access models. You ensure that our organization can operate securely, efficiently, and in a future?proof manner, making you a key component of our IT security and productivity strategy. Key Responsibilities Operation and continuous development of AD DS, Entra ID, and Hybrid Identity (stability, troubleshooting, standards) GPO management: design, hardening, maintenance, and structured rollout of policies Identity lifecycle (Join/Move/Leave): provisioning and deprovisioning, groups/roles/permissions, including regular reviews Security & compliance: implementation of least privilege, separate admin accounts, MFA, and traceable logging Automation & documentation (e.G., PowerShell/Graph) and close collaboration with Security, Infrastructure, HR/People, and application owners Essential Requirements Several years of experience with Active Directory and GPOs (design, hardening, troubleshooting) Hands?on experience with Microsoft Entra ID (users/groups/roles, RBAC, access models) Solid understanding of Identity & Access Management (lifecycle, permission and role concepts, least privilege) Good knowledge of server and Azure administration Experience in the Microsoft 365 / O365 environment Structured, solution?oriented working style Very good Spanish (minimum C1) and good English (minimum B2) Advantageous Experience with Privileged Access Management (PAM) and SSO fundamentals (SAML/OIDC) Experience working in global teams or matrix organizations and with standardizing identity data Benefits Structured start: individual onboarding, organized networking. ## Description As an Identity & Directory Services Engineer (m/f/d), you are responsible for the stable, secure, and standardized operation of our identity and directory services.You manage Active Directory (AD DS), Microsoft Entra ID (including hybrid scenarios/synchronization), and Group Policies (GPOs), and you further develop global standards for identities and access models.You ensure that our organization can operate securely, efficiently, and in a future?proof manner, making you a key component of our IT security and productivity strategy.Key Responsibilities Operation and continuous development of AD DS, Entra ID, and Hybrid Identity (stability, troubleshooting, standards) GPO management: design, hardening, maintenance, and structured rollout of policies Identity lifecycle (Join/Move/Leave): provisioning and deprovisioning, groups/roles/permissions, including regular reviews Security & compliance: implementation of least privilege, separate admin accounts, MFA, and traceable logging Automation & documentation (e.G., PowerShell/Graph) and close collaboration with Security, Infrastructure, HR/People, and application owners Essential Requirements Several years of experience with Active Directory and GPOs (design, hardening, troubleshooting) Hands?on experience with Microsoft Entra ID (users/groups/roles, RBAC, access models) Solid understanding of Identity & Access Management (lifecycle, permission and role concepts, least privilege) Good knowledge of server and Azure administration Experience in the Microsoft 365 / O365 environment Structured, solution?oriented working style Very good Spanish (minimum C1) and good English (minimum B2) Advantageous Experience with Privileged Access Management (PAM) and SSO fundamentals (SAML/OIDC) Experience working in global teams or matrix organizations and with standardizing identity data Benefits Structured start: individual onboarding, organized networking.Goodies: life cover and health insurance and Company Share Ownership Program (WESOP).Modern working model: trust?based working hours, flexible working hours, possibility of hybrid working.Career development/prospects: team or role?based development/training, individual development/training, national and international career prospects within the RIB Group or Schneider Electric.RIB podrá exigir a todos los candidatos seleccionados que superen un control de experiencia y antecedentes antes de empezar a trabajar.La verificación de precedentes se llevará a cabo de acuerdo con las leyes locales y puede, sujeto a dichas leyes, incluir prueba de nivel educativo, verificación de historial de empleo, prueba de autorización de trabajo, antecedentes penales, verificación de identidad, verificación de crédito.Ciertos puestos que tratan con datos personales sensibles y/o de terceros pueden implicar la comprobación de criterios adicionales.RIB es una empresa que ofrece igualdad de oportunidades.Somos y estamos comprometidos a ser un empleador ejemplar con una cultura inclusiva, desarrollando un entorno de trabajo en el que todos nuestros empleados son tratados con dignidad y respeto.Valoramos la diversidad y la experiencia que personas de diferentes orígenes aportan a nuestro negocio.#J-*****-Ljbffr ## Related Videos - [Develop enterprise-ready applications for Microsoft Teams with Azure resources on modern web technologies](https://www.wearedevelopers.com/videos/187-develop-enterprise-ready-applications-for-microsoft-teams-with-azure-resources-on-modern-web-technologies) - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Delegating the chores of authenticating users to Keycloak](https://www.wearedevelopers.com/videos/1558-delegating-the-chores-of-authenticating-users-to-keycloak) - [Build Delightful Mobile Experiences with Kotlin, Realm, and Atlas Device Sync](https://www.wearedevelopers.com/videos/694-build-delightful-mobile-experiences-with-kotlin-realm-and-atlas-device-sync) - [What if your HR software adapted to you, not the other way around?](https://www.wearedevelopers.com/videos/100259-what-if-your-hr-software-adapted-to-you-not-the-other-way-around) ## Related Articles - [Spanish Business Culture and Etiquette](https://www.wearedevelopers.com/magazine/353-spanish-business-culture-and-etiquette) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [Where To Find Software Engineering Jobs](https://www.wearedevelopers.com/magazine/396-where-to-find-software-engineering-jobs)