
Identity Engineer β Tier 2
Posted Sep 4

Posted Sep 4
This is a fully remote position, open to applicants in United States.
β’ Conduct daily administration and support for client hybrid identity environments that encompass both on-premises Active Directory and Microsoft Entra ID.
β’ Manage the provisioning and de-provisioning of user and group accounts in on-premises Active Directory, ensuring correct OU placement.
β’ Implement and uphold established Joiner/Mover/Leaver identity lifecycle automation, confirming completion and addressing any exceptions.
β’ Execute password resets and account unlocks for on-premises AD and synchronized Entra ID identities.
β’ Assist with multifactor authentication enrollment and resolve common authentication failures.
β’ Diagnose Group Policy application issues using approved policies, identifying precedence, scope, and replication problems without altering or creating GPOs.
β’ Oversee and address Entra Connect synchronization errors and sync health alerts, resolving routine issues and escalating configuration-level challenges.
β’ Allocate licenses and perform standard attribute updates within Entra ID.
β’ Address Severity 2 and 3 identity service interruptions, such as sync delays and login failures.
β’ Forward suspected security incidents to the designated cybersecurity team in accordance with the incident response runbook.
β’ Request, utilize, and release just-in-time privileged access in line with client PAM procedures while maintaining precise elevated-activity records.
β’ Cease activities that require client authorization, including sync configuration and topology changes, GPO/OU/schema modifications, Conditional Access adjustments, elevated role assignments, PIM/PAM configuration, trust and federation modifications, and tenant-level authentication method changes.
β’ Ensure accurate documentation and adhere to change management protocols within client environments.
β’ Report to the Director of Operations under the functional guidance of the client's designated identity function owner.
β’ 3β5 years of experience administering Active Directory in a production setting, covering account lifecycle, OU and group management, and Group Policy troubleshooting.
β’ Practical experience with hybrid identity, particularly Entra Connect or Azure AD Connect synchronization, including sync error triage, attribute flow, and knowledge of how on-premises changes propagate to the cloud.
β’ Proficient understanding of Microsoft Entra ID administration, including licensing, attribute management, and authentication methods.
β’ Hands-on experience supporting multifactor authentication and Conditional Access from an end-user troubleshooting perspective.
β’ Familiarity with Privileged Identity Management and just-in-time access models.
β’ Capability to work effectively without standing administrative rights.
β’ Understanding of identity lifecycle automation with the ability to validate and remediate automated provisioning workflows.
β’ Skill in differentiating between an identity service disruption and a potential identity compromise, with immediate escalation for the latter.
β’ Experience providing support in a managed services or multi-client environment, including adherence to ticket queue discipline, SLA compliance, and change management.
β’ Proficiency in PowerShell for directory administration and reporting.
β’ Preferred Microsoft certifications such as SC-300 or equivalent experience.
β’ Ability to manage client and company data responsibly.
β’ Commitment to following information security policies.
β’ Willingness to complete necessary security training.
β’ Promptly report suspected incidents or policy violations.
β’ Maintain accurate documentation and follow change management procedures.
β’ Required security training.
β’ Remote work arrangement.
Northrop Grumman
Thermo Systems
Thermo Systems
Thermo Systems
Get handpicked remote jobs straight to your inbox weekly.