Sr Identity Engineer

Location
MO, Kansas City
Workplace
On-site

About this role

The Senior Identity Engineer – Operations designs, operates, and secures Microsoft Entra ID and its integrations across the enterprise. This role owns identity governance, Conditional Access, privileged access, application identities, and modern authentication controls, while serving as a senior escalation point for complex access and authentication issues. The engineer partners with security, platform, and regional teams to maintain resilient, least-privilege identity services and audit-ready operational standards.
 



Engineer, operate, and secure Microsoft Entra ID in an enterprise environment, including hybrid identity with Active Directory and Entra Connect, directory health, monitoring, and incident response.
Design, implement, and maintain Conditional Access policies enforcing MFA, device trust, sign-in risk, and Zero Trust principles across access scenarios.
Design and enforce identity standards that eliminate network-based trust assumptions, ensuring MFA and risk-based access controls are consistently applied.
Review, approve, and operationalize admin consent for third-party enterprise application integrations across the tenant.
Own enterprise application and service principal onboarding, enforcing least-privilege access models and secure authentication patterns.
Create, manage, and govern App Registrations, including secret and certificate lifecycle management, rotation standards, and expiration monitoring.
Design and enforce least-privilege Microsoft Graph permission models for applications and identity automation.
Define and maintain standards that prevent interactive sign-in for service accounts, leveraging Conditional Access and non-interactive authentication models.
Define and enforce identity security guardrails for privileged access, MFA requirements, service accounts, and break-glass scenarios.
Implement and govern Microsoft Entra Privileged Identity Management (PIM) for administrative roles, just-in-time elevation, approval workflows, access reviews, and privileged access monitoring.
Design and administer Microsoft Entra Administrative Units to delegate identity and user management with scoped administrative control across regions, business units, and support teams.
Operate and evolve modern authentication and MFA methods globally, aligning with Microsoft Entra Authentication Methods and organizational security standards.
Support and standardize passwordless authentication approaches, including FIDO2 and hardware security keys, across regions and business units.
Support B2B, B2C, cross-tenant, and external identity scenarios for partners, vendors, and client-facing platforms.
Partner with platform, security, and Azure engineering teams to design and deliver secure Azure access models, role assignments, and identity integrations.
Act as the escalation point for complex identity-related incidents, authentication failures, and access issues.
Produce audit-safe documentation and evidence supporting security, compliance, and regulatory requirements.
Demonstrate a strong understanding of Microsoft 365 (M365) and its identity integrations with Entra ID, including authentication flows, access controls, and tenant-level governance considerations.
 

#LI-JM

Tired of cold applications?

Sign up with Clera and we'll reach out the moment a role actually fits you — no more spraying applications into the void.

Know someone who'd be great for this?