Summary
AARP is a nonprofit organization dedicated to empowering people 50 and older and their families. The Microsoft Entra ID Engineer II works with cross-functional teams to translate business requirements into technical specifications, develop identity and authentication solutions, troubleshoot issues, and support platform lifecycle strategy and continuous improvement.
Responsibilities
- Establishes a technical roadmap for the platform and/or capability strategy and lifecycle that considers value-based outcomes, costs to maintain, supportability, and performance
- Ensures sound integration, data, security, and business architecture design throughout all stages within the platform and/or capability lifecycle
- Provides rapid delivery and development of technical solutions that align with business and/or platform desired outcomes
- Troubleshoots and resolves technical issues related to platform or capability systems, solutions, and services
- Innovates and drives continuous improvements of implementation methodology and technical service offerings based on customer/employee experiences or other enterprise objectives/outcomes
- Participates in a Community of Interest for engineers across all capability and platform teams to share information and strengthen understanding of business needs and technology-based business solutions
- Develops and maintains deep technical knowledge and expertise related to domain area systems, solutions, services, and applications
Skills
- 5+ years of hands-on experience managing Microsoft identity and network services, including Dynamic Host Configuration Protocol (DHCP) and Domain Name System (DNS) services with Microsoft and Infoblox solutions, as well as Secure DNS and content filtering services with Cisco Umbrella and Fortinet FortiGate, for large-scale enterprises with a variety of endpoints (e.g., laptops, servers, networking equipment, IoT devices, etc.)
- 3+ years of hands-on experience engineering and administering Microsoft Entra ID (formerly Azure AD), including Entra tenant configuration, identity and access management, Microsoft 365 Multi-Factor Authentication (MFA), Conditional Access Policies, Enterprise Applications, Single Sign-On (SSO), application registration, and integration with on-premises Active Directory; experience with Privileged Access Management (PAM) solutions such as CyberArk is preferred
- Demonstrated ability to troubleshoot complex Microsoft Entra ID authentication and identity issues, including SSO failures, Conditional Access, MFA, application integration, identity synchronization, and hybrid authentication; experience with SAML, OpenID Connect, OAuth, and other modern authentication protocols is highly desired
- Ability to lead and execute iterative migration of on-premises Active Directory environments to Microsoft Entra ID, including hybrid identity configurations, Microsoft Entra Connect/Cloud Sync, and cloud-only identity models
- Demonstrated proficiency in DevSecOps practices by designing and implementing API-driven automation for the complete user lifecycle, from onboarding through offboarding
- Demonstrated experience with assessing and documenting existing Active Directory and Entra ID dependencies, including users, groups, service accounts, GPOs, applications, authentication methods, and identity lifecycle processes, and developing migration and modernization strategies
- Demonstrated experience with designing, implementing, and supporting Microsoft Entra ID architecture, including tenant configuration, domain integration, identity lifecycle management, Enterprise Applications, SSO, Conditional Access, MFA, application registration, and integration between on-premises Active Directory, Microsoft Entra ID and Microsoft Defender
- Familiarity with Jira, Confluence, and ServiceNow tools for collaboration and managing identity engineering work, incidents, and technical projects
- Familiarity with cloud computing (e.g., AWS, Azure, GCP), with hands-on experience supporting Microsoft Azure and Microsoft Entra ID environments preferred
- Regular and reliable job attendance
- Effective verbal and written communication skills
- Exhibit respect and understanding of others to maintain professional relationships
- Independent judgement in evaluation options to make sound decisions
- Home office environment with the ability to work effectively surrounded by moderate home environment noise - (Telework)
- Experience with Privileged Access Management (PAM) solutions such as CyberArk is preferred
- Experience with SAML, OpenID Connect, OAuth, and other modern authentication protocols is highly desired
- Hands-on experience supporting Microsoft Azure and Microsoft Entra ID environments preferred
Qualifications
Must Haves
- 5+ years of hands-on experience managing Microsoft identity and network services, including Dynamic Host Configuration Protocol (DHCP) and Domain Name System (DNS) services with Microsoft and Infoblox solutions, as well as Secure DNS and content filtering services with Cisco Umbrella and Fortinet FortiGate, for large-scale enterprises with a variety of endpoints (e.g., laptops, servers, networking equipment, IoT devices, etc.)
- 3+ years of hands-on experience engineering and administering Microsoft Entra ID (formerly Azure AD), including Entra tenant configuration, identity and access management, Microsoft 365 Multi-Factor Authentication (MFA), Conditional Access Policies, Enterprise Applications, Single Sign-On (SSO), application registration, and integration with on-premises Active Directory; experience with Privileged Access Management (PAM) solutions such as CyberArk is preferred
- Demonstrated ability to troubleshoot complex Microsoft Entra ID authentication and identity issues, including SSO failures, Conditional Access, MFA, application integration, identity synchronization, and hybrid authentication; experience with SAML, OpenID Connect, OAuth, and other modern authentication protocols is highly desired
- Ability to lead and execute iterative migration of on-premises Active Directory environments to Microsoft Entra ID, including hybrid identity configurations, Microsoft Entra Connect/Cloud Sync, and cloud-only identity models
- Demonstrated proficiency in DevSecOps practices by designing and implementing API-driven automation for the complete user lifecycle, from onboarding through offboarding
- Demonstrated experience with assessing and documenting existing Active Directory and Entra ID dependencies, including users, groups, service accounts, GPOs, applications, authentication methods, and identity lifecycle processes, and developing migration and modernization strategies
- Demonstrated experience with designing, implementing, and supporting Microsoft Entra ID architecture, including tenant configuration, domain integration, identity lifecycle management, Enterprise Applications, SSO, Conditional Access, MFA, application registration, and integration between on-premises Active Directory, Microsoft Entra ID and Microsoft Defender
- Familiarity with Jira, Confluence, and ServiceNow tools for collaboration and managing identity engineering work, incidents, and technical projects
- Familiarity with cloud computing (e.g., AWS, Azure, GCP), with hands-on experience supporting Microsoft Azure and Microsoft Entra ID environments preferred
- Regular and reliable job attendance
- Effective verbal and written communication skills
- Exhibit respect and understanding of others to maintain professional relationships
- Independent judgement in evaluation options to make sound decisions
- Home office environment with the ability to work effectively surrounded by moderate home environment noise - (Telework)
Nice to Haves
- experience with Privileged Access Management (PAM) solutions such as CyberArk is preferred
- experience with SAML, OpenID Connect, OAuth, and other modern authentication protocols is highly desired
- hands-on experience supporting Microsoft Azure and Microsoft Entra ID environments preferred
Benefits
- 401(k)
- 100% company-funded pension plan
- Health, dental, and vision plans
- Life insurance
- Paid time off including company and individual holidays, vacation, sick, caregiving, and parental leave
- Performance-based recognition
- Peer-based recognition
- Tuition reimbursement
- Remote/telework arrangement