
Staff Cloud Identity Platform Engineer
Posted 10 hours ago

Posted 10 hours ago
This is a fully remote position, open to applicants in Michigan.
• Design, configure, implement, and manage Microsoft Entra ID capabilities for workforce and application identities.
• Implement Microsoft Entra External ID functionalities for external users, partners, and application experiences.
• Integrate applications and services utilizing OAuth 2.0, OpenID Connect, SAML, and other secure identity standards.
• Configure and support single sign-on, multifactor authentication, Conditional Access, role-based access control, privileged access, identity governance, and access reviews.
• Develop secure methodologies for application onboarding, directory synchronization, service principals, managed identities, workload access, and identity lifecycle processes.
• Define and manage service-level indicators and objectives for identity platforms.
• Establish reliability practices, including error budgets, availability targets, dependency mapping, capacity planning, resiliency testing, and operational health reviews.
• Apply Azure infrastructure fundamentals to identity platform engineering.
• Build observability through metrics, logs, traces, synthetic transactions, dashboards, alerting, and identity-specific security and reliability signals.
• Monitor platform health, investigate alerts, troubleshoot authentication and authorization problems, and engage in incident response and on-call duties.
• Lead or assist in incident triage, service restoration, stakeholder communications, root-cause analysis, and blameless post-incident evaluations.
• Identify recurring incidents, manual processes, and operational inefficiencies; automate or redesign them.
• Automate identity and cloud platform tasks using PowerShell, Azure CLI, Microsoft Graph, Bicep, Terraform, or similar technologies.
• Contribute to infrastructure-as-code, continuous integration and delivery, automated testing, policy-as-code, progressive delivery, change validation, and safe rollback practices.
• Design and validate high-availability, failover, recovery, and business continuity frameworks.
• Maintain runbooks, playbooks, service documentation, troubleshooting guides, architecture records, and operational readiness checklists.
• Collaborate with cybersecurity, infrastructure, application, architecture, privacy, compliance, and product teams.
• Evaluate Microsoft capabilities, third-party solutions, and emerging identity patterns.
• Participate in design reviews, reliability assessments, technical planning, and engineering knowledge-sharing initiatives.
• Bachelor’s degree in computer science, information technology, cybersecurity, engineering, or a related field, or equivalent experience.
• A minimum of five years of experience in identity and access management, cloud engineering, cybersecurity, infrastructure, software engineering, SRE, or a related technical discipline.
• Practical experience with Microsoft Entra ID.
• Familiarity with Microsoft Entra External ID or a comparable identity platform for customers, partners, or external users.
• Working knowledge of Azure infrastructure principles, including subscriptions, networking, Key Vault, monitoring, logging, resiliency, and governance.
• Experience in translating security, reliability, and application needs into identity architecture, configurations, integrations, or engineering solutions.
• Background in supporting production services, encompassing monitoring, alerting, troubleshooting, incident response, change management, root-cause analysis, and service reliability practices.
• Understanding of SRE concepts such as SLIs, SLOs, error budgets, incident management, post-incident reviews, automation, toil reduction, and continuous improvement.
• Solid grasp of identity security principles, least privilege, separation of duties, zero-trust concepts, and secure integration techniques.
• Experience with scripting, automation, APIs, infrastructure as code, or policy as code.
• Capability to evaluate operational risk, prioritize reliability enhancements, and make informed technical decisions during incidents.
• Proficiency in communicating effectively with both technical and non-technical stakeholders.
• Preferred: experience with AWS and/or Google Cloud Platform identity, security, infrastructure, or platform services.
• Preferred: experience with AWS IAM, AWS Organizations, AWS KMS, Amazon Cognito, Google Cloud IAM, Google Cloud Identity, Google Cloud KMS, or similar services.
• Preferred: experience defining service health metrics, SLOs, error budgets, operational readiness criteria, or reliability scorecards.
• Preferred: experience with identity governance, entitlement management, privileged identity management, access reviews, and joiner-mover-leaver processes.
• Preferred: experience with application modernization, API security, directory synchronization, Microsoft Graph, or identity automation.
• Preferred: experience with customer identity and access management.
• Preferred: experience with DevOps, continuous integration and delivery, automated testing, infrastructure as code, policy as code, progressive delivery, or automated rollback.
• Preferred: familiarity with platform observability, security analytics, logging, synthetic monitoring, identity-related threat detection, and service dependency mapping.
• Preferred: experience with resiliency testing, disaster recovery, capacity planning, performance engineering, or recovery-time and recovery-point objectives.
• Preferred: Microsoft certifications such as Identity and Access Administrator Associate, Azure Administrator Associate, Cybersecurity Architect Expert, or comparable credentials.
• Preferred: experience designing or operating identity platforms for large, complex, or highly regulated enterprises.
• Bonus potential based on company, job level, and individual performance.
• Medical insurance.
• Dental insurance.
• Vision insurance.
• Health Savings Account.
• Flexible Spending Accounts.
• Retirement savings plan.
• Sickness and accident benefits.
• Life insurance.
• Paid vacation and holidays.
• Tuition assistance programs.
• Employee assistance program.
• GM vehicle discounts.
• Relocation benefits for qualifying candidates.
Keypath Education
NVIDIA
OpenNebula
Get handpicked remote jobs straight to your inbox weekly.