Principal Identity and Access Management Engineer

Navy FederalPensacola, FL
Onsite

About The Position

Navy Federal Credit Union currently does not provide sponsorship for this role. Applicants must be authorized to work in the United States without the need for current or future sponsorship. The Principal IAM Engineer is a technical resource with intermediate or master level skills in the architecture, design, configuration, and management of Active Directory, Microsoft Entra, and modern authentication services. Your success with attaining and performing the required skills and abilities will be enhanced if they consist of the following:

Requirements

  • Bachelor’s Degree in Information Technology or the equivalent combination of education, training or experience
  • 7-10 years of experience in identity security engineering
  • Expert knowledge of identity security best practices surrounding account separation, JIT, least privilege, zero trust
  • Hands-on experience designing and managing Active Directory infrastructure. As evidenced by at least 1 current certification (Microsoft Certified Solutions Associate, or Microsoft Certified Solutions Expert with a focus on server infrastructure.) or the equivalent experience and training.
  • Solid understanding of design and implementation of modern authentication protocols, such as SAML, OIDC, FIDO, and PIV.
  • Strong foundational knowledge of Active Directory infrastructure, protocols and authentication patterns: Domain Controllers, Group Policy, Sites/Services Topology, Replication, Kerberos
  • Experience with the following: Microsoft Entra suite including: Conditional Access Azure SSO leveraging SAML/OIDC, Service Principals, and Agentic Identities Management of directory identity in Entra and M365, leveraging security policies, PIM, RBAC Identity Governance Defender for Identity Strata (Maverics) Identity Orchestration or similar Active Directory Federation Services Active Directory Lightweight Directory Services (AD-LDS) Microsoft Enterprise PKI leveraging OCSP Azure AD Connect

Nice To Haves

  • Strong identity security mindset with a proven ability to design and operate identity solutions that prioritize security, compliance, and long-term resilience
  • Advanced PowerShell Scripting techniques.
  • Knowledge of Golang and YAML.

Responsibilities

  • Identity provider administration, design and maintenance for Active Directory Federation Services, Strata Identity Orchestrator, Active Directory Lightweight Directory Services, Entra ID Identity federation implementation (with internal/external workforce applications.
  • Apply engineering principles into the design and enhancement of new and existing systems.
  • Ensure the security and integrity of system and product solutions including compliance with Navy Federal and Information Security principles and practices.
  • Present clear, organized, and concise information to all audiences through a variety of media to enable effective business decisions.
  • Perform engineering tasks and assignments in support of business needs.
  • Perform engineering technology research, procurement, deployment, and configuration for new and modified systems.
  • Perform other duties as assigned.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service