Sr Identity Engineer

Socket.dev

Kansas City (MO)

On-site

USD 130,000 - 170,000

Full time

5 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Socket.dev is seeking a Senior Identity Engineer - Operations to design, operate, and secure Microsoft Entra ID and its integrations across the enterprise. You will own identity governance, Conditional Access, privileged access, app identities, and modern authentication controls, while serving as a senior escalation point for complex access issues.

The role partners with security, platform, and regional teams to maintain resilient, least-privilege identity services and audit-ready operational

Qualifications

  • Extensive experience operating Microsoft Entra ID in an enterprise setting.
  • Implement and manage Conditional Access, MFA, and Zero Trust controls.
  • Ability to onboard and govern apps, service principals, and Graph permissions.
  • Strong collaboration with security, platform, and regional teams.

Responsibilities

  • Operate and secure Entra ID across hybrid environments with AD and Entra Connect.
  • Design and enforce Conditional Access policies and MFA across scenarios.
  • Manage admin consent, app registrations, secrets, and certificate lifecycles.
  • Implement Entra Privileged Identity Management and just-in-time elevation.
  • Define identity standards preventing interactive sign-in for service accounts.
  • Provide escalation support for complex identity incidents and audit evidence.

Job description

The Senior Identity Engineer - Operations designs, operates, and secures Microsoft Entra ID and its integrations across the enterprise. This role owns identity governance, Conditional Access, privileged access, application identities, and modern authentication controls, while serving as a senior escalation point for complex access and authentication issues. The engineer partners with security, platform, and regional teams to maintain resilient, least-privilege identity services and audit-ready operational standards.

  • Engineer, operate, and secure Microsoft Entra ID in an enterprise environment, including hybrid identity with Active Directory and Entra Connect, directory health, monitoring, and incident response.
  • Design, implement, and maintain Conditional Access policies enforcing MFA, device trust, sign-in risk, and Zero Trust principles across access scenarios.
  • Design and enforce identity standards that eliminate network-based trust assumptions, ensuring MFA and risk-based access controls are consistently applied.
  • Review, approve, and operationalize admin consent for third-party enterprise application integrations across the tenant.
  • Own enterprise application and service principal onboarding, enforcing least-privilege access models and secure authentication patterns.
  • Create, manage, and govern App Registrations, including secret and certificate lifecycle management, rotation standards, and expiration monitoring.
  • Design and enforce least-privilege Microsoft Graph permission models for applications and identity automation.
  • Define and maintain standards that prevent interactive sign-in for service accounts, leveraging Conditional Access and non-interactive authentication models.
  • Define and enforce identity security guardrails for privileged access, MFA requirements, service accounts, and break-glass scenarios.
  • Implement and govern Microsoft Entra Privileged Identity Management (PIM) for administrative roles, just-in-time elevation, approval workflows, access reviews, and privileged access monitoring.
  • Design and administer Microsoft Entra Administrative Units to delegate identity and user management with scoped administrative control across regions, business units, and support teams.
  • Operate and evolve modern authentication and MFA methods globally, aligning with Microsoft Entra Authentication Methods and organizational security standards.
  • Support and standardize passwordless authentication approaches, including FIDO2 and hardware security keys, across regions and business units.
  • Support B2B, B2C, cross-tenant, and external identity scenarios for partners, vendors, and client-facing platforms.
  • Partner with platform, security, and Azure engineering teams to design and deliver secure Azure access models, role assignments, and identity integrations.
  • Act as the escalation point for complex identity-related incidents, authentication failures, and access issues.
  • Produce audit-safe documentation and evidence supporting security, compliance, and regulatory requirements.
  • Demonstrate a strong understanding of Microsoft 365 (M365) and its identity integrations with Entra ID, including authentication flows, access controls, and tenant-level governance considerations.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Microsoft Entra ID Engineer
Microsoft Entra ID Engineer

Veriipro • Indianapolis (IN)

On-site
USD 110,000 - 140,000
Senior Entra Identity Engineer — Secure & Govern Access
Senior Entra Identity Engineer — Secure & Govern Access

Socket.dev • Kansas City (MO)

On-site
USD 130,000 - 170,000
Sr Entra ID Integration Engineer
Sr Entra ID Integration Engineer

Koniag Government Services • Washington

Hybrid
USD 140,000 - 190,000
Medical Insurance
Dental Insurance
Vision Insurance
+8
Entra ID Engineer
Entra ID Engineer

VOLTO Consulting • Indianapolis (IN)

On-site
USD 110,000 - 165,000
Entra ID Engineer
Entra ID Engineer

RedMatter Solutions LLC • Washington

Hybrid
USD 120,000 - 180,000
Sr. Identity Security Engineer Active Directory & Entra ID
Sr. Identity Security Engineer Active Directory & Entra ID

MathWorks • Natick (MA)

On-site
USD 122,000 - 190,000
Infrastructure Engineer
Infrastructure Engineer

Huxley • Boston (MA)

On-site
USD 120,000 - 150,000
Workplace Engineer (P4) - Microsoft 365 and Entra Platform
Workplace Engineer (P4) - Microsoft 365 and Entra Platform

Chemical Abstracts Service • Columbus (OH)

On-site
USD 120,000 - 170,000
Solutions Architect - AD/Entra Architect
Solutions Architect - AD/Entra Architect

Texas Instruments • Dallas (TX)

On-site
USD 140,000 - 200,000
Solutions Architect - AD/Entra Architect
Solutions Architect - AD/Entra Architect

Texas Instruments Incorporated • Dallas (TX), Northern (KY)

Hybrid
USD 140,000 - 190,000