Sr Identity Engineer

Lockton Companies

Kansas City (MO)

On-site

USD 120,000 - 150,000

Full time

2 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Lockton Companies in Kansas City, MO is seeking a Senior Identity Engineer – Operations to design, operate, and secure Microsoft Entra ID across the enterprise. You will own identity governance, Conditional Access, privileged access, application identities, and modern authentication controls, while partnering with security, platform, and regional teams to maintain secure, audit-ready identity services.

This role requires deep expertise in hybrid identity, MFA, and passwordless approaches, along

Qualifications

  • Engineer, operate, and secure Microsoft Entra ID in an enterprise environment, including hybrid identity with AD and Entra Connect.
  • Design, implement, and maintain Conditional Access policies enforcing MFA and Zero Trust across scenarios.
  • Define and enforce identity standards ensuring MFA and risk-based controls are applied.
  • Review admin consent for third-party enterprise app integrations.
  • Own app registrations, secrets, and certificate lifecycle management.
  • Design Graph permission models for apps and identity automation.
  • Define standards to prevent interactive sign-in for service accounts.
  • Implement Entra Privileged Identity Management (PIM) for admin roles and Just-In-Time elevation.
  • Operate Entra Administrative Units for delegated identity management across regions.
  • Support passwordless authentication (FIDO2) and external identity scenarios.
  • Partner with teams to deliver secure Azure access models.
  • Escalate complex identity incidents and produce audit-ready documentation.
  • Understand Microsoft 365 identity integrations with Entra ID.

Responsibilities

  • Own identity governance and access controls across the enterprise.
  • Manage Conditional Access, MFA, and device trust configurations.
  • Onboard enterprise applications and manage admin consent.
  • Support passwordless methods and external identity scenarios.
  • Collaborate with platform and security teams on Azure access models.
  • Serve as escalation point for complex identity incidents.
  • Produce audit-ready documentation for compliance.

Skills

Microsoft Entra ID
Hybrid identity
Conditional Access
Zero Trust
Identity governance
MFA
Privileged access management

Job description

Kansas City, Missouri, United States of America

At Lockton, we’re passionate about helping our people achieve their ultimate potential. Our people are curious, action-oriented and always striving to make ourselves and those around us better. We’re active listeners working to ensure understanding and problem solvers developing innovative solutions. If you can see yourself delivering excellent service to clients, giving back to our communities and being a part of our caring culture, you belong here.

The Senior Identity Engineer – Operations designs, operates, and secures Microsoft Entra ID and its integrations across the enterprise. This role owns identity governance, Conditional Access, privileged access, application identities, and modern authentication controls, while serving as a senior escalation point for complex access and authentication issues. The engineer partners with security, platform, and regional teams to maintain resilient, least-privilege identity services and audit-ready operational standards.

Qualifications
  • Engineer, operate, and secure Microsoft Entra ID in an enterprise environment, including hybrid identity with Active Directory and Entra Connect, directory health, monitoring, and incident response.
  • Design, implement, and maintain Conditional Access policies enforcing MFA, device trust, sign-in risk, and Zero Trust principles across access scenarios.
  • Design and enforce identity standards that eliminate network-based trust assumptions, ensuring MFA and risk-based access controls are consistently applied.
  • Review, approve, and operationalize admin consent for third-party enterprise application integrations across the tenant.
  • Own enterprise application and service principal onboarding, enforcing least-privilege access models and secure authentication patterns.
  • Create, manage, and govern App Registrations, including secret and certificate lifecycle management, rotation standards, and expiration monitoring.
  • Design and enforce least-privilege Microsoft Graph permission models for applications and identity automation.
  • Define and maintain standards that prevent interactive sign-in for service accounts, leveraging Conditional Access and non-interactive authentication models.
  • Define and enforce identity security guardrails for privileged access, MFA requirements, service accounts, and break-glass scenarios.
  • Implement and govern Microsoft Entra Privileged Identity Management (PIM) for administrative roles, just-in-time elevation, approval workflows, access reviews, and privileged access monitoring.
  • Design and administer Microsoft Entra Administrative Units to delegate identity and user management with scoped administrative control across regions, business units, and support teams.
  • Operate and evolve modern authentication and MFA methods globally, aligning with Microsoft Entra Authentication Methods and organizational security standards.
  • Support and standardize passwordless authentication approaches, including FIDO2 and hardware security keys, across regions and business units.
  • Support B2B, B2C, cross-tenant, and external identity scenarios for partners, vendors, and client-facing platforms.
  • Partner with platform, security, and Azure engineering teams to design and deliver secure Azure access models, role assignments, and identity integrations.
  • Act as the escalation point for complex identity-related incidents, authentication failures, and access issues.
  • Produce audit-safe documentation and evidence supporting security, compliance, and regulatory requirements.
  • Demonstrate a strong understanding of Microsoft 365 (M365) and its identity integrations with Entra ID, including authentication flows, access controls, and tenant-level governance considerations.

#LI-JM

Equal Opportunity Statement

Lockton Companies is proud to provide everyone anequal opportunity to grow and advance. We are committed to an inclusive culture and environment where our people, clients and communities are treated with respect and dignity.

At Lockton, supporting diversity, equity and inclusion is ingrained in our values, and we believe that we are at our best when we fully embrace everyone. We strive to cultivate a caring culture that learnsfrom, celebrates and thrives because of ourbreadth of differences. As such, we recognize that recruiting, developing and retaining people with diverse backgrounds and experiences is vital and enabling our people to thrive personally and professionally is critical to our long‑term success.

About Lockton

Lockton is the largest privately held independent insurance brokerage in the world. Since 1966, our independence has allowed us to serve our clients, take care of our people and give back to our communities. As such, our 13,100+ Associates doing business in over 155 countries are empowered to do what’s right every day.

At Lockton, we believe in the power of all people. You belong at Lockton.

How We Will Support You

At Lockton, we empower you to be true to yourself in all that you do. Your success is our success, and we provide opportunities to help you grow and create a rewarding career path, however you envision it.

We are ready to meet you where you are today, and as your needs change over time. In addition to industry-leading health insurance, we offer additional options to support your overall health and wellbeing.

Any Employment Agency, person or entity that submits an unsolicited resume to this site does so with the understanding that the applicant's resume will become the property of Lockton Companies, Inc. Lockton Companies will have the right to hire that applicant at its discretion and without any fee owed to the submitting Employment Agency, person or entity. Employment Agencies, who have fee Agreements with Lockton Companies must submit applicants to the designated Lockton Companies Employment Coordinator to be eligible for placement fees.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Sr MS365 Engineer - Copilot & Power Platform ...
Sr MS365 Engineer - Copilot & Power Platform ...

Lockton Companies • Kansas City (MO), Northern (KY)

Hybrid
USD 120,000 - 155,000
Health insurance
Senior Identity Engineer — Entra ID & Access Security
Senior Identity Engineer — Entra ID & Access Security

Lockton Companies • Kansas City (MO)

On-site
USD 120,000 - 150,000
Sr Cloud Engineer
Sr Cloud Engineer

Lockton Companies • Kansas City (MO)

On-site
USD 120,000 - 180,000
Health insurance
US Market Strategy & Engagement Leader
US Market Strategy & Engagement Leader

Lockton Companies • Kansas City (MO)

On-site
USD 140,000 - 180,000
Business Applications Analyst
Business Applications Analyst

Lockton Companies • Overland Park (KS)

On-site
USD 65,000 - 90,000
Lead Analytics Engineer
Lead Analytics Engineer

Lockton Companies • Kansas City (MO), Northern (KY)

Hybrid
USD 120,000 - 180,000
Health insurance
Wellbeing program
Account Manager -PRS
Account Manager -PRS

Lockton Companies • Kansas City (MO)

Hybrid
USD 60,000 - 90,000
12-week paid parental leave
Rolex after 10 years
Paid training and professional develop
+1
Account Administrator
Account Administrator

Lockton Companies • Kansas City (MO)

On-site
USD 42,000 - 62,000
Senior Account Manager- People Solutions
Senior Account Manager- People Solutions

Lockton Companies • San Francisco (CA), Northern (KY)

Hybrid
USD 110,000 - 170,000
Account Manager
Account Manager

Lockton Companies • Minneapolis (MN)

On-site
USD 60,000 - 85,000
12-week paid parental leave
Opportunities for growth and training
Community involvement
+2