LEAD IT Specialist - SR. IT Specialist - Cloud Identity, PKI, and AI Specialist
Job in
San Antonio, Bexar County, Texas, 78201, USA
Listed on 2026-09-01
Listing for:
Southwest Research Institute - Fulltime
Full Time
position Listed on 2026-09-01
Job specializations:
-
IT/Tech
Azure, Cloud Computing: Infrastructure & Operations, Cybersecurity
Job Description & How to Apply Below
Who We Are:
Our team, the Cloud Services team within the Information Technology Center, is responsible for EntraID (formerly Azure)/M365 cloud services and Active Directory for the Enterprise. The team provides support and implementation services to the entire organization's IT infrastructure. Objectives of this Role:
Manage and enhance internal Public Key Infrastructure (PKI), ADFS (Active Directory Federation Services), and Certificate Lifecycle Management (e.g. Keyfactor Command) to maintain secure, reliable access to enterprise resources. Design and implement secure identity and access patterns for Azure and AWS services, including Azure OpenAI, Azure AI Hub/Foundry, Azure Cognitive Services, and AWS Bedrock. Lead the design, configuration, and maintenance of Entra (Azure AD) app registrations, service principals, and RBAC models that provide controlled, auditable access to cloud and AI workloads.
Collaborate across IT teams (Cloud, Security, Networking, Applications, Help Desk) to resolve complex issues related to AD, Entra , ADFS, PKI, certificates, and cloud identity. Drive best practices for identity and access management, Azure and AWS infrastructure governance, and operational scalability across cloud and on-premises environments. Maintain strong change control discipline and keep supporting documentation up to date. Daily and Monthly Responsibilities:
Manage and support internal PKI and certificate lifecycle processes, including:
Administration of CAs, OCSP/CRL endpoints, and certificate trust chains. Configuration and operation of Keyfactor Command certificate discovery, issuance, renewal, and revocation. Support and maintain identity and federation services, including Active Directory (user and group management, roles, delegation), Entra registrations, service principals, Conditional Access, RBAC, ADFS configuration and integration with internal and external applications. Collaborate with IT teams to resolve helpdesk tickets related to: AD and Entra and authorization issues.
ADFS sign-on/federation problems and claims troubleshooting. Certificate deployment, trust, and lifecycle problems impacting applications and services. Implement and maintain secure access for Azure and AWS AI platforms, including:
App registrations and security group-based access controls for Azure OpenAI, Azure AI Hub/Foundry, and Azure Cognitive Services. IAM roles, policies, and network/security configuration for AWS service. Maintain documentation of identity architectures, PKI designs, AI enablement patterns, and change records for audits and future engineers, and research and propose improvements to identity, PKI, certificate lifecycle, and AI enablement, including automation and governance tooling.
Requirements:
Requires a Bachelors degree in Information Technology or related degree field with relevant experience. In lieu of a Bachelors degree, 10 years of professional level experience, a high school education or equivalent with related certifications will be considered. Related Microsoft certifications are preferred. 6 years:
Hands-on experience managing enterprise identity platforms, including:
Active Directory domain services. Entra (Azure AD) app registrations, service principals, and Conditional Access. ADFS design, configuration, and support. 3 years:
Managing a PKI environment and certificate lifecycle, including:
Internal CA infrastructure, OCSP/CRL, and certificate templates. Demonstrated experience designing and securing access for Azure and/or AWS solutions, including at least some of the following:
Azure OpenAI, Azure AI Hub/Foundry, Azure Cognitive Services. AWS Bedrock or similar AWS AI/ML services. Strong understanding of identity and access management best practices, including:
Role-based access control (RBAC) in Azure and AWS. Least-privilege design, MFA, and Conditional Access. Governance and operational scalability in cloud environments. A valid/clear driver's license is required.
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×