Active Directory / Entra ID / IAM Engineer

Hybrid in New York, NY, US • Posted 1 day ago • Updated 1 day ago
Contract Independent
Contract W2
12 Months
No Travel Required
Hybrid
$65 - $70/hr
Fitment

Dice Job Match Score™

🤯 Applying directly to the forehead...

Job Details

Skills

  • Active Directory
  • Access Control
  • Microsoft Entra
  • Identity Management
  • SIEM
  • Windows PowerShell
  • SailPoint
  • OAuth
  • Python

Summary

Active Directory / Entra ID / IAM Engineer
Location: NYC, Jersey City, or Pittsburgh (2-3 days onsite)
Duration: 12-month engagement
 
Seeking an experienced Active Directory / Entra ID / IAM Engineer to support enterprise identity and access management services across production environments. This role is focused on maintaining and enhancing on-premises and cloud-based identity infrastructure, with deep emphasis on Active Directory, Microsoft Entra ID, hybrid identity operations, authentication services, and privileged access controls.
Key Responsibilities
  • Provide day-to-day engineering and operational support for enterprise Active Directory and Entra ID environments supporting large-scale global user populations.
  • Administer, harden, and support on-premises Active Directory infrastructure including domain controller build and maintenance, DNS (SRV records), LDAP, Kerberos, NTLM, GPO, OU structure, replication, and directory health.
  • Support Microsoft Entra ID administration including Conditional Access, MFA, Identity Protection, Privileged Identity Management (PIM), app registrations, and service principal governance.
  • Maintain and support hybrid identity environments including AD Connect configuration, sync operations, failover between data center instances, and PowerShell-based sync troubleshooting.
  • Administer PKI infrastructure including certificate authority management, certificate lifecycle, LDAP signing, and certificate installation on domain controllers and services.
  • Support authentication and access solutions including SSO, federation (SAML, OIDC, OAuth2), MFA, and privileged access controls.
  • Perform enterprise application onboarding and integration with identity platforms; troubleshoot authentication, authorization, and provisioning issues.
  • Execute platform hardening aligned with Microsoft cumulative hardening guidance and enterprise security policy — including SMB signing, LDAP signing, Kerberos enforcement, and legacy protocol disablement.
  • Support audit, compliance, and vulnerability remediation activities; respond to security findings from scanning tools such as Rapid7, Nessus, or CrowdStrike.
  • Partner with infrastructure, cybersecurity, and application teams to deliver identity-related changes and service improvements.
  • Develop and maintain runbooks, operational documentation, and support procedures; train follow-the-sun operations teams on repeatable workflows.
  • Participate in on-call rotations, after-hours change windows, and incident response including major incident bridge management.
  • Use PowerShell, Python, and Microsoft Graph / Entra APIs to automate operational tasks and improve efficiency.
Required Skills & Experience
  • 8+ years of hands-on experience administering and supporting enterprise Active Directory — including building, hardening, and directly owning domain controllers.
  • Knowledge of AD fundamentals: Kerberos and NTLM authentication protocols, DNS (SRV records), LDAP and LDAP signing, GPO design, replication, forest/domain architecture, and DC security hardening.
  • Strong experience with Microsoft Entra ID including Conditional Access, MFA, Identity Protection, PIM, app registrations, and service principal governance.
  • Hands-on experience with AD Connect in high-availability configurations including multi-data-center failover, sync troubleshooting, and PowerShell-based sync commands.
  • Experience supporting hybrid identity environments across on-premises Active Directory and Microsoft Entra ID.
  • Working knowledge of PKI infrastructure including certificate authority administration, LDAP signing, and certificate use cases on domain controllers.
  • Experience with IAM and PAM platforms such as SailPoint, Okta, and CyberArk.
  • Proficiency in PowerShell; Python and Microsoft Graph API experience preferred.
  • Experience with enterprise SIEM platforms (Splunk preferred) for log analysis, dashboard use, and incident triage.
 
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: 91070970
  • Position Id: 8985001
  • Posted 1 day ago
Contact the job poster
SK

Shubham Kanojiya

Recruiter @ Simple Solutions
Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

Jersey City, New Jersey

Today

Easy Apply

Full-time, Part-time, Third Party, Contract

Hybrid in Newark, New Jersey

Yesterday

Easy Apply

Full-time

Depends on Experience

New York, New York

28d ago

Easy Apply

Contract

50 - 60

Hybrid in New York, New York

Today

Easy Apply

Contract

$70 - $90

Search all similar jobs