Make Your Resume Now

Staff Security Operations Engineer - Active Directory (AD) & Azure AD (Entra ID)

Posted July 20, 2026
Full-time Mid-Senior Level

Job Overview

This role is primarily focused on the administration, engineering, and operational ownership of the organization’s directory services - Active Directory (AD) and Azure AD (Microsoft Entra ID) - including hybrid identity integration. The Staff Security Operations Engineer serves as the day-to-day technical lead for AD and Entra ID, ensuring their availability, reliability, and security across the organization.

Supporting identity and access management technologies - IAM process automation, incident response and troubleshooting, compliance reporting, and multifactor authentication - make up the secondary scope of the role. This position works cross time zones to support Asia coverage needs.

ESSENTIAL DUTIES AND RESPONSIBILITIES

Active Directory (AD) and Azure AD (Entra ID) (Primary Focus)

  • Serve as the primary administrator and operational owner of the organization’s Active Directory and Microsoft Entra ID directory services.
  • Manage user accounts, security and distribution groups, Group Policy (GPO), and organizational units across the Active Directory environment.
  • Design, implement, and maintain hybrid identity using Azure AD Connect - synchronization between on-premises AD and Entra ID, seamless single sign-on, and password hash sync / pass-through authentication.
  • Administer Microsoft Entra ID, including RBAC, Privileged Identity Management (PIM), Conditional Access, application registrations / enterprise applications, and identity governance.
  • Provide day-to-day operational support, including monitoring directory health and troubleshooting replication, DNS, authentication, and access provisioning issues.
  • Act as the technical escalation point for directory-related incidents, working with vendors and internal teams to identify root causes and implement durable solutions.
  • Maintain documentation, runbooks, and operational procedures for the Active Directory and Entra ID environment.

Multifactor Authentication - Supporting Scope

  • Support the integration of MFA with Active Directory and Entra ID (Duo MFA, Windows Hello for Business, and Conditional Access), enabling the organization’s passwordless and passkey authentication program.
  • Assist with troubleshooting and escalations where directory issues affect authentication and access.

IAM Process Automation

  • Automate directory lifecycle tasks and workflows - joiner / mover / leaver provisioning, group and access management, and reporting - using PowerShell and Microsoft Graph to increase efficiency and reduce manual errors.
  • Continuously evaluate and improve identity and directory processes to enhance security and the user experience.

Incident Response and Troubleshooting

  • Act as the technical escalation point for identity-related incidents involving Active Directory, Entra ID, and hybrid identity synchronization.
  • Investigate, troubleshoot, and resolve directory and access issues, working closely with other teams to identify root causes and implement solutions.

Compliance and Reporting

  • Ensure directory and IAM solutions meet compliance requirements such as SOX, etc.
  • Generate reports for auditing purposes - including access reviews and privileged access - and provide insights into the security posture of identity systems.

Collaboration and Documentation

  • Collaborate with security, IT, and compliance teams to define and implement identity governance frameworks.
  • Develop and maintain comprehensive documentation for all directory and IAM solutions, policies, and procedures.

Training and Knowledge Sharing

  • Provide training to end-users and technical staff on directory services and IAM best practices, focusing on Active Directory and Entra ID.
  • Stay up-to-date with industry trends and emerging technologies to continuously enhance the organization’s directory and IAM capabilities.

Professional Attributes

  • Leadership: Demonstrated ability to assist in leading cross-functional teams and manage technical resources, driving projects and solutions to successful completion.
  • Problem-Solving: Strong analytical and troubleshooting skills with a proactive approach to identifying and resolving issues within complex identity and directory environments.
  • Analytical Skills: Ability to analyze complex IAM issues and apply logical troubleshooting techniques to resolve identity-related problems.
  • Attention to Detail: High accuracy and attention to detail in managing identity policies, systems configurations, and security protocols.
  • Communication: Strong communication skills to collaborate with technical and non-technical stakeholders across the organization.
  • Team Player: Ability to work effectively as part of a cross-functional team, with a focus on supporting the broader IAM strategy.
  • Customer Focused: Demonstrated ability to deliver excellent service to internal and external stakeholders, focusing on user experience without compromising security.
  • Adaptability: Ability to quickly learn and adapt to new tools, technologies, and security practices in a dynamic IT environment.

Ready to Apply?

Take the next step in your career journey

Stand out with a professional resume tailored for this role

Build Your Resume – It’s Free!