Entra/Active Directory Engineer
Listed on 2026-06-18
-
IT/Tech
Systems Engineer, Cybersecurity, Cloud Computing: Infrastructure & Operations, IT Support
Description
TGen, the Translational Genomics Research Institute, is part of City of Hope. We are an Arizona-based, nonprofit medical research institute dedicated to conducting groundbreaking research with life-changing results. No matter the role, every TGen employee contributes to success. Together, we work toward a common goal: improving medicine to enhance a patient’s quality of life. It’s not all biomarkers and sequencing; it is a mix of humanity improving the human condition.
Find your role at TGen, in an environment ignited by a profound purpose.
The work in our laboratories and offices leads to innovative scientific breakthroughs and improved quality of life. Collectively, we offer renewed hope to patients worldwide through our highly-specialized precision medicine approach that places the patient at the heart of all our work. For individuals faced with a dire medical condition, that story can be powerful and transformative. It can pinpoint a diagnosis, and lead to more precise and individual treatments.
That’s because TGen rapidly translates genomic research into medical practice by collaborating with the most progressive scientific and medical minds worldwide.
We are currently seeking a mid-level Entra/Active Directory Engineer
. This role is critical to building and maintaining the identity infrastructure in on-prem Active Directory (AD) and Entra (formerly Azure AD) that will better enable secure, frictionless, POSIX-compliant access for external users on the TGen HPC cluster while preserving each organization’s security and operational independence. It is a hybrid work location role, with some time in office required.
We are a human-centric organization that translates to our employees. Some of the perks in working for us:
- BC/BS of Arizona health coverage.
- Dental, Vision, Life, Short and Long Term Disability
- Top notch EAP with a full scope of concierge type services
- 401k with 6% match
- Generous time off
- Commuter benefits
- Much, much more!
- Microsoft Entra / AD
- Validate existing cloud-based Entra on-prem AD environment and configuration
- Validate existing Entra Okta Implementation, including Office
365 and Sharepoint related configuration. - Ensure compliance with Entra practices for all aspects of TGen Entra / O365 environment, including directory services, Exchange configuration, SharePoint, and others.
- Identity and Access Management
- Evaluate existing implementation of, and recommend best practice refinements to, Unix authentication to AD, including distribution of globally unique POSIX UID and GID Information sourced from on-prem AD, Entra , or Okta to HPC login and compute nodes (Rocky Linux
9) as well as network-attached or distributed file systems including Power Scale and VAST. - Work with business partners to identify, define, and implement best-practice-based forest configuration with external business partners which use Entra , including possible cross-integrations with TGen Okta identity management platform.
- Evaluate existing implementation of, and recommend best practice refinements to, Unix authentication to AD, including distribution of globally unique POSIX UID and GID Information sourced from on-prem AD, Entra , or Okta to HPC login and compute nodes (Rocky Linux
- Administration & Operations
- Manage daily operations of any cross-forest trusts, Entra AD services.
- Monitor trust health, Kerberos ticket flows, LDAP queries, and authentication performance.
- Automate repetitive tasks using Ansible and other scripting languages where appropriate.
- Collaborate with HPC engineers to ensure consistent identity resolution and caching behavior across all HPC login and compute nodes.
- Support the standardization of the installation, configuration, and hardening of SSSD/IdM client configurations for reliable user and group resolution, RBAC rules, sudo policies, and automount on HPC nodes on Linux Rocky 9 and associated infrastructure.
- Support & Troubleshooting
- Monitor for and troubleshooting Kerberos, SSSD, cross-forest referral issues, as well as Azure connectivity problems.
- Work with external collaborators (Entra ) on trust implementations, maintenance, selective authentication adjustments, and incident resolution.
- Ensure high availability and disaster recovery for IdM trust controllers and related components.
- Security & Compliance
- Implement least-privilege principles, selective authentication, and auditing for cross-forest access.
- Participate in…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).