您是否渴望助力激动人心的先进电子领域的下一次飞跃?您是否希望跟我们一起解决难题,共同推动电子技术和互联科技的快速发展?那么,带着您的解决问题的能力、热情和创造力,与我们一起推动电子领域的下一次飞跃。
在启诺迪,我们不仅是先进电子和高科技领域材料及解决方案的全球领导者,更是一个紧密团结、充满激情、勇于挑战的团队。我们所有敬业的团队都致力于将尖端技术变为现实。我们重视具有前瞻性思维的挑战者、突破界限的开拓者以及各个部门的多元化视角,因为我们深知,我们在推动世界进步、造福全人类方面扮演着至关重要的角色。了解如何加入我们,开启或加速您的职业生涯。
Qnity is seeking a Directory Services Leader to lead and operate enterprise directory and identity services across Microsoft Active Directory, Microsoft Entra ID, hybrid identity, privileged access, and integration with Saviynt IGA and PAM.
This is a hands-on working manager role responsible for the reliability, security, governance, and continuous improvement of the identity platforms supporting Qnity users, endpoints, servers, applications, cloud services, manufacturing environments, and privileged access.
The Directory Services Leader will manage identity engineers and service partners while remaining directly involved in architecture, implementation, technical review, troubleshooting, incident response, and operational support. The successful candidate must be able to move comfortably between team leadership, service ownership, security controls, architecture, and detailed engineering work. This role is intended for an experienced identity professional who can lead the function while remaining technically capable of performing and validating the work.
Key Responsibilities
- Own the operation, security, resilience, and lifecycle of Qnity directory and identity services.
- Lead the architecture, administration, and support of Microsoft Active Directory, Microsoft Entra ID, and hybrid identity services.
- Manage and develop identity engineers, administrators, contractors, and service providers.
- Establish technical standards, operating procedures, support models, escalation paths, and service performance expectations.
- Review and approve changes affecting domains, trusts, organizational units, group policy, directory permissions, privileged groups, synchronization, and authentication services.
- Govern Entra ID administrative roles, Privileged Identity Management, enterprise applications, application registrations, service principals, managed identities, and administrative consent.
- Lead implementation of least privilege, just-in-time administration, role-based access control, privileged account separation, and emergency-access controls.
- Oversee service accounts, group managed service accounts, non-human identities, application identities, and credential-management standards.
- Partner with Cybersecurity and IAM teams to integrate Active Directory and Entra ID with Saviynt IGA and PAM.
- Support identity lifecycle processes, including provisioning, deprovisioning, access requests, birthright access, access reviews, entitlement management, and segregation of duties.
- Oversee Saviynt connectors, account and entitlement reconciliation, provisioning failures, orphaned accounts, and access-removal issues.
- Lead technical design reviews for authentication, authorization, federation, privileged access, and directory integration.
- Troubleshoot complex issues involving Kerberos, LDAP, replication, synchronization, SAML, OAuth, OpenID Connect, service principals, and application access.
- Provide senior technical leadership during identity incidents, outages, account compromises, and privileged-access events.
- Ensure directory recovery, backup validation, disaster-recovery procedures, monitoring, patching, certificate renewal, and platform maintenance are performed reliably.
- Maintain accurate architecture diagrams, service inventories, operating documentation, standards, and dependency maps.
- Support internal and external audits by producing accurate evidence for identity, access, and privileged-access controls.
- Identify technical debt, control weaknesses, and operational risks, and drive remediation to completion.
- Partner with Infrastructure, End User Computing, Cloud, Application, ERP, Compliance, Service Management, and manufacturing technology teams.
Required Qualifications
- Bachelor's or Master’s degree in Computer Science or related field.
- 8+ years of relevant IT experience with significant experience designing, operating, and securing enterprise Microsoft identity environments.
- Deep hands-on expertise with Microsoft Active Directory, including domains, forests, trusts, organizational units, group policy, replication, authentication, privileged groups, service accounts, and directory recovery.
- Strong hands-on expertise with Microsoft Entra ID, including administrative roles, Privileged Identity Management, enterprise applications, application registrations, service principals, access reviews, and hybrid identity.
- Demonstrated experience leading technical teams while remaining directly engaged in engineering and operations.
- Experience operating identity services in a large, complex, hybrid enterprise environment.
- Strong understanding of least privilege, role-based access control, privileged-access management, administrative tiering, and segregation of duties.
- Working knowledge of Kerberos, LDAP, SAML, OAuth 2.0, OpenID Connect, and certificate-based authentication.
- Experience with identity lifecycle management, provisioning, deprovisioning, access certification, and entitlement governance.
- Ability to troubleshoot complex identity issues across directories, cloud platforms, networks, servers, endpoints, and applications.
- Experience leading major incidents, root-cause analysis, and corrective-action planning.
- Strong communication, documentation, stakeholder-management, and technical decision-making skills.
Preferred Qualifications
- Hands-on experience with Saviynt IGA, Saviynt PAM, or a comparable enterprise identity platform.
- Experience integrating identity platforms with SAP, cloud services, databases, infrastructure systems, and enterprise applications.
- Experience supporting a global manufacturing, industrial, semiconductor, chemical, or regulated enterprise.
- Experience with PowerShell, Microsoft Graph, REST APIs, and identity automation.
- Knowledge of Microsoft Sentinel, Defender, Intune, Purview, or related Microsoft security technologies.
- Experience with mergers, divestitures, directory separations, tenant migrations, or large-scale identity transformations.
- Relevant Microsoft, identity, security, or cloud certifications.
Leadership Expectations
The successful candidate will be expected to:
- Act as the accountable owner of the directory and identity service.
- Lead through technical competence, clear decisions, and consistent execution.
- Challenge insecure or unsupported designs while providing practical alternatives.
- Review configurations, scripts, technical designs, and implementation quality.
- Participate directly in complex troubleshooting and high-risk changes.
- Build a capable team with strong documentation, repeatable processes, and clear accountability.
- Balance security, reliability, usability, and business delivery requirements.
- Communicate identity risks and technical constraints clearly to both technical teams and senior leadership.
#LI-LH1
#LI-Hybrid
加入我们的人才社区 并与我们保持联系!https://careers.qnityelectronics.com/cn/zh/jointalentcommunity
Qnity是一家推崇机会均等的公司。我们对符合条件的求职者一视同仁,不会因其种族、肤色、宗教、信条、性别、性取向、性别认同、婚姻状况、国籍、年龄、退伍军人身份、残疾或或属于任何其他受保护阶层而区别对待。如果您需要借助合理的便利条件来搜索或申请职位,请访问我们的无障碍功能页面获取联系信息。http://www.qnityelectronics/accessibility.html
Qnity提供全面的薪资和福利方案。要了解更多,请访问薪酬和福利页面https://careers.qnityelectronics.com/cn/zh/compensation-and-benefits-final
我们使用人工智慧(AI)来增強我們的招聘流程。