Authentication Engineer (Entra / AD) - 3667093

Lighthouse Technology ServicesBuffalo, NY
Hybrid

About The Position

Lighthouse Technology Services is partnering with our client to fill their Authentication Engineer specializing in AD and Entra position! This is a 12 month contract with potential to extend and will be hybrid in Buffalo, NY. This role will be a W2 employee of Lighthouse Technology Services. No C2C or subcontracting arrangements will be considered.

Requirements

  • 6+ years of hands-on experience engineering both Active Directory and Microsoft Entra ID in enterprise environments
  • Proven track record of strategic identity engineering beyond operational tasks, with demonstrated ability to design standards and modernization initiatives
  • Deep expertise in hybrid identity architecture including Entra Connect, Conditional Access, MFA, and authentication protocols (SAML, OAuth, OIDC)
  • Advanced PowerShell scripting and automation skills, with experience in Microsoft Graph API and REST API integration
  • Strong understanding of Zero Trust principles, Tier-0 security controls, and Identity Governance frameworks
  • Experience with monitoring and analytics tools such as Splunk, KQL, and CrowdStrike for identity threat detection
  • Solid knowledge of authentication technologies including Kerberos, LDAP/LDAPS, and certificate-based authentication
  • Background working in regulated environments with compliance frameworks such as SOX, NIST, or FFIEC preferred

Nice To Haves

  • Active Directory and Azure certifications highly preferred

Responsibilities

  • Design and implement strategic authentication frameworks and standards for enterprise Active Directory and Microsoft Entra ID environments
  • Lead automation initiatives to modernize identity services, including Conditional Access policy development and authentication hardening
  • Architect hybrid identity solutions leveraging Entra Connect, ensuring secure synchronization between on-premises AD and cloud environments
  • Develop advanced PowerShell scripts and Microsoft Graph API integrations to streamline identity lifecycle management and operational processes
  • Build and maintain monitoring solutions using Splunk and KQL for identity threat detection, incident investigation, and compliance reporting
  • Engineer Zero Trust security controls and Privileged Access Management frameworks to protect Tier-0 administration
  • Support incident management and troubleshooting for complex authentication and directory services issues
  • Collaborate with cybersecurity teams to evaluate and remediate identity vulnerabilities in regulated financial services environment
  • Create app registrations and service principals within Entra ID while managing certificate-based and passwordless authentication implementations
  • Document technical standards, configuration patterns, and governance processes for audit and compliance requirements
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service