Sr Engineer, IT Security (NTD)

Nintendo of America Inc

Redmond (WA)

On-site

USD 145,150 - 261,200

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

401(k)
Comprehensive medical benefits
Paid time off

Job summary

Nintendo of America Inc in Redmond, Washington seeks a Senior Engineer specializing in IT Security. This role involves evolving security for Microsoft 365, leading Identity and Access Management operations, and improving endpoint security across various devices.

The ideal candidate will have 8+ years of experience in IT/Security engineering, expertise in M365 administration, and strong automation skills in PowerShell and Python.

This position offers a salary range of $145,150—$261,200 USD, along with a comprehensive benefits package including medical, dental, vision, and 401(k).

Qualifications

  • 8+ years in enterprise IT/Security engineering with deep hands-on experience.
  • Expert-level experience with M365 & Entra ID.
  • Strong automation skills with PowerShell and Python.

Responsibilities

  • Own and evolve the security for Microsoft 365 tenant.
  • Drive Identity and Access Management operations.
  • Design and operate controls using existing and emerging technologies.

Skills

M365 administration
Identity and Access Management
Endpoint Security
Splunk
Automation skills
Fluency in Japanese

Education

Bachelor or Master of Science degree in Engineering or Information Technology

Tools

CrowdStrike Falcon
PowerShell
Python

Job description

Nintendo Technology Development is a wholly owned subsidiary of Nintendo, based in Redmond, Washington, focused on future hardware and software technology.

Nintendo is an equal opportunity employer and offers a welcoming and inclusive environment.

Senior Engineer, IT Security

The Senior Engineer, IT Security for Nintendo Technology Development Inc. (NTD) organization will own and evolve the security for our Microsoft 365 (M365) tenant, drive Identity and Access Management (IAM) operations, and harden endpoint security at scale across Windows, macOS, and Linux devices. This role will be the technical driver for secure collaboration and device protection; designing, implementing, and operating controls using existing and emerging technologies. This role requires partnership with NTD IT Operations, IT security teams at Nintendo Co., Ltd. (NCL), and Nintendo of America Inc. (NOA) to deliver reliable, compliant, and auditable services with measurable outcomes.

Description of Duties
M365 Tenant, Identity & Access Management
  • Implement and optimize Microsoft Entra Conditional Access, tenant security defaults, privileged access policies, and MFA/SSPR at scale.
  • Operate and harden Microsoft Entra ID (Azure AD): lifecycle governance, automated provisioning/deprovisioning, privileged identities (PIM), app registrations, consent/permission reviews.
  • Build and maintain RBAC/least-privilege access models for cloud and SaaS apps; implement Just-In-Time access for admins and sensitive roles.
  • Integrate HRIS and identity sources for Joiner-Mover-Leaver flows, enforce identity proofing and MFA step‑up for high‑risk transactions.
  • Design and enforce data governance (labels, DLP, retention, eDiscovery/Legal Hold, insider risk signals) and collaboration controls (external sharing, guest access, B2B/B2C).
  • Establish monitoring/alerting/SLAs for tenant and identity‑related services; lead incident response and help develop IR playbooks in conjunction with IT Security Operations.
Endpoint Security (Windows, macOS, Linux)
  • Own the migration from an existing endpoint management system to a more robust solution, such as the CrowdStrike Falcon platform, for all endpoints: sensor deployment/coverage, policy tuning, RTR workflows, and threat hunting guardrails.
  • Lead efforts with platform engineers for OS‑specific hardening baselines (CIS/NIST) and secure configuration: BitLocker/FileVault/LUKS, kernel extension/driver policies, local admin control, application allow/deny lists.
  • Lead incident triage and response on endpoints, including containment, forensic collection, and post‑incident hardening.
Observability, Detection & Response
  • Build and operationalize Splunk detections and dashboards integrating M365, Entra, CrowdStrike, Defender, Intune, and OS logs.
  • Develop automated response playbooks to reduce MTTR.
Automation & Engineering Excellence
  • Create robust automation and self‑service tooling for identity and endpoint operations.
  • Maintain IaC for policy‑as‑code (e.g., Conditional Access, PIM role settings).
  • Document runbooks, architecture diagrams, inventories, and SOPs; mentor engineers and drive operational maturity.
Compliance & Risk
  • Map controls to regulatory frameworks (SOX, J‑SOX, etc.); support audits with evidence and narratives.
  • Lead periodic access reviews, admin entitlement recertification, and break‑glass account governance.
  • Conduct tabletop exercises, disaster recovery testing, and security drills tied to identity and endpoint scenarios.

Up to 10% travel; domestic and international.

Summary of Requirements
  • 8+ years in enterprise IT/Security engineering with deep hands‑on experience in M365 administration, IAM operations, or endpoint security.
  • Expert‑level experience with M365 & Entra ID: Conditional Access, MFA/SSPR, PIM/PAM, app registrations, service principals, identity lifecycle.
  • Expert‑level experience with Endpoint Security: CrowdStrike Falcon or equivalent (policy design, RTR, detection tuning) across Windows, macOS, Linux.
  • Expert‑level experience with Logging/SIEM: Splunk or equivalent (search, dashboards, alerting, detection engineering).
  • Strong automation skills: PowerShell (Graph modules), Python, REST/Graph APIs; CI/CD and version control (Git).
  • Proven track record delivering secure baselines at scale (Intune/Jamf/MDM); leading incident response involving identity and endpoints.
  • Deep understanding of Zero Trust, least privilege, RBAC, token flows (OAuth/OIDC), and modern auth (MSAL).
  • Experience with compliance control design and audit support.
  • Experience mentoring others and cultivating technical breadth and depth on a team.
  • Fluency in Japanese a plus.
  • Bachelor or Master of Science degree in Engineering, Information Technology, or related field; or equivalent combination of education and experience.

This position includes the base pay range listed below, potential for a semi‑annual discretionary performance bonus, and a comprehensive benefits package that includes medical, dental, vision, 401(k), and paid time off.

Pay Range: $145,150—$261,200 USD

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Sr Engineer, IT Security (NTD)
Sr Engineer, IT Security (NTD)

Nintendo • Redmond (WA)

On-site
USD 145,000 - 262,000
Comprehensive benefits package including medical, dental, vision.
401(k)
Paid time off
+1
Sr Engineer, IT Security (NTD)
Sr Engineer, IT Security (NTD)

Nintendo of America Inc. • Redmond (WA)

On-site
USD 145,000 - 262,000
Senior IT Security Engineer: IAM, M365 & Endpoint Security
Senior IT Security Engineer: IAM, M365 & Endpoint Security

Nintendo of America Inc • Redmond (WA)

On-site
USD 145,000 - 262,000
401(k)
Comprehensive medical benefits
Paid time off
Engineer, Networking (NTD)
Engineer, Networking (NTD)

Nintendo • Redmond (WA)

On-site
USD 120,000 - 218,000
Medical, dental, and vision insurance
401(k) plan
Paid time off
+1
Engineer, Networking (NTD)
Engineer, Networking (NTD)

Nintendo of America Inc • Redmond (WA)

On-site
USD 120,000 - 218,000
Comprehensive benefits package
Performance bonus
401(k)
Senior IT Security Engineer — IAM & Endpoint Guardian
Senior IT Security Engineer — IAM & Endpoint Guardian

Nintendo of America Inc. • Redmond (WA)

On-site
USD 145,000 - 262,000
Engineer, Networking (NTD)
Engineer, Networking (NTD)

Nintendo of America Inc. • Redmond (WA)

On-site
USD 120,000 - 218,000
Medical benefits
Dental benefits
Vision benefits
+3
CONTRACT - Sr Systems Engineer, Cloud (NTD)
CONTRACT - Sr Systems Engineer, Cloud (NTD)

Nintendo of America Inc • Redmond (WA)

On-site
USD <1,000
Medical insurance
Employee assistance program
Paid sick leave
CONTRACT - Sr Engineer (NTD)
CONTRACT - Sr Engineer (NTD)

Nintendo • Redmond (WA)

On-site
Senior IT Security Engineer - IAM, Endpoints & Zero Trust
Senior IT Security Engineer - IAM, Endpoints & Zero Trust

Nintendo • Redmond (WA)

On-site
USD 145,000 - 262,000
Comprehensive benefits package including medical, dental, vision.
401(k)
Paid time off
+1