Senior Identity System Engineer

Sanford HealthRapid City, SD
$40 - $66Onsite

About The Position

The Senior Identity Systems Engineer is an advanced technical role responsible for designing, implementing, and optimizing enterprise identity infrastructure across on-premises and cloud environments. This position leads the architecture of domain topologies, forest structures, and global replication, while ensuring hybrid identity solutions provide seamless sign-in experiences across platforms. The engineer drives the adoption of modern authentication protocols such as Kerberos, OAuth, OpenID Connect, and SAML, and leads initiatives around just-in-time access, privileged session monitoring, and automated access governance. Responsibilities include integrating systems through API calls (REST, SOAP, JSON), managing enterprise PKI and certificate lifecycles, enforcing security baselines via Group Policy, and ensuring compliance with regulatory frameworks such as SOX, HIPAA, and GDPR. In addition to technical execution, the Senior Identity Systems Engineer plays a mentoring role, guiding junior engineers in best practices and fostering team knowledge growth. With a focus on innovation and automation, this role ensures that the organization's identity services remain secure, resilient, and aligned with modern zero trust principles and evolving business needs. This role requires deep technical expertise in Active Directory, Entra ID, authentication protocols, Identity Governance Administration (IGA), Privileged Access Management (PAM) and PKI with a strong focus on information security, compliance, strong problem-solving skills, a security-first mindset, and least-privilege enforcement. The Senior Identity Systems Engineer ensures the organization's identity platforms are resilient, scalable, and secure to support business operations and protect sensitive data. The Senior Identity Systems Engineer will work closely with cross-functional IT, application, and security teams to ensure alignment with business objectives, regulatory requirements, and industry best practices.

Requirements

  • Bachelor’s degree required, in lieu of education, leadership may consider an Associate’s Degree plus 3 years of applicable experience in computer science or related field.
  • Minimum of 3-4 years applicable work experience required.
  • Supporting Active Directory, Domain Services, Hybrid Identities, & Entra ID.
  • Implementing SSO/MFA workflows using SAML 2.0 and/or OIDC.
  • Maintaining Public Key Infrastructure (PKI).
  • Supporting Identity Lifecycle & Access Governance workflows and technical integrations.
  • Implementation of information security standards and procedures including HIPAA and PCI.
  • Deep technical expertise in Active Directory, Entra ID, authentication protocols, Identity Governance Administration (IGA), Privileged Access Management (PAM) and PKI.
  • Strong focus on information security, compliance, strong problem-solving skills, a security-first mindset, and least-privilege enforcement.

Nice To Haves

  • Saviynt experience highly preferred.
  • Certifications (CISSP, CISA, CISM, Security+, CEH, etc.) are highly desired.

Responsibilities

  • Designing, implementing, and securing enterprise identity and access management infrastructure.
  • Ensuring reliable authentication, authorization, and access management across hybrid environments.
  • Leading the architecture of domain topologies, forest structures, and global replication.
  • Ensuring hybrid identity solutions provide seamless sign-in experiences across platforms.
  • Driving the adoption of modern authentication protocols (Kerberos, OAuth, OpenID Connect, SAML).
  • Leading initiatives around just-in-time access, privileged session monitoring, and automated access governance.
  • Integrating systems through API calls (REST, SOAP, JSON).
  • Managing enterprise PKI and certificate lifecycles.
  • Enforcing security baselines via Group Policy.
  • Ensuring compliance with regulatory frameworks (SOX, HIPAA, GDPR).
  • Mentoring junior engineers in best practices and fostering team knowledge growth.
  • Ensuring identity services remain secure, resilient, and aligned with zero trust principles.
  • Working closely with cross-functional IT, application, and security teams.

Benefits

  • Salary Range: $40.00 - $66.00
  • Pay starts at $40 and increases according to years of applicable experience.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service