Principal IAM/AD Engineer
Listed on 2025-11-27
-
IT/Tech
Cybersecurity, IT Support
Base pay range
$/yr - $/yr
OverviewMath Works has a hybrid work model that enables staff members to split their time between office and home. This model provides the advantage of in‑person collaboration with colleagues while also supporting flexible at‑home life optimizations. Learn More:
Do you design secure, resilient Active Directory at scale and enjoy automating identity operations? Join our Security Operations IAM team responsible for enterprise identity foundations across on‑prem Active Directory and Microsoft Entra partner with Security Engineering, IT, and Compliance to deliver hardened directory services, modern authentication, ITDR capabilities, and Zero‑Trust controls that enable the business.
Math Works nurtures growth, appreciates inclusivity, encourages initiative, values teamwork, shares success, and rewards excellence.
Responsibilities- Operate and maintain on‑premises Active Directory: domain controller health, patching, promotion/demotion, replication, sites/subnets, time services, SYSVOL/GPO health, and capacity monitoring.
- Implement and manage Entra :
Conditional Access, Identity Protection risk policies, PIM, and app registrations/service principals. - Monitor, troubleshoot, and optimize directory synchronization and identity lifecycle flows.
- Partner with our SOC to drive a successful ITDR program. Build and tune detections to identify threats such as DCSync, Golden/Silver Ticket, Kerberoasting, pass‑the‑hash/ticket, risky sign‑ins, and impossible travel.
- Harden AD and Entra baselines, admin tiering, PAW usage, secure delegation, privileged workflow controls, regular access reviews, and identity threat hunting.
- Automate identity operations and ITDR tasks with Power Shell and APIs (Graph/Entra): alert enrichment, response runbooks, access certifications, reporting, and drift remediation.
- Lead complex troubleshooting and incident response for identity (Kerberos/NTLM, replication, DCSync/Golden/Silver Ticket detections, Conditional Access failures); drive root cause and preventive actions.
- Produce runbooks, standards, and change records; mentor team members and collaborate with stakeholders to align IAM operations with business needs.
- A bachelor's degree and 10 years of professional work experience (or equivalent experience) is required.
- 7+ years in enterprise Active Directory operations and hardening including DC lifecycle management, sites/services, replication, BCDR, and observability.
- Hands‑on experience with Microsoft Entra l Access, MFA, Identity Protection, PIM, app registration and service principal governance.
- Experience operating Azure AD Connect or Cloud Sync in hybrid identity environments.
- Identity Governance and Administration experience for provisioning, role/entitlement models, and access certifications.
- Proficiency with Power Shell, Python and Microsoft Graph/Entra APIs for automation.
- Experience with privileged access models and administrative tiering.
- Ability to support after‑hours maintenance and incident response as needed.
- SSO/Federation: SAML/OIDC/OAuth; SCIM provisioning to SaaS apps.
- AD security: trusts, LDAP/LDAPS, constrained delegation, GPO hardening, PAWs.
- PKI and certificates: AD CS, CRL/OCSP, auto enrollment, renewal automation for workloads and service principals/certs.
- Backup/Recovery: authoritative restore, forest recovery planning and drills.
- IaC/automation: DSC, GPO as Code, Git workflows; CI/CD familiarity for scripts/policies.
- Compliance familiarity: CMMC, NIST CSF/800‑53/171, ISO 27001
Mid‑Senior level
Employment typeFull‑time
Job functionStrategy/Planning, Information Technology, and Engineering
Location:
Natick, MA
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).