More jobs:
Mid-Level Entra/Active Directory Engineer
Job in
Phoenix, Maricopa County, Arizona, 85003, USA
Listed on 2026-07-29
Listing for:
Jobtailor
Full Time
position Listed on 2026-07-29
Job specializations:
-
IT/Tech
Cybersecurity, Systems Engineer, Cloud Computing: Infrastructure & Operations, Systems Administrator
Job Description & How to Apply Below
Responsibilities
- Validate existing cloud-based Entra on-prem AD environment and configuration
- Validate existing Entra Okta Implementation, including Office
365 and Sharepoint related configuration - Ensure compliance with Entra practices for all aspects of TGen Entra / O365 environment, including directory services, Exchange configuration, SharePoint, and others
- Evaluate existing implementation of, and recommend best practice refinements to, Unix authentication to AD, including distribution of globally unique POSIX UID and GID
- Work with business partners to identify, define, and implement best-practice-based forest configuration with external business partners which use Entra , including possible cross-integrations with TGen Okta identity management platform
- Manage daily operations of any cross-forest trusts, Entra AD services
- Monitor trust health, Kerberos ticket flows, LDAP queries, and authentication performance
- Automate repetitive tasks using Ansible and other scripting languages where appropriate
- Collaborate with HPC engineers to ensure consistent identity resolution and caching behavior across all HPC login and compute nodes
- Support the standardization of the installation, configuration, and hardening of SSSD/IdM client configurations for reliable user and group resolution, RBAC rules, sudo policies, and automount on HPC nodes on Linux Rocky 9 and associated infrastructure
- Monitor for and troubleshooting Kerberos, SSSD, cross-forest referral issues, as well as Azure connectivity problems
- Work with external collaborators (Entra ) on trust implementations, maintenance, selective authentication adjustments, and incident resolution
- Ensure high availability and disaster recovery for IdM trust controllers and related components
- Implement least-privilege principles, selective authentication, and auditing for cross-forest access
- Participate in security reviews, audits, and compliance activities related to the identity infrastructure, including Entra
-side controls - Work closely with external partners’ Entra IAM teams for trust configuration, network connectivity, and ongoing coordination
- Collaborate with TGen HPC system engineers managing storage/NFS configuration on Power Scale and VAST, as well as external partners accessing these HPC file systems on edge devices
- Coordinate with TGen information security team as needed to establish Entra and AD configuration policies that meet TGen requirements
- Bachelor’s degree in Computer Science, Information Technology, or related field (or equivalent experience)
- 5+ years of hands‑on experience in enterprise Identity and Access Management, with strong focus on hybrid Windows‑Linux and cloud/on‑premises environments
- Deep expertise in Entra , On‑Prem AD (creating and managing forest/domain trusts, selective authentication, Kerberos, DNS integration, Entra Domain Services forest trusts)
- Track record of clearly documenting architectures, procedures, and runbooks
- Proven ability to own the end‑to‑end creation and delivery of the on‑premises trust and identity infrastructure while balancing operational support
- Solid understanding of POSIX UID/GID management, SID‑to‑POSIX algorithmic mapping, and ensuring consistency for shared file system access
- Proficiency with automation tools (Ansible, Power Shell, Azure CLI)
- Knowledge of Microsoft Entra d scenarios, including Entra Domain Services forest trusts
- Relevant certifications:
Microsoft Certified:
Identity and Access Administrator Associate (or Entra ), or Azure Network Engineer - Strong troubleshooting expertise using Microsoft Entra (Sign‑in Logs, Audit Logs, Provisioning Logs, and the Diagnose and Solve Problems blade), Kerberos commands (klist, nltest), packet analysis (Wireshark), Azure connectivity diagnostics (Azure Network Watcher), and Linux identity tools (sssctl, journalctl, SSSD debug logging)
- Practical experience with Rocky Linux 9 / RHEL 9, preferably in cluster environments and large‑scale Linux deployments
- Familiarity with or experience in HPC or scientific computing environments, particularly with identity challenges on login/compute nodes
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×