Principal Identity Security Engineer - AD & MS Entra ID
Indexed description
Do you enjoy solving complex identity challenges and building secure, scalable platforms that enable the business?
Join our Identity and Access Management team, where you will work on enterprise identity foundations across Active Directory, Microsoft Entra ID, hybrid identity, privileged access, and non-human identities. You will partner across security, cloud, IT, and application teams to strengthen identity platforms, improve access controls, and support secure patterns for applications, services, and emerging AI-enabled systems.
In this role, you will help shape the security, reliability, and governance of core identity services while using automation and engineering practices to make those services more scalable, consistent, and resilient.
MathWorks nurtures growth, appreciates inclusivity, encourages initiative, values teamwork, shares success, and rewards excellence.
Responsibilities
- Provide technical leadership for the evolution of core identity platforms and capabilities, including Active Directory, Microsoft Entra ID, hybrid identity, and non-human identities.
- Design and improve authentication, authorization, privileged access, and identity governance capabilities across human and non-human identities.
- Lead efforts to strengthen the security, resilience, and recoverability of enterprise identity services through platform hardening, threat detection, operational readiness, and recovery planning.
- Establish and promote engineering practices that improve automation, consistency, reliability, and operational excellence across identity platforms.
- Define scalable identity patterns and engineering guardrails for applications, services, AI-enabled systems, and automation platforms in partnership with security, cloud, IT, and application teams.
- A bachelor's degree and 10 years of professional work experience (or equivalent experience) is required.
- Enterprise identity platform experience, including Active Directory, Microsoft Entra ID, hybrid identity, federation, provisioning, and authentication technologies.
- Identity security experience, including privileged access, administrative tiering, identity threat detection and response, recovery planning, and identity hardening practices.
- Workload and non-human identity experience, including service principals, managed identities, certificates, secrets, application permissions, and federated credentials.
- IAM engineering and automation experience, including scripting, APIs, configuration-as-code, Git-based workflows, and CI/CD practices.
- Application identity and permission governance experience, including app registrations, delegated and application permissions, consent models, and least-privilege access design.
- Familiarity with regulatory and security frameworks such as NIST, ISO 27001, and similar standards.
- Familiarity with emerging identity patterns supporting AI-enabled systems, automation platforms, and agentic workflows.
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search