Staff Identity Engineer (Radiant One)

NBCUniversalNew York, NY
$125,000 - $155,000Remote

About The Position

Join the NBCUniversal Identity and Access Management team as a Staff Engineer focused on Identity Provisioning and Directory Services. This role owns the architecture, design, and evolution of our directory virtualization and provisioning capabilities that underpin identity correlation, authentication, and provisioning across NBCU's enterprise workforce. This is a hands-on role: you will design solutions, provide input to technical direction, mentor other engineers, and partner across IAM, security architecture, and application teams to solve complex, large-scale directory and provisioning challenges.

Requirements

  • Bachelor's degree in Computer Science, Information Security, or related field, or equivalent work experience
  • 8+ years of hands-on experience in enterprise Identity and Access Management, with a concentration in identity provisioning and directory services
  • Hands-on production experience with Radiant Logic RadiantOne, including virtual directory design and identity correlation/aggregation
  • Hands-on production experience with Ping Directory (or PingDirectoryProxy), including replication and performance tuning
  • Deep working knowledge of LDAP/LDAPS fundamentals: schema design, referrals, and replication conflict resolution
  • Experience designing and building provisioning workflows and connectors (SCIM, JIT, custom connector development)
  • Scripting experience in JavaScript, Python and PowerShell for automation, tooling, and provisioning
  • Demonstrated ability to make and articulate architectural tradeoffs, and to set technical direction for other engineers
  • Ability to work effectively in a remote-first team environment

Nice To Haves

  • Experience with SailPoint IdentityIQ or other IGA platforms, and collaborating with governance teams
  • Experience with hybrid identity architectures (Azure AD/Entra ID) and multi-forest Active Directory environments
  • Exposure to broader security architecture concepts: PAM boundaries, service account lifecycle, and privileged directory access
  • Experience leading directory consolidation or large-scale migration projects
  • Prior experience mentoring engineers or informally setting technical direction across a team

Responsibilities

  • Design, deploy, and tune Identity Fabric environments, including replication topology, ACIs, high-availability configuration, and performance optimization at enterprise scale
  • Identity provisioning workflows spanning provisioning, and custom connector development, extending beyond out-of-box configuration to build and debug bespoke integrations
  • Lead directory consolidation, migration, and hybrid identity initiatives (e.g., multi-forest AD, Azure AD/Entra integration) where Radiant Logic serves as an abstraction and correlation layer
  • Serve as a technical escalation point for complex production issues involving directory replication, provisioning failures, and identity correlation conflicts, driving root cause analysis and durable fixes
  • Partner with IAM governance (SailPoint), security architecture, and application teams to align directory and provisioning capabilities with broader identity strategy
  • Set technical direction and best practices for directory and provisioning engineering; mentor senior and mid-level engineers on the team
  • Build automation and tooling (Python/PowerShell) to reduce manual operational overhead and improve reliability of provisioning and directory services
  • Document architecture decisions, design tradeoffs, and operational runbooks for supportability across the team
  • Evaluate and influence roadmap decisions for the directory and provisioning technology stack

Benefits

  • medical, dental and vision insurance
  • 401(k)
  • paid leave
  • tuition reimbursement
  • a variety of other discounts and perks
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service