Senior Identity & Access Management Engineer

Integration International Inc.

Wayzata (MN)

On-site

USD 120,000 - 160,000

Full time

2 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Integration International Inc. is seeking a Senior Identity & Access Management Professional to design, engineer, secure, and modernize a large-scale enterprise Active Directory environment in Wayzata, MN. The role emphasizes automation, cloud integration, and modern engineering practices.

The candidate will lead AD design, security, and automation efforts, integrating LDAP/Kerberos with IAM and PAM platforms, while ensuring global multi-domain support and CI/CD driven improvements.

Qualifications

  • Extensive hands-on experience administering Microsoft Active Directory in large, complex enterprise environments.
  • Strong knowledge of AD architecture: forests, domains, trusts, OU, Group Policy, Domain Controllers.
  • Understanding of AD security, delegation models, and privileged group management.
  • Experience troubleshooting authentication, replication, DNS, and account lifecycle issues.
  • Experience integrating AD with IAM and PAM platforms.
  • Experience with AWS AD implementations and LDAP/Kerberos integrations.
  • Hands-on experience with IaC, CI/CD, and automation.
  • Proven experience modernizing AD environments through automation.

Responsibilities

  • Design, engineer, operate, secure, and maintain Microsoft Active Directory environments.
  • Manage forests, domains, trusts, OU, Group Policy, and Domain Controllers.
  • Monitor, troubleshoot, and resolve authentication, replication, DNS, and access issues.
  • Partner with IAM and PAM teams to support privileged access controls.
  • Support integrations between AD and identity governance and access platforms.
  • Develop integration patterns between AD and AWS using LDAP and Kerberos.
  • Establish authentication patterns leveraging Kerberos where appropriate.
  • Modernize AD infrastructure through automation and engineering best practices.
  • Develop and maintain automation using Ansible, Terraform, Chef, or similar.
  • Implement IaC and CI/CD for identity infrastructure and operations.
  • Create and maintain standards, runbooks, and operational docs.
  • Participate in change management, incidents, audits, and continuous improvement.
  • Support global, multi-domain, and multi-region AD environments.

Skills

Active Directory
IAM
Automation
Infrastructure as Code
CI/CD
LDAP
Kerberos
Multi-region AD
Cloud integration
Enterprise IAM

Tools

Ansible
Terraform
Chef
AWS Managed Microsoft AD

Job description

Job Title: Senior Identity & Access Management Professional

Project Duration: 12 Months

Job location: WAYZATA, MN

Job Summary

We are seeking a Senior Identity & Access Management professional with extensive hands‑on experience in Microsoft Active Directory to design, engineer, secure, and modernize a large-scale enterprise identity environment.

This role will focus on Active Directory infrastructure, security, automation, cloud integration, and modernization. The ideal candidate will have strong experience managing complex enterprise AD environments and applying modern engineering practices such as Infrastructure as Code, CI/CD, and automation.

Key Responsibilities
  • Design, engineer, operate, secure, and maintain Microsoft Active Directory environments.
  • Manage Active Directory forests, domains, trusts, Organizational Units, Group Policy, and Domain Controllers.
  • Monitor, troubleshoot, and resolve issues related to authentication, replication, DNS, Domain Controller availability, account lifecycle, and access.
  • Partner with IAM and PAM teams to support privileged access controls, delegated administration, and administrative group structures.
  • Support integrations between Active Directory and identity governance, access request, authentication, and access certification platforms.
  • Develop integration patterns between Active Directory and AWS environments using LDAP and Kerberos authentication.
  • Establish application authentication patterns that leverage Kerberos where appropriate.
  • Modernize existing Active Directory infrastructure through automation and engineering best practices.
  • Develop and maintain automation using tools such as Ansible, Terraform, Chef, or similar technologies.
  • Implement Infrastructure as Code and CI/CD practices for identity infrastructure and operations.
  • Create and maintain technical standards, runbooks, and operational documentation.
  • Participate in change management, incident response, audits, and continuous improvement initiatives.
  • Support global, multi-domain, and multi-region Active Directory environments.
Required Qualifications
  • Extensive hands‑on experience administering Microsoft Active Directory in large, complex enterprise environments.
  • Strong knowledge of Active Directory architecture, including forests, domains, trusts, Group Policy, Organizational Units, and Domain Controllers.
  • Strong understanding of Active Directory security, delegation models, and privileged group management.
  • Experience troubleshooting authentication, replication, DNS, account lifecycle, and access‑related issues.
  • Experience working with Active Directory as part of an enterprise IAM ecosystem.
  • Experience integrating Active Directory with Identity Governance and Administration and/or Privileged Access Management platforms.
  • Experience with AWS Active Directory implementations, including AWS Managed Microsoft AD, self‑hosted Active Directory, or similar solutions.
  • Experience developing or supporting authentication integrations using LDAP and Kerberos.
  • Experience supporting global, multi- domain, or multi-region Active Directory environments.
  • Hands‑on experience with Infrastructure as Code, CI/CD, and automation.
  • Experience with automation tools such as Ansible, Terraform, Chef, or similar technologies.
  • Proven experience modernizing and transforming existing Active Directory environments using automation and modern engineering practices.
Preferred Profile

The ideal candidate is a senior Active Directory or IAM professional with a strong combination of enterprise identity expertise and modern software engineering skills. Candidates should demonstrate a proven ability to transform traditional Active Directory environments through automation, Infrastructure as Code, CI/CD, and cloud integration.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior IAM Engineer: AD Modernization & Automation
Senior IAM Engineer: AD Modernization & Automation

Integration International Inc. • Wayzata (MN)

On-site
USD 120,000 - 160,000
Identity & Access Management
Identity & Access Management

Performix • Wayzata (MN)

On-site
USD 120,000 - 180,000
IT - DTD - Senior Professional, Identity & Access Management
IT - DTD - Senior Professional, Identity & Access Management

TALENT Software Services • Wayzata (MN)

On-site
USD 130,000 - 180,000
Senior IAM Consultant: AD & AWS Identity Expert
Senior IAM Consultant: AD & AWS Identity Expert

Performix • Atlanta (GA)

On-site
USD 120,000 - 180,000
IAM EntraID specialist
IAM EntraID specialist

Programmers.io • Atlanta (GA)

On-site
USD 110,000 - 160,000
IAM Consultant
IAM Consultant

Performix • Atlanta (GA)

On-site
USD 120,000 - 180,000
Windows Active Directory Architect
Windows Active Directory Architect

PRI Technology • New York (NY)

On-site
USD 120,000 - 180,000
Senior IAM Engineer
Senior IAM Engineer

Veriipro • United States

On-site
USD 120,000 - 160,000
Active Directory Specialist
Active Directory Specialist

Compunnel, Inc. • Richmond (VA)

On-site
USD 100,000 - 130,000
Senior IAM Architect
Senior IAM Architect

Veriipro • Fort Lauderdale (FL)

On-site
USD 140,000 - 190,000