Enterprise Security Engineer - IC2 (ENTSEC - Enterprise Security)

PowerSchool Group LLC

Dallas (TX)

Presencial

USD 110.000 - 150.000

Jornada completa

Hace 6 días
Sé de los primeros/as/es en solicitar esta vacante
Generador de candidaturas

Una candidatura hecha a medida para este puesto de trabajo — un currículum y una carta de presentación adaptados que responden directamente a la oferta.

Supera los filtros ATS

Descripción de la vacante

PowerSchool Group LLC is seeking an Identity & Access Management Engineer to secure and streamline access across our hybrid enterprise. You will own IAM capabilities, integrating Microsoft Entra ID, Active Directory, SailPoint, and enterprise apps while automating processes to reduce manual work.

In this hands‑on role you will implement MFA, SSO, RBAC, and privileged access controls, troubleshoot complex identity issues, and collaborate with Security, Infra, Compliance, HR, and app owners to

Formación

  • 3+ years in identity and access management or related field.
  • Hands‑on experience administering Microsoft Active Directory and Microsoft Entra ID in an enterprise environment.
  • Experience with identity lifecycle: provisioning, deprovisioning, access requests, entitlements, joiner/mover/leaver processes.
  • Experience implementing or supporting SSO and federation using SAML, OAuth, and OIDC.
  • Experience configuring MFA, Conditional Access, and modern authentication controls.
  • Working knowledge of identity governance and administration platforms such as SailPoint Identity Security Cloud or IdentityIQ.
  • Experience with RBAC, least privilege, privileged access, access certification, and identity governance principles.
  • Experience using PowerShell / Bash scripting to automate identity administration and troubleshoot IAM processes.
  • Strong troubleshooting and root‑cause analysis skills across complex cloud and hybrid identity environments.
  • Ability to communicate technical concepts clearly and work effectively with security, infrastructure, application, compliance, and business teams.

Responsabilidades

  • Administer AD and Entra ID across hybrid environments.
  • Manage identity lifecycle events: provisioning, deprovisioning, entitlements.
  • Implement RBAC, least privilege, and identity governance controls.
  • Configure MFA, CA, passwordless auth, passkeys, and related authentication technologies.
  • Enable SSO and federation using SAML, OAuth, OIDC, SCIM.
  • Onboard applications into PowerSchool’s identity ecosystem.
  • Administer PIM and support privileged access controls.
  • Support SailPoint governance: provisioning, access requests, certifications.
  • Troubleshoot authentication, federation, provisioning across cloud/hybrid.
  • Automate IAM with PowerShell, Bash, Graph API, REST, etc.
  • Monitor IAM platforms for availability and security events.
  • Document controls, runbooks, and procedures.
  • Collaborate with Security, Infra, Compliance, HR, and app owners to secure scalable solutions.
  • Provide backup support for Microsoft 365 identity administration.

Conocimientos

Active Directory
Entra ID
RBAC
MFA & CA
SSO & Federation
SailPoint
PowerShell
Bash
Graph API
SCIM provisioning
PIM / PAM
Troubleshooting
Communication

Herramientas

Microsoft Entra ID
Microsoft Graph API
SailPoint Identity Security Cloud
PowerShell
Bash

Descripción del empleo

Overview

At PowerSchool, we power education for students around the world. As a global leader in cloud-based K-12 education technology, we help schools operate more effectively and support better outcomes for educators, students, and families.

Our Security team protects the people, systems, and information that make that mission possible. We are looking for an Identity & Access Management Engineer who can help us make access simple for the right people and difficult for everyone else.

Responsibilities

The Identity & Access Management (IAM) Engineer helps build, secure, automate, and support the identity services that connect PowerSchool employees and partners to the technology they need.

You will own and support IAM capabilities across Microsoft Active Directory, Microsoft Entra ID, SailPoint, privileged access, authentication, and enterprise applications. You will implement secure access controls, onboard applications, troubleshoot complex identity issues, automate manual processes, and continuously improve how identities and access are managed across our environment.

This is a hands‑on engineering role for someone who understands both sides of identity: protecting the organization while providing a reliable, efficient user experience.

What You Will Do

  • Administer and support Microsoft Active Directory and Microsoft Entra ID across hybrid enterprise environments, including identity synchronization, users, groups, roles, and authentication services.
  • Manage identity lifecycle processes across joiner, mover, and leaver events, including provisioning, deprovisioning, access requests, birthright access, and entitlement changes.
  • Implement and maintain role-based access control (RBAC), least‑privilege access, separation of duties, and other identity governance controls.
  • Configure and support Multi‑Factor Authentication (MFA), Conditional Access, passwordless authentication, passkeys, FIDO2, and related authentication technologies.
  • Implement and support enterprise SSO and federation integrations using SAML 2.0, OAuth 2.0, OpenID Connect (OIDC), SCIM, and related standards.
  • Onboard enterprise and SaaS applications into PowerSchool’s identity ecosystem, including application registrations, federation, provisioning, certificates, claims, permissions, and access models.
  • Administer Microsoft Entra Privileged Identity Management (PIM) and support privileged access controls that enforce just‑in‑time and least‑privilege access.
  • Support SailPoint identity governance capabilities, including provisioning workflows, access requests, entitlement management, access certifications, and application onboarding.
  • Troubleshoot authentication, federation, provisioning, directory synchronization, entitlement, and access issues across cloud and on‑premises environments.
  • Build and maintain automation using PowerShell, Bash, Microsoft Graph API, REST APIs, and other appropriate tools to improve reliability and reduce manual administration.
  • Monitor IAM platforms and authentication services for availability, performance, security events, and control failures, and support identity‑related incident investigation and response.
  • Support access reviews, audits, and compliance activities by maintaining accurate controls, documentation, technical evidence, and remediation records.
  • Partner with Security, Infrastructure, Compliance, HR, application owners, and business teams to translate access requirements into secure and scalable identity solutions.
  • Create and maintain technical documentation, diagrams, standards, runbooks, and operating procedures.
  • Identify recurring issues and opportunities to improve IAM processes through automation, standardization, and stronger controls.
  • Provide backup support for Microsoft 365 identity‑related administration, including Exchange Online and SharePoint, as needed.

What Success Looks Like

You make secure access easier to manage, easier to audit, and more reliable for the people who depend on it. You reduce manual work through automation, resolve identity issues before they become larger problems, strengthen access controls, and help PowerSchool continuously improve how identities are protected across the enterprise.

You bring sound technical judgment, curiosity, attention to detail, and a service mindset to an area of security where both protection and user experience matter.

Qualifications

What You Bring

  • 3+ years of experience in identity and access management, security engineering, systems engineering, or a related technical field, or an equivalent combination of education and experience.
  • Hands‑on experience administering Microsoft Active Directory and Microsoft Entra ID in an enterprise environment.
  • Experience with identity lifecycle management, including provisioning, deprovisioning, access requests, entitlements, and joiner/mover/leaver processes.
  • Experience implementing or supporting SSO and federation using SAML, OAuth, and OIDC.
  • Experience configuring MFA, Conditional Access, and modern authentication controls.
  • Working knowledge of identity governance and administration platforms such as SailPoint Identity Security Cloud or IdentityIQ.
  • Experience with RBAC, least privilege, privileged access, access certification, and identity governance principles.
  • Experience using PowerShell / Bash scripting to automate identity administration and troubleshoot IAM processes.
  • Strong troubleshooting and root‑cause analysis skills across complex cloud and hybrid identity environments.
  • Ability to communicate technical concepts clearly and work effectively with security, infrastructure, application, compliance, and business teams.

Even Better If You Have

  • Experience with Microsoft Graph API, REST APIs, JSON, Python, or other scripting and integration technologies.
  • Experience configuring Microsoft Entra PIM or enterprise Privileged Access Management (PAM) platforms.
  • Experience with SCIM provisioning and API-based application integrations.
  • Experience with SailPoint application onboarding, connectors, access certifications, workflows, or entitlement management.
  • Experience supporting Microsoft 365, cloud platforms, or enterprise SaaS applications.
  • Familiarity with security and compliance frameworks such as NIST, ISO 27001, SOC 2, or SOX.
  • Experience supporting security incidents involving compromised identities, credentials, authentication, or privileged access.
  • Microsoft SC-300, SailPoint, Security+, SSCP, CISSP, or other relevant identity/security certification.
Compensation & Benefits

PowerSchool offers the following benefits:

  • Comprehensive Insurance Coverage (including Medical, Dental, Vision, Pharmacy benefits, Life Insurance and AD&D)
  • Flexible Spending Accounts and Health Savings Accounts
  • Short‑Term Disability and Long‑Term Disability
  • Comprehensive 401(k) plan
  • Generous Parental Leave
  • Unrestricted paid time off (known as Discretionary Time Off - DTO)
  • Wellness Program, including ClassPass & Employee Assistance Program
  • Tuition Reimbursement
  • Optional Benefits: Pet Insurance, Identity Theft Protection, Student Debt Repayment Program and Prepaid Legal coverage
EEO Commitment

PowerSchool is committed to a diverse and inclusive workplace. PowerSchool is an equal opportunity employer and does not discriminate on the basis of race, national origin, gender, gender identity, sexual orientation, protected veteran status, disability, age, or other legally protected status. Our inclusive culture empowers PowerSchoolers to deliver the best results for our customers. We not only celebrate the diversity of our workforce, we celebrate the diverse ways we work. If you have a disability and need an accommodation regarding our recruiting process, please let us know by emailing accommodations@powerschool.com.

Consigue la evaluación confidencial y gratuita de tu currículum.

o arrastra y suelta tu archivo aquí

Similar jobs

Puestos de trabajo similares que vale la pena comparar

Identity Access Management Engineer
Identity Access Management Engineer

PowerSchool • Dallas (TX), Northern (KY)

Híbrido
USD 110.000 - 150.000
Comprehensive Insurance Coverage
Flexible Spending Accounts
Discretionary Time Off
+3
Senior IT Engineer - IC3 (ITENG - IT Engineering)
Senior IT Engineer - IC3 (ITENG - IT Engineering)

PowerSchool Group LLC • Dallas (TX)

Presencial
USD 120.000 - 170.000
Comprehensive Insurance Coverage
401(k) plan with match
Parental Leave
Senior Mobile Device Management (MDM) Engineer
Senior Mobile Device Management (MDM) Engineer

PowerSchool • Dallas (TX)

Presencial
USD 120.000 - 170.000
Medical dental vision
401(k) plan
Parental Leave
+5
Senior Mobile Device Management (MDM) Engineer
Senior Mobile Device Management (MDM) Engineer

PowerSchool Group LLC • Dallas (TX)

Presencial
USD 120.000 - 170.000
Health insurance
401(k) plan
Parental leave
+2
Vice President, Product Management - Student Information Systems
Vice President, Product Management - Student Information Systems

PowerSchool Group LLC • Dallas (TX)

Presencial
USD 230.000 - 280.000
Comprehensive Insurance
Flexible Spending Accounts
Short-Term Disability
+10
Distinguished Data & Integration Architect
Distinguished Data & Integration Architect

PowerSchool Group, LLC • Dallas (TX)

Presencial
USD 163.000 - 204.000
Insurance coverage
401(k) plan
Parental leave
+4
Senior Software Engineer I
Senior Software Engineer I

PowerSchool Group LLC • Dallas (TX)

Presencial
USD 80.000 - 137.000
Medical Insurance
Dental Insurance
Vision Insurance
+6
Vice President, Product Management - Student Information Systems
Vice President, Product Management - Student Information Systems

PowerSchool • Dallas (TX)

A distancia
USD 230.000 - 330.000
Comprehensive Insurance Coverage
401(k) plan
Generous Parental Leave
+3
Distinguished Data & Integration Architect (Dallas/Austin)
Distinguished Data & Integration Architect (Dallas/Austin)

PowerSchool • Dallas (TX)

Presencial
USD 163.000 - 204.000
Medical Insurance
Dental Insurance
Vision Insurance
+3
Senior Software Engineer
Senior Software Engineer

PowerSchool Group LLC • Dallas (TX)

Presencial
USD 80.000 - 137.000
Medical, Dental, Vision coverage
401(k) plan
Discretionary Time Off