Senior Identity and Access Management Engineer
hace 6 días
New York
The Senior IAM Engineer will play a key role in designing, implementing, and operating enterprise identity and access management capabilities across Microsoft Entra ID and the organization's credential management systems to include PKI. This role requires deep technical expertise, hands-on engineering experience, and the ability to translate business and security requirements into secure, automated identity controls. 1. Microsoft Entra Identity Services • Design, implement, and maintain secure SSO integrations for SaaS and on-prem applications using SAML, OIDC, and OAuth2., • Lead the automation of user provisioning and deprovisioning workflows via Entra ID and SCIM-based integrations., • Develop and manage access reviews, entitlement management, and least-privilege policies using Microsoft Entra and Azure AD Identity Governance., • Implement and maintain conditional access policies, MFA configurations, and group-based access controls., • Collaborate with application owners and security teams to ensure consistent identity lifecycle management across hybrid cloud environments. 2. PKI and Credential Management • Design, implement, and operationalize enterprise PKI infrastructure, including certificate authorities, registration authorities, and certificate templates., • Enhance and automate certificate enrollment, renewal, and revocation workflows across servers, applications, and end-user devices., • Integrate certificate-based authentication (CBA) with identity platforms and endpoint management systems., • Develop policies and processes for credential issuance, rotation, and lifecycle management., • Bachelor's degree in Computer Science, Cybersecurity, or related field (or equivalent experience)., • 5-8 years of experience in IAM engineering or related security infrastructure roles., • Deep knowledge of Microsoft Entra ID (Azure AD), identity protocols (SAML, OIDC, OAuth2), and lifecycle management best practices., • Experience implementing Entra ID Identity Governance features (access reviews, entitlement management, PIM)., • Strong expertise with PKI technologies (Microsoft ADCS, cloud-based CAs, HSM integration, CRLs, and certificate automation)., • Familiarity with modern credential management tools (e.g., Venafi, Keyfactor, HashiCorp Vault, or Azure Key Vault)., • Hands-on scripting experience (PowerShell, Python, or similar) for automation and API integrations., • Experience with identity federation and hybrid cloud IAM architectures., • Prior experience integrating EntraID (or other IDP) with SAP GRC Access Management and/or SAP IAS., • Knowledge of device identity, machine certificates, and code-signing processes., • Strong troubleshooting and documentation skills., • Strong Microsoft based skills as it relates to IAM., • Streamlined identity lifecycles with measurable improvements in provisioning efficiency and access compliance., • Automated certificate management processes reducing human intervention and outages. Chobani uses food as a force for good in the world - putting humanity first in everything it does. The company's philanthropic efforts prioritize giving back to its communities and beyond. Chobani manufactures its products inNew York,Idaho,MichiganandAustralia, and its products are available throughoutNorth Americaand distributed inAustraliaand other select markets. For more information, please visit___ or follow us on Facebook, Twitter, Instagram and LinkedIn. Chobani is an equal opportunity employer. Chobani will not discriminate against any applicant for employment on any basis including, but not limited to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, military and/or veteran status, marital status, predisposing genetic characteristics and genetic information, or any other classification protected by federal, state, and local laws. The salary range for this full-time position is $105,500.00 - $151,000.00, + bonus + equity + benefits. Within the range, individual pay is determined by work location and additional factors, including job-related skills, experience, and relevant education or training. Your recruiter can share more about the specific salary range for your preferred location during the hiring process. Chobani provides a comprehensive benefits package, including medical, dental, vision coverage, disability insurance, health savings account, flexible spending accounts, and tuition reimbursement. To help save for the future, all employees are eligible for a 401k match of 100% on up to 5% of eligible pay. To support growing families, we provide fertility and childcare assistance, and 12 weeks of parental leave at full pay after six months of continuous employment. In addition, we provide wellness resources which include an employee assistance program, fitness discounts, a wellness reimbursement, on-site gym access (certain locations) and a monthly wellness newsletter to connect you with resources and timely information. We offer various types of paid time of including: 120 hours of paid time off, 11 holidays, and paid volunteer time off.