Senior Engineer — Identity Infrastructure & MA & D

CencoraConshohocken, PA
Hybrid

About The Position

We are seeking a Senior Engineer — Identity Infrastructure & MA&D to serve as a technical leader responsible for the design, integration, and optimization of Cencora's identity platform across on-premises Active Directory, Microsoft Entra ID (formerly Azure AD), and related authentication/authorization services. This role is central to our corporate development strategy: you will lead the identity workstream for acquisitions (onboarding users, devices, and applications from acquired entities into Cencora's identity ecosystem) and divestitures (cleanly separating identity services and severing trust relationships). Identity is the foundational layer that gates access to every system, application, and resource — making this one of the most critical and complex workstreams in any deal. The ideal candidate combines deep Active Directory and Entra expertise with the structured, security-conscious mindset required to execute identity transitions without disrupting user productivity or compromising the security posture of either organization. The primary focus of this role includes advanced identity infrastructure design, MA&D identity integration/separation, authentication and access management, complex troubleshooting, and cross-functional technical leadership.

Requirements

  • Bachelor’s degree or technical institute degree/certificate in a relevant field or equivalent work experience.
  • Typically requires 8 or more years of relevant IT work experience.
  • Relevant certification is required.
  • Demonstrates in-depth knowledge of a broad range of hardware and software products.
  • Strong experience with Unix-based systems and command-line interfaces.
  • Experience with Terraform or other infrastructure as code.
  • Familiarity with Git or other version control systems.
  • Good analytical and problem-solving skills.
  • Good interpersonal skills; effective team player.
  • Exceptional presentation skills.
  • Ability to prioritize load.
  • Technical leadership, negotiation, and conflict resolution.
  • Ability to be on-site as needed in Conshohocken, PA.

Nice To Haves

  • Experience leading technical teams.
  • Strong experience with AWS, including EC2, S3, Lambda, and IAM.
  • Experience with RDS/MySQL/database management.
  • Knowledge of networking concepts such as DNS, TCP/IP, and load balancing.

Responsibilities

  • Design and maintain Cencora's enterprise identity architecture spanning on-premises Active Directory Domain Services (AD DS), Microsoft Entra ID, Entra Connect (formerly Azure AD Connect), and Entra Domain Services — ensuring a resilient, well-governed, and scalable identity platform.
  • Own the AD forest and domain topology — manage domain controllers, sites and services, replication topology, FSMO roles, Group Policy (GPO) architecture, and OU structure across a multi-site enterprise environment.
  • Administer and optimize Microsoft Entra ID — manage tenant configuration, application registrations, enterprise app SSO integrations (SAML, OIDC, WS-Fed), Entra Connect sync rules, and hybrid identity topologies.
  • Manage multi-factor authentication (MFA) and Conditional Access — design and enforce Entra MFA policies, Conditional Access frameworks, authentication strengths, and risk-based access controls aligned with zero-trust principles.
  • Oversee certificate services and PKI where applicable — AD Certificate Services (AD CS), certificate templates, auto-enrollment, and certificate-based authentication.
  • Perform advanced troubleshooting of complex identity issues — Kerberos/NTLM authentication failures, AD replication conflicts, Entra Connect sync errors, token issuance problems, Conditional Access policy conflicts, and hybrid join issues.
  • Drive identity automation — leverage PowerShell, Microsoft Graph API, and automation platforms to streamline user lifecycle management, group management, and identity governance tasks.
  • Document and maintain identity architecture diagrams, trust relationship maps, Entra Connect topology, GPO standards, and operational run-books.
  • Lead the identity workstream for each MA&D event end-to-end — from due diligence through Day 1 access enablement to full identity consolidation or separation and steady-state hand-off.
  • Conduct identity discovery and assessment of target company environments: inventory AD forests/domains, domain controllers, Entra tenants, federation services (AD FS, PingFederate, Okta, etc.), MFA solutions, PAM tools, and SSO-integrated applications.
  • Develop identity integration blueprints that define the path from Day 0 (deal close) to full consolidation — including interim coexistence strategies, trust relationships, Entra B2B/cross-tenant access, GAL synchronization, and phased user migration plans.
  • Architect and execute AD consolidation — design inter-forest trust relationships, plan and execute domain migrations (ADMT or equivalent), migrate user accounts, computer objects, group memberships, SID history, and GPOs into the Cencora AD environment.
  • Plan and execute Entra ID tenant consolidation — migrate cloud identities, application registrations, Conditional Access policies, and MFA registrations from the acquired tenant into Cencora's Entra tenant using cross-tenant migration tools and Microsoft Graph.
  • Manage Entra Connect reconfiguration — transition sync scope, filtering rules, and hybrid identity topology as domains and OUs are consolidated.
  • Coordinate user MFA re-enrollment or migration — ensure acquired users are seamlessly onboarded to Cencora's Entra MFA policies with minimal friction, planning for authentication method registration, Authenticator app rollout, and fallback methods.
  • Enable Day 1 access — ensure acquired employees have functional credentials, email, and access to critical systems from the moment the deal closes, even before full consolidation (e.g., via Entra B2B, external identities, or temporary trust configurations).
  • Architect identity separation plans that cleanly extract divested users, groups, service accounts, and computer objects from Cencora's AD and Entra environments into a new or target-company identity platform.
  • Stand up greenfield identity infrastructure where needed — new AD forests/domains, Entra tenants, Entra Connect instances, MFA policies, and Conditional Access baselines for the divested entity.
  • Manage coexistence during TSA periods — design interim trust relationships, cross-tenant access policies, and shared authentication mechanisms that allow continued access to shared resources until the Transition Services Agreement expires.
  • Plan and execute credential cutover — coordinate the transition of user identities, passwords (or forced resets), MFA methods, and device registrations to the divested entity's identity platform with minimal disruption.
  • Sever trust relationships and remove residual access — methodically decommission forest/domain trusts, Entra B2B relationships, cross-tenant configurations, and stale objects post-TSA to eliminate security exposure.
  • Collaborate cross-functionally with Security, Network, Messaging/M365, Application, Endpoint, and GRC teams to ensure identity changes are coordinated with dependent systems — email migration, device management (Intune), application SSO cutover, and security tooling.
  • Partner with Project Management and Corporate Development to align identity milestones with broader deal timelines, legal close dates, budgets, and business commitments.
  • Coordinate with the acquired/divested company's IT staff to gather requirements, validate discoveries, and execute joint cutover activities.
  • Develop and enforce identity standards and policies, ensuring compliance with Cencora security and regulatory requirements (e.g., HIPAA, SOX, DEA) and zero-trust principles.
  • Mentor and guide junior identity and systems engineers; serve as the technical escalation point for complex identity incidents.
  • Build repeatable MA&D identity playbooks — standardize discovery templates, migration checklists, cutover run-books, and rollback procedures to accelerate and de-risk future deals.

Benefits

  • Compensation, benefits, and resources that enable a highly inclusive culture and support our team members’ ability to live with purpose every day.
  • Traditional offerings like medical, dental, and vision care.
  • A comprehensive suite of benefits that focus on the physical, emotional, financial, and social aspects of wellness.
  • Support for working families, which may include backup dependent care, adoption assistance, infertility coverage, family building support, behavioral health solutions, paid parental leave, and paid caregiver leave.
  • A variety of training programs.
  • Professional development resources.
  • Opportunities to participate in mentorship programs, employee resource groups, volunteer activities, and much more.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service