Principal Identity System Engineer

Sanford HealthSioux Falls, SD

About The Position

The Principle Identity Systems Engineer is responsible for setting strategy and designing secure enterprise identity and access management infrastructure that enables reliable authentication, authorization, and access management across hybrid environments. Engineers in this family ensure that users, systems, and applications are authenticated, authorized, and protected in alignment with security standards, regulatory requirements, and business needs. The Principal Identity Systems Engineer is a senior technical leader responsible for setting the vision and driving enterprise-wide strategies for identity platforms across on-premises and cloud environments. This role defines and champions the IAM roadmap, establishes architectural standards for hybrid identity, Zero Trust, and cloud integrations, and collaborates closely with executives, architects, and security leadership to ensure alignment with business objectives and regulatory requirements. The Principal Identity Systems Engineer leads modernization efforts around Active Directory, Entra ID, PKI, and authentication services while evaluating emerging technologies to strengthen enterprise identity security. Core responsibilities include architecting domain and forest structures, overseeing hybrid identity synchronization, enforcing secure authentication protocols, and automating access governance, provisioning, and privileged access management. This role also monitors and enhances KRIs to proactively identify risks, conducts expert-level troubleshooting and root cause analysis, and provides guidance on audit and compliance initiatives. In addition, the Principal Identity Systems Engineer mentors senior and lead engineers, develops standards and playbooks, and represents identity services as a strategic enabler of secure, scalable business operations. Balancing deep technical execution with enterprise strategy, this position ensures the identity ecosystem is resilient, future-ready, and integral to the organization's long-term security posture. This role requires deep technical expertise in Active Directory, Entra ID, authentication protocols, Identity Governance Administration (IGA), Privileged Access Management (PAM) and PKI with a strong focus on information security, compliance, strong problem-solving skills, a security-first mindset, and least-privilege enforcement. The Principal Identity Systems Engineer ensures the organization's identity platforms are resilient, scalable, and secure to support business operations and protect sensitive data. The Principal Identity Systems Engineer will work closely with cross-functional IT, application, and security teams to ensure alignment with business objectives, regulatory requirements, and industry best practices.

Requirements

  • Bachelor’s degree required, in lieu of education, leadership may consider an Associate’s Degree plus 3 years of applicable experience in computer science or related field.
  • Minimum of 8 years applicable work experience required.
  • Supporting Active Directory, Domain Services, Hybrid Identities, & Entra ID
  • Implementing SSO/MFA workflows using SAML 2.0 and/or OIDC
  • Maintaining Public Key Infrastructure (PKI)
  • Supporting Identity Lifecycle & Access Governance workflows and technical integrations
  • Implementation of information security standards and procedures including HIPAA and PCI
  • Expert knowledge of Cloud security principles
  • One or more security certifications (CISSP, CISA, CISM, Security+, CEH, etc.) are required

Responsibilities

  • Setting strategy and designing secure enterprise identity and access management infrastructure
  • Ensuring users, systems, and applications are authenticated, authorized, and protected
  • Setting the vision and driving enterprise-wide strategies for identity platforms
  • Defining and championing the IAM roadmap
  • Establishing architectural standards for hybrid identity, Zero Trust, and cloud integrations
  • Leading modernization efforts around Active Directory, Entra ID, PKI, and authentication services
  • Evaluating emerging technologies to strengthen enterprise identity security
  • Architecting domain and forest structures
  • Overseeing hybrid identity synchronization
  • Enforcing secure authentication protocols
  • Automating access governance, provisioning, and privileged access management
  • Monitoring and enhancing KRIs to proactively identify risks
  • Conducting expert-level troubleshooting and root cause analysis
  • Providing guidance on audit and compliance initiatives
  • Mentoring senior and lead engineers
  • Developing standards and playbooks
  • Representing identity services as a strategic enabler of secure, scalable business operations
  • Ensuring the identity ecosystem is resilient, future-ready, and integral to the organization's long-term security posture
  • Ensuring the organization's identity platforms are resilient, scalable, and secure
  • Working closely with cross-functional IT, application, and security teams
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service