Identity Engineer

AAA Auto Club Enterprises

Costa Mesa (CA)

On-site

USD 110,000 - 146,000

Full time

20 hours ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Health coverage
401(K) + Pension
Tuition assistance
Floating holidays and PTO
Paid parental leave
Wellness programs
Employee discounts

Job summary

Auto Club Enterprises in Costa Mesa is seeking an Identity Engineer to design, implement, automate, and support enterprise identity platforms that enable secure access to critical business applications and infrastructure.

You will collaborate with Cybersecurity, Infrastructure, Cloud Engineering, App Development, and Architecture teams to advance an identity-first security strategy and support a modern Zero Trust environment.

Qualifications

  • Experience with identity and access management concepts and governance.
  • Hands-on with authentication, authorization, federation, lifecycle management and governance.
  • Experience with LDAP, Active Directory, Entra ID, SAML, OAuth, OIDC and related tech.
  • RBAC design, entitlement management, role engineering and access provisioning.
  • Automation scripting using PowerShell or Python.

Responsibilities

  • Design, engineer, and support IAM solutions including authentication, authorization, and governance.
  • Develop automation to improve efficiency and strengthen security controls.
  • Integrate with SAML, OAuth, OpenID Connect, LDAP, and SCIM.
  • Support directory services, cloud identity platforms, and hybrid identities.
  • Collaborate with cybersecurity and infrastructure teams to align with Zero Trust.

Skills

IAM concepts
RBAC design
Automation scripting
Cloud security
Zero Trust concepts

Tools

Active Directory
Entra ID / Azure AD
SAML
OAuth / OpenID Connect
Ansible / Terraform
PKI / certificate lifecycle

Job description

As an Identity Engineer within Auto Club Enterprise's Enterprise Identity Engineering (EIE) team, you will design, implement, automate, and support enterprise identity platforms that enable secure, seamless, and scalable access to critical business applications and infrastructure. You will play a key role in strengthening ACE's security posture by delivering identity governance, authentication, authorization, privileged access management, and directory services solutions. As part of the Information Systems organization, you will collaborate closely with Cybersecurity, Infrastructure, Cloud Engineering, Application Development, and Architecture teams to advance ACE's identity-first security strategy and support a modern Zero Trust environment. The Enterprise Identity Engineering team is responsible for the design, operation, automation, and continuous improvement of enterprise identity services that reduce risk, improve user experience, and enable secure business outcomes. The team focuses on delivering resilient, scalable, and highly available identity solutions across on‑premises, cloud, and hybrid environments while driving automation and operational excellence. Your work will directly support mission‑critical services that empower and protect ACE's workforce, partners, and members.

What You'll Do
  • Design, engineer, and support enterprise identity and access management solutions, including authentication, authorization, identity governance, and privileged access management.
  • Develop and maintain automation solutions that improve operational efficiency, reduce manual effort, and strengthen security controls.
  • Implement and manage identity integrations using industry standards such as SAML, OAuth, OpenID Connect, LDAP, and SCIM.
  • Support enterprise directory services, cloud identity platforms, and hybrid identity architectures.
  • Design and manage solutions utilizing Public Key Infrastructure (PKI), Multi‑Factor Authentication (MFA), certificate services, and privileged access technologies.
  • Collaborate with cybersecurity teams to strengthen access controls, reduce risk, and align with regulatory and security requirements.
  • Participate in Agile delivery practices, contributing to the design, testing, deployment, and operational support of identity services and platforms.
  • Monitor, troubleshoot, and improve the reliability, performance, and resiliency of identity infrastructure and services.
  • Partner with business and technology stakeholders to deliver secure, scalable, and user‑centered identity capabilities.
  • Contributes to the implementation of Zero Trust security principles through modern identity and access management practices.
What You'll Need
  • Experience working within large, complex technology environments and leading efforts to address identity, access control, and security challenges.
  • Strong understanding of Identity and Access Management concepts, including authentication, authorization, federation, lifecycle management, and governance.
  • Hands‑on experience with LDAP, Active Directory, Entra ID (Azure AD), SAML, OAuth, OpenID Connect, and related identity technologies.
  • Experience designing and implementing Role‑Based Access Control (RBAC), entitlement management, role engineering, role mining, and access provisioning processes.
  • Experience developing automation and scripting solutions using PowerShell, Python, or similar technologies.
  • Knowledge of cloud platforms such as Microsoft Azure and AWS, including cloud‑native identity services.
  • Experience with infrastructure automation and configuration management platforms such as Ansible, Terraform, or similar technologies.
  • Knowledge of Public Key Infrastructure (PKI), certificate lifecycle management, Multi‑Factor Authentication (MFA), and privileged access solutions.
  • Experience supporting highly available, scalable, and fault‑tolerant systems in enterprise environments.
  • Strong communication, collaboration, and problem‑solving skills with the ability to work effectively across technical and business teams.
Preferred Experience
  • Identity Governance and Administration (IGA) platforms.
  • Privileged Access Management (PAM) solutions such as CyberArk.
  • Zero Trust architecture and security frameworks.
  • CI/CD pipelines, DevOps practices, and Infrastructure as Code methodologies.
  • Cloud‑native security and identity solutions.
  • Enterprise certificate services and secrets management.

The starting pay range for this position is: $109,500.00 - $146,200.00

Additionally, for full time positions, you will be eligible to participate in our incentive program based upon the achievement of organization, team and personal performance.

Remarkable benefits
  • Health coverage for medical, dental, vision
  • 401(K) saving plans with company match AND Pension
  • Tuition assistance
  • Floating holidays and PTO for community volunteer programs
  • Paid parental leave
  • Wellness programs
  • Employee discounts (membership, insurance, travel, entertainment, services and more!)

Auto Club Enterprises is the largest club within the national AAA federation. We have nearly 17,000 employees in 24 states helping more than 18 million members. The strength of our organization is our employees. Bringing together and supporting different cultures, backgrounds, personalities, and strengths creates a team capable of delivering legendary, lifetime service to our members. When we embrace our diversity – we win. All of Us! With our national brand recognition, long‑standing reputation since 1900, and constantly growing membership, we are seeking career‑minded, service‑driven professionals to join our team.

“Through dedicated employees we proudly deliver legendary service and beneficial products that provide members peace of mind and value.”

AAA is an Equal Opportunity Employer

Our organization participates in E-Verify

The Automobile Club of Southern California will consider for employment all qualified applicants, including those with criminal histories, in a manner consistent with the requirements of applicable federal, state, and local laws, including the City of Los Angeles’ Fair Chance Initiative for Hiring Ordinance (FCIHO), the Unincorporated Los Angeles County (ULAC) regulation, and the California Fair Chance Act (CFCA).

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Identity Engineer
Identity Engineer

RiseMe • Costa Mesa (CA)

On-site
USD 110,000 - 146,000
Health coverage
401(k) match and Pension
Tuition assistance
+4
Identity Engineer
Identity Engineer

ACSC Auto Club Of Southern Calif • United States

On-site
USD 110,000 - 146,000
Health coverage
401(K) saving plans with company match
Tuition assistance
+3
DevSecOps Engineer
DevSecOps Engineer

AAA Auto Club Enterprises • Costa Mesa (CA)

On-site
USD 109,000 - 146,000
Health coverage (medical, dental, vis​
401(K) with company match and Pension
Tuition assistance
+4
DevSecOps Engineer
DevSecOps Engineer

ACSC Auto Club Of Southern Calif • United States

On-site
USD 110,000 - 146,000
Health coverage (medical, dental, and視
401(K) retirement plan with company-m
Tuition assistance
+4
DevSecOps Engineer
DevSecOps Engineer

AAA • Costa Mesa (CA)

On-site
USD 110,000 - 146,000
Health coverage
401(K) savings with company match
Pension
+5
Benefits Senior Specialist
Benefits Senior Specialist

AAA Auto Club Enterprises • Costa Mesa (CA)

On-site
USD 86,000 - 115,000
Health coverage
401(k) matching and Pension
Tuition assistance
+3
Membership Analyst
Membership Analyst

AAA Auto Club Enterprises • Costa Mesa (CA)

On-site
USD 65,000 - 86,000
Health coverage
401(K) saving plans with company match
Pension
+5
Membership Analyst
Membership Analyst

ACSC Auto Club Of Southern Calif • United States

On-site
USD 65,000 - 86,000
Health coverage
401(k) matching
Pension
+5
Head of Product
Head of Product

AAA Auto Club Enterprises • Costa Mesa (CA)

On-site
USD 176,000 - 259,000
Health coverage
401(k) matching
Pension
+5
Security Lead Graveyard
Security Lead Graveyard

ACSC Auto Club Of Southern Calif • Los Angeles (CA)

On-site
USD 26,000 - 35,000
Incentive program
Health coverage
401(K) with company match and Pension
+5