Microsoft Entra ID Engineer II

OATS

Washington (District of Columbia)

Remote

USD 110,000 - 150,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

401(k)
Pension plan
Health, dental, and vision plans
Life insurance
Paid time off

Job summary

AARP is seeking an Engineer II in Washington, DC area to work within Information Technology Services on Microsoft identity and cloud security. You will translate business requirements into technical specs, lead identity projects, and collaborate with cross-functional teams to deliver secure solutions.

Responsibilities include building and maintaining Entra ID-based architectures, MFA/CA/SSO operations, and on-prem to cloud migrations, with a focus on secure, scalable identity services and

Qualifications

  • 5+ years managing Microsoft identity and network services (DHCP/DNS) for large-scale enterprises.
  • 3+ years engineering and administering Microsoft Entra ID with MFA, CA, SSO, and Enterprise Applications.
  • Experience with SAML, OpenID Connect, OAuth, and hybrid authentication.
  • Ability to lead migration of on-prem AD to Entra ID, including cloud integrations.

Responsibilities

  • Establishes a technical roadmap for platform and lifecycle.
  • Ensures secure integration, data, security, and architecture designs across lifecycle stages.
  • Delivers rapid, technically sound solutions aligned with business outcomes.
  • Troubleshoots and resolves platform and service issues.
  • Drives continuous improvements of implementation methodologies and offerings.
  • Participates in a Community of Interest for engineers to share knowledge.
  • Maintains deep technical knowledge of domain systems and applications.

Skills

Azure Entra ID
DHCP/DNS
MFA/CA/SSO
Hybrid identity
DevSecOps automation
Cloud computing
On-call rotation

Tools

Jira
Confluence
ServiceNow

Job description

Overview

AARP is the nation's largest nonprofit, nonpartisan organization dedicated to empowering people 50 and older to choose how they live as they age. With a nationwide presence, AARP strengthens communities and advocates for what matters most to the more than 100 million Americans 50-plus and their families: health and financial security, and personal fulfillment. AARP also works for individuals in the marketplace by sparking new solutions and allowing carefully chosen, high-quality products and services to carry the AARP name. As a trusted source for news and information, AARP produces the nation's largest-circulation publications, AARP The Magazine and the AARP Bulletin.

Information Technology Services is responsible for AARP enterprise-wide technology and information security functions. Services range from infrastructure design and operations, system and software lifecycle implementations, enabling the mobile workforce and protecting AARP network, systems and data. A variety of technologies and practices are used including cloud computing, automation, artificial intelligence and machine learning within highly collaborative Agile teams.

The Engineer II works with cross-functional teams and customers to understand business requirements and translates into technical specifications. They discover the true requirements underlying feature requests and recommend alternative technical approaches. The Engineer II partners with cross-functional technical teams to launch projects and provide ongoing technical support. They collaborate with management to identify opportunities to streamline technology processes and develop new procedures that support the business unit/department.

Responsibilities
  • Establishes a technical roadmap for the platform and/or capability strategy and lifecycle that considers value-based outcomes, costs to maintain, supportability, and performance.
  • Ensures sound integration, data, security, and business architecture design throughout all stages within the platform and/or capability lifecycle.
  • Provides rapid delivery and development of technical solutions that align with business and/or platform desired outcomes.
  • Troubleshoots and resolves technical issues related to platform or capability systems, solutions, and services.
  • Innovates and drives continuous improvements of implementation methodology and technical service offerings based on customer/employee experiences or other enterprise objectives/outcomes.
  • Participates in a Community of Interest for engineers across all capability and platform teams to share information and strengthen understanding of business needs and technology-based business solutions.
  • Develops and maintains deep technical knowledge and expertise related to domain area systems, solutions, services, and applications.
Qualifications
  • 5+ years of hands-on experience managing Microsoft identity and network services, including Dynamic Host Configuration Protocol (DHCP) and Domain Name System (DNS) services with Microsoft and Infoblox solutions, as well as Secure DNS and content filtering services with Cisco Umbrella and Fortinet FortiGate, for large-scale enterprises with a variety of endpoints (e.g., laptops, servers, networking equipment, IoT devices, etc.).
  • 3+ years of hands-on experience engineering and administering Microsoft Entra ID (formerly Azure AD), including Entra tenant configuration, identity and access management, Microsoft 365 Multi-Factor Authentication (MFA), Conditional Access Policies, Enterprise Applications, Single Sign-On (SSO), application registration, and integration with on-premises Active Directory; experience with Privileged Access Management (PAM) solutions such as CyberArk is preferred.
  • Demonstrated ability to troubleshoot complex Microsoft Entra ID authentication and identity issues, including SSO failures, Conditional Access, MFA, application integration, identity synchronization, and hybrid authentication; experience with SAML, OpenID Connect, OAuth, and other modern authentication protocols is highly desired.
  • Ability to lead and execute iterative migration of on-premises Active Directory environments to Microsoft Entra ID, including hybrid identity configurations, Microsoft Entra Connect/Cloud Sync, and cloud-only identity models.
  • Demonstrated proficiency in DevSecOps practices by designing and implementing API-driven automation for the complete user lifecycle, from onboarding through offboarding.
  • Demonstrated experience with assessing and documenting existing Active Directory and Entra ID dependencies, including users, groups, service accounts, GPOs, applications, authentication methods, and identity lifecycle processes, and developing migration and modernization strategies.
  • Demonstrated experience with designing, implementing, and supporting Microsoft Entra ID architecture, including tenant configuration, domain integration, identity lifecycle management, Enterprise Applications, SSO, Conditional Access, MFA, application registration, and integration between on-premises Active Directory, Microsoft Entra ID and Microsoft Defender.
  • Familiarity with Jira, Confluence, and ServiceNow tools for collaboration and managing identity engineering work, incidents, and technical projects.
  • Familiarity with cloud computing (e.g., AWS, Azure, GCP), with hands‑on experience supporting Microsoft Azure and Microsoft Entra ID environments preferred.
  • Participate in a rotational on-call schedule approximately once per month to provide support and respond to urgent identity and authentication issues as needed.

AARP will not sponsor an employment visa for this position at this time.

Additional Requirements
  • Regular and reliable job attendance
  • Effective verbal and written communication skills
  • Exhibit respect and understanding of others to maintain professional relationships
  • Independent judgement in evaluation options to make sound decisions
  • Home office environment with the ability to work effectively surrounded by moderate home environment noise - (Telework)
Compensation and Benefits
  • 401(k)
  • 100% company-funded pension plan
  • Health, dental, and vision plans
  • Life insurance
  • Paid time off to include company and individual holidays, vacation, sick, caregiving, and parental leave
  • Performance-based and peer-based recognition and tuition reimbursement
Equal Employment Opportunity

AARP is an equal opportunity employer committed to hiring a diverse workforce and sustaining an inclusive culture. AARP does not discriminate on the basis of race, ethnicity, religion, sex, color, national origin, age, sexual orientation, gender identity or expression, mental or physical disability, genetic information, veteran status, or on any other basis prohibited by applicable law.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Identity and Access Management Technical Analyst
Identity and Access Management Technical Analyst

Staples • Framingham (MA)

On-site
USD 110,000 - 160,000
Inclusive culture
Flexible PTO
Company discounts & 401(k)
Identity and Access Management Technical Analyst
Identity and Access Management Technical Analyst

Staples, Inc. • Framingham (MA)

On-site
USD 120,000 - 150,000
Flexible PTO
Company discounts
401(k) match
Sr Engineer M365 Platform
Sr Engineer M365 Platform

Optimum • Plano (TX)

On-site
USD 120,000 - 180,000
Microsoft Systems Engineer
Microsoft Systems Engineer

Experimental Aircraft Association Inc • Oshkosh (WI)

On-site
USD 90,000 - 130,000
Engineer I, Data Platforms
Engineer I, Data Platforms

AARP • Washington

On-site
USD 70,000 - 90,000
401(k)
Company-funded pension
Health, dental, and vision plans
+2
Sr. Identity Security Engineer Active Directory & Entra ID
Sr. Identity Security Engineer Active Directory & Entra ID

MathWorks • Natick (MA)

On-site
USD 122,000 - 190,000
System Engineer
System Engineer

Search Services • Houston (TX)

Hybrid
USD 90,000 - 130,000
Hybrid work arrangement
Full-time employment
Identity & Security Engineer
Identity & Security Engineer

Coda Search│Staffing • Town of Texas (WI)

Hybrid
USD 110,000 - 170,000
Microsoft System and Identity Administrator
Microsoft System and Identity Administrator

Buoyant • Salt Lake City (UT)

On-site
USD 90,000 - 115,000
Three weeks paid vacation
Paid holidays
401(k) with employer match
+4
Microsoft System and Identity Administrator
Microsoft System and Identity Administrator

Resource Innovations • Salt Lake City (UT)

On-site
USD 90,000 - 115,000
401(k) matching
Health insurance
Paid vacation