Senior Identity Engineer

Sunrise Senior LivingMclean, VA
2d

About The Position

When you join Sunrise Senior Living, you will be able to use your unique skills to empower residents to live longer, healthier, and happier lives. Not only will you build meaningful relationships with residents, their families, and team members alike, you will also gain joy in serving others and deep fulfillment in your work. Explore how you can follow your passions and shed light on meaningful ways to serve, grow, and shine together. Sunrise Senior Living was again certified as a Great Place to Work® by Activated Insights. This is the 8th time Sunrise has received this top culture and workplace designation, highlighting the special place Sunrise is to be a part of. The Senior Identity Engineer is a hands-on technical owner for Sunrise’s enterprise Identity & Access Management (IAM) platform across Hybrid Active Directory and Microsoft Entra ID, with a roadmap to fully migrate to Entra and offload legacy authentication mechanisms. The role owns application onboarding to SSO, HRIS-driven identity lifecycle automation, privileged and group access models, Conditional Access policy design, self-service password reset and passwordless authentication, while establishing robust monitoring, documentation and stakeholder training.

Requirements

  • Programming experience in Python (or similar) and strong PowerShell skills for directory and application automation.
  • Deep experience with Active Directory, Azure Active Directory / Entra ID, and hybrid identity architectures.
  • Hands-on experience with SAML, OAuth 2.0, and OpenID Connect (OIDC), including token and claim design, scopes, consent, refresh and PKCE flows, and session management.
  • Experience designing, operating, and decommissioning ADFS or similar platforms, including secure migration to modern authentication.
  • Proven ability to onboard and maintain large numbers of enterprise applications, standardizing metadata, attribute mappings, and provisioning workflows.
  • Experience with HRIS-driven JML processes, SCIM or API-based provisioning and deprovisioning, orphaned account controls, and access recertification support.
  • Policy design, testing, rollout, and exception handling experience, including passwordless authentication approaches such as FIDO2 and passkeys.
  • Exposure to regulated environments (e.g., HIPAA, SOC 2) and experience supporting audits.
  • Experience using REST APIs or Microsoft Graph API for advanced automation and reporting.
  • Bachelor’s degree in Computer Science, Engineering, or a related field, or equivalent practical experience.

Responsibilities

  • Operate and improve hybrid identity (on-prem Active Directory and Entra ID), directory synchronization, and domain/namespace hygiene; plan and execute a staged migration toward an Entra-first model.
  • Lead deprecation of legacy authentication schemes (e.g., ADFS where appropriate), migrate applications to modern federation protocols (SAML, OAuth, OIDC), and document cutover and rollback procedures.
  • Own intake and integration patterns for single sign-on (SSO) across enterprise and third-party applications; enforce standards for claims, groups, roles, and provisioning, and maintain a service catalog.
  • Implement and maintain HR-driven joiner, mover, and leaver (JML) workflows using SCIM, APIs, or ETL processes, including authoritative source mapping, attribute governance, and automated access grants and revocations.
  • Design role-based access control (RBAC) models and dynamic group strategies; codify least-privilege access patterns across directories, applications, and data.
  • Engineer policies for device and user risk, network and location-based controls, and session management; manage authentication methods such as push notifications, TOTP, FIDO2, passkeys, and certificate-based authentication.
  • Define the roadmap for passwordless authentication adoption, implement solutions for targeted populations, and track adoption, support needs, and exceptions.
  • Build and maintain automation using Python and PowerShell for provisioning, policy enforcement, reporting, and configuration drift detection; manage scripts and runbooks in source control.
  • Publish standards, reference integrations, and training materials for IT, HR, and application teams; provide office hours and targeted workshops.
  • Maintain compliance in assigned required training and all training required by state/province or other regulating authorities as applicable to this role to ensure that Sunrise standards are always met.
  • Perform other duties as assigned.

Benefits

  • Medical, Dental, Vision, Life, and Disability Plans
  • Retirement Savings Plans
  • Employee Assistant Program / Discount Program
  • Paid time off (PTO), sick time, and holiday pay
  • myFlexPay offered to get paid within hours of a shift
  • Tuition Reimbursement
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service