Microsoft Entra ID Engineer II

AARP
Washington, DC, United States
2 days ago
Apply on careers.aarp.org
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Working hours
Regular working hours

Tech stack

Microsoft Windows Active Directory Amazon Web Services Microsoft Antivirus Application Integration Architecture Confluence JIRA User Authentication Authentication Protocols Microsoft Azure Cloud Computing Dynamic Host Configuration Protocol
+20 more
Domain Name System (DNS) Multi-Factor Authentication Identity and Access Management Networking Hardware Network Service OAuth Openid Connect Azure Active Directory Security Assertion Markup Language (SAML) Single Sign-On Google Cloud Enterprise Software Applications Cyberark Web Filtering Fortinet Api Design Network Server Devsecops Cisco Servicenow

Job description

The Engineer II works with cross-functional teams and customers to understand business requirements and translates into technical specifications. They discover the true requirements underlying feature requests and recommend alternative technical approaches. The Engineer II partners with cross-functional technical teams to launch projects and provide ongoing technical support. They collaborate with management to identify opportunities to streamline technology processes and develop new procedures that support the business unit/department. Responsibilities

  • Establishes a technical roadmap for the platform and/or capability strategy and lifecycle that considers value-based outcomes, costs to maintain, supportability, and performance.
  • Ensures sound integration, data, security, and business architecture design throughout all stages within the platform and/or capability lifecycle.
  • Provides rapid delivery and development of technical solutions that align with business and/or platform desired outcomes.
  • Troubleshoots and resolves technical issues related to platform or capability systems, solutions, and services.
  • Innovates and drives continuous improvements of implementation methodology and technical service offerings based on customer/employee experiences or other enterprise objectives/outcomes.
  • Participates in a Community of Interest for engineers across all capability and platform teams to share information and strengthen understanding of business needs and technology-based business solutions.
  • Develops and maintains deep technical knowledge and expertise related to domain area systems, solutions, services, and applications.

Requirements

  • 5+ years of hands-on experience managing Microsoft identity and network services, including Dynamic Host Configuration Protocol (DHCP) and Domain Name System (DNS) services with Microsoft and Infoblox solutions, as well as Secure DNS and content filtering services with Cisco Umbrella and Fortinet FortiGate, for large-scale enterprises with a variety of endpoints (e.g., laptops, servers, networking equipment, IoT devices, etc.).
  • 3+ years of hands-on experience engineering and administering Microsoft Entra ID (formerly Azure AD), including Entra tenant configuration, identity and access management, Microsoft 365 Multi-Factor Authentication (MFA), Conditional Access Policies, Enterprise Applications, Single Sign-On (SSO), application registration, and integration with on-premises Active Directory; experience with Privileged Access Management (PAM) solutions such as CyberArk is preferred.
  • Demonstrated ability to troubleshoot complex Microsoft Entra ID authentication and identity issues, including SSO failures, Conditional Access, MFA, application integration, identity synchronization, and hybrid authentication; experience with SAML, OpenID Connect, OAuth, and other modern authentication protocols is highly desired.
  • Ability to lead and execute iterative migration of on-premises Active Directory environments to Microsoft Entra ID, including hybrid identity configurations, Microsoft Entra Connect/Cloud Sync, and cloud-only identity models.
  • Demonstrated proficiency in DevSecOps practices by designing and implementing API-driven automation for the complete user lifecycle, from onboarding through offboarding.
  • Demonstrated experience with assessing and documenting existing Active Directory and Entra ID dependencies, including users, groups, service accounts, GPOs, applications, authentication methods, and identity lifecycle processes, and developing migration and modernization strategies.
  • Demonstrated experience with designing, implementing, and supporting Microsoft Entra ID architecture, including tenant configuration, domain integration, identity lifecycle management, Enterprise Applications, SSO, Conditional Access, MFA, application registration, and integration between on-premises Active Directory, Microsoft Entra ID and Microsoft Defender.
  • Familiarity with Jira, Confluence, and ServiceNow tools for collaboration and managing identity engineering work, incidents, and technical projects.
  • Familiarity with cloud computing (e.g., AWS, Azure, GCP), with hands-on experience supporting Microsoft Azure and Microsoft Entra ID environments preferred.
  • Participate in a rotational on-call schedule approximately once per month to provide support and respond to urgent identity and authentication issues as needed., * Regular and reliable job attendance
  • Effective verbal and written communication skills
  • Exhibit respect and understanding of others to maintain professional relationships
  • Independent judgement in evaluation options to make sound decisions
  • Home office environment with the ability to work effectively surrounded by moderate home environment noise - (Telework)

Benefits & conditions

AARP offers a competitive compensation and benefits package including a 401(k); 100% company-funded pension plan; health, dental, and vision plans; life insurance; paid time off to include company and individual holidays, vacation, sick, caregiving, and parental leave; performance-based and peer-based recognition and tuition reimbursement.

About the company

AARP is the nation’s largest nonprofit, nonpartisan organization dedicated to empowering people 50 and older to choose how they live as they age. With a nationwide presence, AARP strengthens communities and advocates for what matters most to the more than 100 million Americans 50-plus and their families: health and financial security, and personal fulfillment. AARP also works for individuals in the marketplace by sparking new solutions and allowing carefully chosen, high-quality products and services to carry the AARP name. As a trusted source for news and information, AARP produces the nation’s largest-circulation publications, AARP The Magazine and the AARP Bulletin.

Information Technology Services is responsible for AARP enterprise-wide technology and information security functions. Services range from infrastructure design and operations, system and software lifecycle implementations, enabling the mobile workforce and protecting AARP network, systems and data. A variety of technologies and practices are used including cloud computing, automation, artificial intelligence and machine learning within highly collaborative Agile teams.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on careers.aarp.org
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:05 min

Integrating an assistant application with Jira software

Felix Augenstein · LIVE

1:29 min

Expanding practical knowledge with community sandboxes and resources

Stuart Clark · LIVE

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

1:20 min

Identifying multi-disciplinary talent for developer experience engineering roles

Hazal Mestci +1 · Coffee With Developers

5:47 min

Integrating user stories and test automation via Jira tools

Christoph Ruggenthaler · LIVE

4:35 min

Setting up passwordless federated identity configuring OpenID Connect patterns

Marcel Lupo · LIVE

Videos

See all

Related articles

See all