IT Systems Directory Services and Cloud Identity Specialist Senior

Modine Manufacturing Company
United States
7 days ago
Apply on diversityjobs.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
8 years minimum
Compensation
$93,000.0 - $163,000.0
Working hours
Regular working hours

Tech stack

Microsoft Access Active Directory Microsoft Azure Microsoft Online Services Business Software Software as a Service Cloud Computing Cyber Security Computer Engineering Dynamic Host Configuration Protocol DevOps Integrated Windows Authentication
+36 more
Domain Name System (DNS) Multi-Factor Authentication Microsoft Exchange Server Federated Identity Management Identity and Access Management Kerberos (Protocol) Log Analysis Windows Servers Network Virtualization OAuth OpenID Public Key Infrastructure Windows PowerShell Role-Based Access Control Azure Active Directory Cloud Services Migration Manager Zero Trust Network Access Security Assertion Markup Language (SAML) Microsoft SharePoint Single Sign-On Scripting Google Cloud Cloud Platform System Multi-Cloud Azure Powershell Technical Debt Infrastructure as Code (IaC) Information Technology Deployment Automation Bicep Graphql CIS Benchmarks Api Design Restful APIs Terraform

Job description

The Senior Directory Services & Cloud Identity Specialist serves as a senior-level technical authority and hands-on subject matter expert responsible for the architecture, security, lifecycle governance, and operational resilience of enterprise identity ecosystems and cloud infrastructure.

This role requires a proactive, highly autonomous go-getter who thrives in dynamic environments, takes immediate ownership of complex challenges, and actively identifies architectural gaps before they impact the business. Bridging hybrid Active Directory Domain Services (AD DS) and Microsoft Entra ID, this engineer will lead identity modernization, automate critical operational workflows via PowerShell and DevOps practices, manage Azure subscriptions and core SaaS platforms, and serve as the tier-3/4 escalation authority across enterprise collaboration and infrastructure services., + Hybrid Identity Architecture: Design, implement, optimize, and maintain enterprise Active Directory (AD DS), Azure AD Connect / Entra Cloud Sync, and Microsoft Entra ID across hybrid multi-domain and multi-tenant environments.

  • Access Federation & SSO: Architect and administer Single Sign-On (SSO), SAML 2.0 / OIDC integrations, Entra Application Proxy, and enterprise federation with third-party SaaS and line-of-business applications.
  • Identity Governance & Lifecycle: Implement and maintain automated user lifecycle provisioning (JML: Joiner/Mover/Leaver workflows), Entra ID Governance, Access Reviews, Privileged Identity Management (PIM), and dynamic role-based access control (RBAC).
  • Zero Trust & Security Posture: Define and enforce Conditional Access Policies, Multi-Factor Authentication (MFA), passwordless authentication mechanisms, and Active Directory Fine-Grained Password Policies to maintain a robust Zero Trust security posture.

  • Cloud Infrastructure & SaaS Management

*

  • Azure Subscription & Resource Governance: Administer enterprise Azure subscriptions, management groups, Resource Groups, Azure Policy, cost optimization, and virtual networking (VNets, NSGs, private endpoints).
  • SaaS Administration & Collaboration Support: Oversee tenant-level configurations, cross-tenant synchronization, security baselines, and escalated troubleshooting for Microsoft 365 services-with deep administrative focus on Microsoft Teams and SharePoint (Online & Hybrid/On-Premises).
  • Public Key Infrastructure (PKI): Oversee Microsoft Certificate Authority (AD CS), certificate lifecycle management, and secure enrollment services (NDES/SCEP).

  • DevOps Automation, Scripting & Initiative

*

  • Advanced PowerShell Automation: Build, maintain, and document production-grade PowerShell modules, automation runbooks, and API-driven scripts (Graph API, Azure CLI) to eliminate manual administration tasks and automate cross-platform syncs.
  • Continuous Improvement & Problem Discovery: Proactively identify legacy technical debt, performance bottlenecks, and security vulnerabilities across directory and cloud services without waiting for task assignment.
  • Infrastructure as Code (IaC): Drive modern automation practices utilizing ARM/Bicep templates or Terraform for repeatable Azure resource deployments.

  • Escalations, Collaboration & Mentorship

*

  • Tier 3/4 Escalation Authority: Serve as the definitive escalation tier for complex directory, authentication, sync, and M365 infrastructure issues, interfacing directly with Helpdesk, Local Tech Support, Infosec, and engineering teams.
  • Vendor & Project Leadership: Partner with external technology vendors, lead enterprise migration and divestiture initiatives, and author detailed technical documentation, architectural diagrams, and standard operating procedures (SOPs).
  • Technical Mentorship: Guide and upskill junior system administrators, desktop engineers, and support personnel., + Microsoft Certified: Identity and Access Administrator Associate (SC-300)
  • Microsoft Certified: Azure Administrator Associate (AZ-104)
  • Microsoft Certified: Cybersecurity Architect Expert (SC-100) or Azure Solutions Architect Expert (AZ-305)

Requirements

  • Experience: 8+ years of progressive engineering experience in enterprise Windows Server, Active Directory, and Microsoft Cloud / Identity ecosystems.
  • Directory & Cloud Identity: Deep, proven expertise in Active Directory Domain Services (AD DS), Group Policy (GPO), DNS/DHCP, Kerberos/NTLM authentication, and Microsoft Entra ID (Azure AD).
  • Scripting & Automation: Advanced proficiency in PowerShell scripting (including Graph PowerShell SDK, REST APIs, and background job handling) for large-scale enterprise administration.
  • Federation & IAM: Extensive hands-on experience configuring SSO, SAML, OAuth, Conditional Access, PIM, and SCIM-based identity provisioning.
  • Cloud Platform Governance: Practical administration experience with Microsoft Azure (Subscriptions, IAM/RBAC, Resource Governance, Networking, and Log Analytics/Sentinel).
  • Mindset & Initiative: Self-directed problem solver with a proven track record of wearing multiple hats, driving unassigned initiatives to completion, and navigating ambiguity in fast-paced enterprise environments.
  • Communication & Interpersonal Skills: Excellent written and verbal communication skills with the ability to articulate complex technical architectures to leadership and mentor operational support teams.

Preferred / “Nice to Have” Qualifications

  • Multi-Cloud & GCP Experience:

*

  • Hands-on administration or foundational experience with Google Cloud Platform (GCP), including Google Cloud IAM, Cloud Identity, and Workload Identity Federation with Microsoft Entra ID / Active Directory.
  • Familiarity with GCP Zero Trust access controls, Cloud Identity-Aware Proxy (IAP), and hybrid multi-cloud networking.

  • Enterprise Collaboration: Strong operational administration and migration experience with Microsoft Teams and SharePoint Online / Server (permissions, site architectures, and external sharing policies).
  • Migration & Coexistence Tools: Experience utilizing enterprise identity/mailbox migration platforms (e.g., Quest On Demand Migration / Migration Manager, BitTitan, or native cross-tenant sync).
  • Hybrid Messaging: Experience supporting hybrid Microsoft Exchange environments (Exchange Online and Exchange Server).
  • Industry Certifications (Highly Desirable), * Bachelor’s degree in Information Technology, Computer Science, Computer Engineering, or a related technical discipline (or equivalent relevant professional experience).

Benefits & conditions

  • Competitive health, dental & vision insurance coverage
  • Employee Assistance Program

After 90 days of continuous employment

  • Maternity Leave (12 weeks at 100% pay)

  • 8 weeks of short term disability leave paid at 100%
  • 4 weeks of paid parental leave paid at 100%

Paternity Leave (4 weeks at 100% pay)

Financial Benefits:

  • 401k Retirement plan and company paid match
  • Life Insurance
  • Health Savings Account (HSA) with employer contribution
  • Flexible Spending Accounts (FSA)
  • Short Term Disability (company paid)
  • Long Term Disability

Work-Life Balance:

  • Competitive time-off policies
  • Tuition Reimbursement

To view full benefits information:MyModine Benefits

Modine is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, veteran status, or any other characteristic protected by law. Modine provides a competitive benefit package, which could include paid vacation, short term disability, 401(k), health, dental, vision, life insurance, flex spending benefits, tuition reimbursement, Health Savings Account and much more. Human Resources will provide more detail upon your hiring., The salary range for this position is estimated in good faith to be $93,000-$163,000. The specific offer will depend on the candidate’s qualifications, experience, and other job-related considerations but will be within the stated range. Where required by applicable law, a general description of benefits and other compensation offered for this role is also provided or made available.

About the company

For more than 100 years, Modine has solved the toughest thermal management challenges for mission-critical applications. Our purpose of Engineering a Cleaner, Healthier World means we are always evolving our portfolio of technologies to provide the latest heating, cooling, and ventilation solutions. Through the hard work of more than 11,000 employees worldwide, our Climate Solutions and Performance Technologies segments advance our purpose with systems that improve air quality, reduce energy and water consumption, lower harmful emissions, enable cleaner running vehicles, and use environmentally friendly refrigerants. Modine is a global company headquartered in Racine, Wisconsin (U.S.), with operations in North America, South America, Europe, and Asia. For more information about Modine, visit modine.com.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on diversityjobs.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:34 min

Pivoting careers into specialized platform engineering roles

Xavier Portilla Edo · LIVE

4:35 min

Setting up passwordless federated identity configuring OpenID Connect patterns

Marcel Lupo · LIVE

2:56 min

Provisioning a secure container infrastructure with Bicep

Matthias Falkenberg +1 · World Congress 2022

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

2:24 min

Securing cloud deployments by utilizing OpenID Connect mapping

Chris Ayers · LIVE

Videos

See all

Related articles

See all