Senior Identity Management Engineer

Steelcase

Grand Rapids (MI)

Hybrid

USD 100,000 - 135,000

Full time

3 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Hybrid work schedule
Competitive wages and benefits
Continuous learning opportunities
Inclusion culture

Job summary

Steelcase is seeking a senior identity engineer to lead the next generation of our identity platform, including phishing-resistant authentication, Conditional Access, and privileged access management, while guiding migration from legacy Active Directory and designing secure non-human identities such as service accounts and AI agents.

You will build automation and AI-assisted workflows for provisioning, anomaly detection, and remediation, collaborating with HR, IT, and engineering to make secure

Qualifications

  • Substantial hands-on experience designing, implementing, or operating enterprise identity and access management solutions.
  • Strong understanding of modern authentication and authorization, including SAML, OIDC/OAuth, and FIDO2/passkeys, as well as directory services.
  • A drive to automate identity work rather than repeat it, and comfort working against APIs such as Microsoft Graph.
  • Experience leading technical initiatives and influencing outcomes across teams without direct authority.
  • Bachelor's degree in a related field, or equivalent experience.

Responsibilities

  • Architecting and building the next generation of Steelcase's identity platform: phishing-resistant authentication, Conditional Access, and privileged access management.
  • Leading the retirement of legacy identity technologies and directory services, including reducing our dependence on legacy Active Directory, and designing the migration paths that get us there safely.
  • Designing identity for non-human actors, including service accounts, workloads, and AI agents: how they authenticate, what they can reach, and how that access is reviewed and revoked.
  • Building automation and AI-assisted workflows for provisioning, privileged access, anomaly detection, and remediation.
  • Partnering with HR, IT, application owners, and engineering teams to make secure access the default and the easy path.
  • Mentoring other engineers and setting technical standards and patterns for the Identity Management Office.
  • Evaluating emerging identity and security technologies and running proofs of concept that shape our roadmap.

Skills

IAM design
Auth protocols
Automation via APIs
Influence without authority

Education

Bachelor's degree

Tools

Microsoft Graph
PowerShell
Python
CyberArk

Job description

Who you are:

You know identity is the control plane for modern security, and you want to build one that people actually like using: passwordless, phishing-resistant, and invisible when it works.

You are a senior engineer who leads through design and example. You are excited about the identity problems that did not exist five years ago, such as securing workloads, service accounts, and AI agents, and you would rather define the answer than wait for a vendor to.

You automate. You would rather build the workflow than process the ticket, and you see AI as the way to make identity work continuous and self-correcting instead of manual and periodic.

Helping You Thrive By:
  • Offering competitive wages and benefits, that support your life both in and out of work
  • Providing a flexible hybrid work schedule, meaning we expect the office to be your primary place of work, balanced with choice and control.
  • Creating continuous learning opportunities to help you grow and upskill.
  • Fostering a culture of inclusion where employees feel seen, heard and valued - and living it out every day.
  • Empowering you to make a meaningful impact on people and the planet through your work and Steelcase's ongoing commitment.
You'll Support Meaningful Work By:
  • Architecting and building the next generation of Steelcase's identity platform: phishing-resistant authentication, Conditional Access, and privileged access management.
  • Leading the retirement of legacy identity technologies and directory services, including reducing our dependence on legacy Active Directory, and designing the migration paths that get us there safely.
  • Designing identity for non-human actors, including service accounts, workloads, and AI agents: how they authenticate, what they can reach, and how that access is reviewed and revoked.
  • Building automation and AI-assisted workflows for provisioning, privileged access, anomaly detection, and remediation.
  • Partnering with HR, IT, application owners, and engineering teams to make secure access the default and the easy path.
  • Mentoring other engineers and setting technical standards and patterns for the Identity Management Office.
  • Evaluating emerging identity and security technologies and running proofs of concept that shape our roadmap.
Minimum Qualifications
  • Substantial hands-on experience designing, implementing, or operating enterprise identity and access management solutions.
  • Strong understanding of modern authentication and authorization, including protocols such as SAML, OIDC/OAuth, and FIDO2/passkeys, as well as directory services.
  • A drive to automate identity work rather than repeat it, and comfort working against APIs such as Microsoft Graph. Whether you write the PowerShell or Python yourself or build it with AI and low-code tooling matters far less to us than knowing what to automate and why.
  • Experience leading technical initiatives and influencing outcomes across teams without direct authority.
  • Bachelor's degree in a related field, or equivalent experience.
Desired Skills and Experience
  • Deep experience with Microsoft Entra ID, Conditional Access, Privileged Identity Management, and Intune integration.
  • Experience with privileged access management platforms such as CyberArk, Delinea, or BeyondTrust.
  • Experience securing workload identities, secrets, and machine-to-machine or agent-to-service access.
  • Experience applying Zero Trust principles in a large, global enterprise.
  • Have you helped an organization meaningfully shrink or eliminate its reliance on legacy Active Directory? That is rare, and we are not expecting it on day one. But we know legacy AD is a liability, we intend to do something about it, and we would love to talk with anyone who has been part of that journey.
  • Experience using AI or automation to streamline identity operations, authentication rollouts, or investigation work.
  • Certifications such as SC-300, CISSP, CIDPRO, or CCZT.

Qualified applicants must be authorized to work in the United States on a full-time basis. Steelcase will not provide support for or sponsor work authorization and/or visas for this role.

QualificationsAdditional Information

The starting annual base salary range for this position is $100,000 - $135,000. Please note that the salary information is a general guideline only. Steelcase considers factors such as (but not limited to) scope and responsibilities of the position, candidate's work experience, education/training, key skills, internal peer equity, as well as market and business considerations when extending an offer.

#mid_senior_level #LI-Onsite #Information_Technology #Management #Consulting #LI-EW1

At Steelcase, we put people at the center of everything we do. We understand the role of work and believe that it can bring meaning and purpose to the lives of our customers and our employees. We prioritize supporting our employees both in and out of work, in all aspects of their lives. When we bring our talents together, we make a positive lasting impact through our work and communities.

Steelcase provides employment opportunities to all qualified employees and applicants without regard to race, color, creed, genetic information, religion, national origin, gender, sexual orientation, gender identity and expression, age, disability, or veteran status and bases all employment decisions only on valid job requirements. If we can make the application process easier through accommodation, please email us at myhr@steelcase.com.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Identity Management Engineer
Senior Identity Management Engineer

Purchaseyourfreedom • Grand Rapids (MI)

On-site
USD 100,000 - 135,000
Vulnerability Management Engineer
Vulnerability Management Engineer

Purchaseyourfreedom • Grand Rapids (MI)

Hybrid
USD 110,000 - 160,000
Competitive wages & benefits
Flexible hybrid work schedule
Continuous learning opportunities
+2
Senior Data Engineer
Senior Data Engineer

Steelcase • Grand Rapids (MI)

On-site
USD 97,000 - 121,000
Flexible hybrid schedule
Learning & development opportunities
Inclusive culture
+1
Vulnerability Management Engineer
Vulnerability Management Engineer

Steelcase • Grand Rapids (MI)

Hybrid
USD 110,000 - 150,000
Hybrid work schedule
Continuing education and learning
Inclusive culture
+1
Cyber Manager - Governance, Risk and Compliance
Cyber Manager - Governance, Risk and Compliance

Steelcase • Grand Rapids (MI)

Hybrid
USD 150,000 - 200,000
Hybrid work model
Continual learning opportunities
Competitive wages and benefits
Senior Identity & Access Architect
Senior Identity & Access Architect

OEC • United States

Hybrid
USD 140,000 - 190,000
Staff Identity Governance and Access Engineer
Staff Identity Governance and Access Engineer

United States Digital Space LLC • Washington

On-site
USD 180,000 - 230,000
Staff Identity Engineer
Staff Identity Engineer

United States Digital Space LLC • Washington

On-site
USD 161,000 - 221,000
Equity
Health insurance
Dental & Vision insurance
+1
Senior Product Engineer
Senior Product Engineer

Steelcase • Grand Rapids (MI)

On-site
USD 99,000 - 115,000
Competitive wages
Learning opportunities
Inclusive culture
Senior Identity Platform Engineer — AI-Driven Security
Senior Identity Platform Engineer — AI-Driven Security

Steelcase • Grand Rapids (MI)

Hybrid
USD 100,000 - 135,000
Hybrid work schedule
Competitive wages and benefits
Continuous learning opportunities
+1