> Markdown version of [/jobs/ext/3052850-identity-engineer](https://www.wearedevelopers.com/jobs/ext/3052850-identity-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Identity Engineer - **Company:** American Automobile Association, Inc. - **Location:** Costa Mesa, CA, United States - **Salary:** $109,500.0 - $146,200.0 - **Contract:** Permanent contract - **Skills:** Active Directory, Amazon Web Services, Microsoft Azure, Business Software, Cloud Computing, Cloud Computing Security, Cloud Engineering, Configuration Management, Cyber Security, Information Systems, DevOps, Multi-Factor Authentication, Fault Tolerance, Identity and Access Management, Python (Programming Language), Key Management, Lightweight Directory Access Protocols (LDAP), OAuth, Public Key Infrastructure, Windows PowerShell, Role-Based Access Control, Openid Connect, Azure Active Directory, Ansible, Zero Trust Network Access, Security Assertion Markup Language (SAML), Software Engineering, Cyberark, Infrastructure Automation Frameworks, Terraform - **Published:** September 24, 2026 - **Apply:** https://ace.wd5.myworkdayjobs.com/careers/job/Costa-Mesa-CA/Identity-Engineer_JR202639314 ## About the Role * Experience working within large, complex technology environments and leading efforts to address identity, access control, and security challenges. * Strong understanding of Identity and Access Management concepts, including authentication, authorization, federation, lifecycle management, and governance. * Hands-on experience with LDAP, Active Directory, Entra ID (Azure AD), SAML, OAuth, OpenID Connect, and related identity technologies. * Experience designing and implementing Role-Based Access Control (RBAC), entitlement management, role engineering, role mining, and access provisioning processes. * Experience developing automation and scripting solutions using PowerShell, Python, or similar technologies. * Knowledge of cloud platforms such as Microsoft Azure and AWS, including cloud-native identity services. * Experience with infrastructure automation and configuration management platforms such as Ansible, Terraform, or similar technologies. * Knowledge of Public Key Infrastructure (PKI), certificate lifecycle management, Multi-Factor Authentication (MFA), and privileged access solutions. * Experience supporting highly available, scalable, and fault-tolerant systems in enterprise environments. * Strong communication, collaboration, and problem-solving skills with the ability to work effectively across technical and business teams. Preferred Experience * Identity Governance and Administration (IGA) platforms. * Privileged Access Management (PAM) solutions such as CyberArk. * Zero Trust architecture and security frameworks. * CI/CD pipelines, DevOps practices, and Infrastructure as Code methodologies. * Cloud-native security and identity solutions. * Enterprise certificate services and secrets management. ## Description As an Identity Engineer within Auto Club Enterprise's Enterprise Identity Engineering (EIE) team, you will design, implement, automate, and support enterprise identity platforms that enable secure, seamless, and scalable access to critical business applications and infrastructure. You will play a key role in strengthening ACE's security posture by delivering identity governance, authentication, authorization, privileged access management, and directory services solutions. As part of the Information Systems organization, you will collaborate closely with Cybersecurity, Infrastructure, Cloud Engineering, Application Development, and Architecture teams to advance ACE's identity-first security strategy and support a modern Zero Trust environment. The Enterprise Identity Engineering team is responsible for the design, operation, automation, and continuous improvement of enterprise identity services that reduce risk, improve user experience, and enable secure business outcomes. The team focuses on delivering resilient, scalable, and highly available identity solutions across on-premises, cloud, and hybrid environments while driving automation and operational excellence. Your work will directly support mission-critical services that empower and protect ACE's workforce, partners, and members. What You'll Do * Design, engineer, and support enterprise identity and access management solutions, including authentication, authorization, identity governance, and privileged access management. * Develop and maintain automation solutions that improve operational efficiency, reduce manual effort, and strengthen security controls. * Implement and manage identity integrations using industry standards such as SAML, OAuth, OpenID Connect, LDAP, and SCIM. * Support enterprise directory services, cloud identity platforms, and hybrid identity architectures. * Design and manage solutions utilizing Public Key Infrastructure (PKI), Multi-Factor Authentication (MFA), certificate services, and privileged access technologies. * Collaborate with cybersecurity teams to strengthen access controls, reduce risk, and align with regulatory and security requirements. * Participate in Agile delivery practices, contributing to the design, testing, deployment, and operational support of identity services and platforms. * Monitor, troubleshoot, and improve the reliability, performance, and resiliency of identity infrastructure and services. * Partner with business and technology stakeholders to deliver secure, scalable, and user-centered identity capabilities. * Contributes to the implementation of Zero Trust security principles through modern identity and access management practices. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Delegating the chores of authenticating users to Keycloak](https://www.wearedevelopers.com/videos/1558-delegating-the-chores-of-authenticating-users-to-keycloak) - [Dev & Test in the Cloud? Deploy your cloud environments with Ansible & Terraform](https://www.wearedevelopers.com/videos/1607-dev-test-in-the-cloud-deploy-your-cloud-environments-with-ansible-terraform) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [#90DaysOfDevOps - The DevOps Learning Journey](https://www.wearedevelopers.com/videos/548-90daysofdevops-the-devops-learning-journey) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [The Best X (Twitter) Accounts for Developers](https://www.wearedevelopers.com/magazine/294-the-best-x-twitter-accounts-for-developers) - [Navigating the AI Shift](https://www.wearedevelopers.com/magazine/629-navigating-the-ai-shift) - [Everything a Developer Needs to Know About MCP with Neo4j](https://www.wearedevelopers.com/magazine/604-everything-a-developer-needs-to-know-about-mcp-with-neo4j)