Senior Systems Engineer (Iam
Listed on 2026-08-22
-
IT/Tech
Cybersecurity, Systems Engineer
The Opportunity:
Avantor is looking for Senior Identity Access Management (IAM) Engineer will lead the implementation, administration, and optimization IAM systems and services across enterprise environments. This role is essential for maintaining security, compliance, and operational efficiency in on-prem, self-hosted, and cloud-based environments.
As a Senior IAM Engineer, you will collaborate closely with Engineering Services teams, Engineering Architects, cloud providers, and system administrators to implement best practices for both on-premises and cloud-based IAM solutions. Serving as a subject matter expert in identity management and authentication technologies, you will provide global Tier 3 support and troubleshooting for all IAM services, including but not limited to Active Directory services, EntraID (Azure AD) services, cloud services, single sign-on integrations, Identity management, Certificate services, and PAM solutions.
This role requires strong technical expertise, problem-solving skills, and the ability to drive IAM initiatives that enhance security while supporting business objectives.
Key Responsibilities Identity and Access Management- Support and enhance IAM tools and services, focusing on secure user privileges, credential management, and access control.
- Strong knowledge of Active Directory and Entra (Azure AD) services e.g. – AD Domain Services, Azure AD Connect, GPOs, DHCP, DNS, AD Certificate Services, DFS, MIM, MFA, SSO, etc.
- Strong knowledge of AD Integration, synchronization and federation with Azure, Entra (Azure AD), Office 365, Duo, Identity Governance as well as Windows Server OS administration.
- Strong knowledge of Entra (Azure AD) Conditional Access Polices.
- Strong knowledge of Active Directory and Entra (Azure AD) security best practices that follow NIST, SOX, GDPR, framework.
- Strong experience in Active Directory services demoting and promoting domain controllers.
- Strong troubleshooting experience in Active Directory services and Entra (Azure AD) incident and problem management.
- Strong knowledge of developing processes for IAM governance, compliance, and reporting.
- Good knowledge of designing and implementing policies around Delegated Administration for managing Group Policy Objects, Servers, and Devices.
- Good knowledge of cloud technologies, especially AWS would be a plus.
- Good knowledge of PAM technologies, especially Cyber Ark would be a plus.
- Good knowledge of Identity technologies, especially Saviyant would be a plus.
- Collaborate with IT, security, and compliance teams to design and implement IAM and PAM strategies.
- Act as a subject matter expert on Cyber Ark and IAM technologies, providing training and mentorship to team members.
- Ensure alignment of IAM solutions with organizational security and compliance requirements.
- Represent the IAM function during audits, assessments, and stakeholder discussions.
- Bachelor's degree in Computer Science, Information Systems, or related field (or equivalent experience).
- Additional certifications (e.g., Microsoft, AWS, Azure, CISSP) are a plus.
- 10+ years of IT experience with a focus on IAM and security solutions.
- 5+ years of Tier 3 experience with IAM systems like Active Directory and EntraID implementations and management.
- Proven expertise in Active Directory, Azure AD, LDAP, PKI, SSO, and 2FA systems.
- Hands-on experience with scripting (Power Shell, Python, Java or other) for automation and system integration.
- Deep understanding of privileged access management principles, including least privilege enforcement and session monitoring.
- Strong knowledge of Active Directory services, group policies, DNS, and certificate services.
- Proficiency in integrating IAM tools with cloud environments (e.g., AWS, Azure).
- Excellent troubleshooting, analytical thinking, and communication skills.
- Ability to define and drive projects from concept to completion, ensuring alignment with deadlines.
- Flexible work options, including hybrid, or on-site arrangements.
- Occasional after-hours support and on-call responsibilities for critical systems.
The above statements are intended to describe the general nature and level of work being performed by employees assigned to this classification. They are not intended to be construed as an exhaustive list of all responsibilities, duties and skills required of employees assigned to this position. Avantor is proud to be an equal opportunity employer.
Why Avantor?Dare to go further in your career. Join our global team of 14,000+ associates whose passion for discovery and determination to overcome challenges relentlessly advances life-changing science.
The work we do changes people's lives for the better. It brings new patient treatments and therapies to market, giving a cancer survivor the chance to walk his daughter down the aisle. It enables medical devices that help a little boy hear his mom's voice for the first…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).