
Salary not listedPosted 13m ago
Real job — pulled straight from Enterprise Minds’s careers page · Verified September 15, 2026 · No reposts.
Job description
Enterprise Minds is hiring a IAM and Email Security Program — a full-time role. Apply directly on Enterprise Minds's careers page below.
IAM and eMail Security Program_UG170826
Department: IT
Experience: 7-12
Job Title: T3-Level AD / SSO Support Engineer – Entra ID, PingOne & IAM
Experience: 7–12 Years
Employment Type: Full-Time
Role Overview
We are looking for a highly experienced T3-Level AD / SSO Support Engineer with strong expertise in Active Directory, Identity & Access Management (IAM), SSO, Microsoft Entra ID, PingOne, security technologies, and automation.
The ideal candidate should have hands-on experience supporting large-scale enterprise identity environments and managing business-critical platforms such as Entra ID and PingOne.
The candidate should possess strong knowledge of identity protocols, authentication and authorization mechanisms, federation, security best practices, enterprise IAM architecture, troubleshooting, automation, and current identity/security trends.
This role requires a strong production support and engineering mindset, with the ability to independently handle complex T3 escalations, perform root-cause analysis, implement permanent fixes, and continuously improve the reliability and security of identity services.
Key Responsibilities
1. Active Directory – T3 Support
- Provide advanced T3-level support for enterprise Active Directory environments.
- Troubleshoot complex issues related to AD authentication, domain services, DNS, Group Policy, LDAP, Kerberos, replication, and trust relationships.
- Analyze authentication failures, account lockouts, replication issues, Group Policy problems, and domain-related incidents.
- Perform detailed root-cause analysis (RCA) for recurring AD issues.
- Support large-scale, highly available enterprise AD environments.
- Work with infrastructure, networking, security, and application teams to resolve complex identity issues.
2. Microsoft Entra ID / Azure AD
- Provide advanced administration and troubleshooting for Microsoft Entra ID.
- Manage and troubleshoot enterprise applications, users, groups, authentication policies, MFA, Conditional Access, and identity synchronization.
- Support hybrid identity environments involving Active Directory and Entra ID.
- Troubleshoot Entra Connect / Azure AD Connect synchronization issues.
- Analyze sign-in logs, authentication failures, synchronization errors, and Conditional Access-related issues.
- Support secure application onboarding and enterprise SSO integrations.
- Implement and maintain Entra security best practices.
3. PingOne & SSO
- Provide T3-level support for PingOne / Ping Identity environments.
- Configure, troubleshoot, and maintain enterprise SSO integrations.
- Support application federation and authentication flows across enterprise and SaaS applications.
- Troubleshoot complex authentication and authorization issues.
- Work with application teams to onboard and integrate applications into the SSO platform.
- Configure and troubleshoot authentication policies, MFA, federation, and access controls.
- Monitor platform health and proactively identify potential authentication or availability issues.
4. Identity & Authentication Protocols
- Strong understanding of enterprise identity and authentication protocols, including:
- SAML 2.0
- OAuth 2.0
- OpenID Connect (OIDC)
- LDAP
- Kerberos
- WS-Federation
- Troubleshoot authentication flows by analyzing tokens, claims, certificates, assertions, headers, logs, and protocol responses.
- Understand federation concepts including Identity Provider (IdP), Service Provider (SP), authentication, authorization, claims, and token validation.
- Troubleshoot complex cross-platform authentication and federation issues.
5. IAM & Security
- Apply strong Identity & Access Management (IAM) principles across enterprise environments.
- Implement and support least-privilege access, role-based access, MFA, privileged access, identity lifecycle management, and access governance.
- Follow enterprise security standards and identity security best practices.
- Identify potential security risks within authentication and access-management environments.
- Support security investigations involving identity, authentication, and access-related events.
- Stay updated on evolving IAM, cybersecurity, Zero Trust, authentication, and identity-security trends.
- Ensure identity platforms are configured according to enterprise security and compliance requirements.
6. Automation & Scripting
- Develop automation to reduce repetitive manual activities across AD, Entra ID, PingOne, and IAM operations.
- Use PowerShell, Python, REST APIs, or equivalent scripting technologies for automation.
- Automate activities such as:
- User and group management
- Access provisioning/deprovisioning
- Identity reporting
- Health checks
- Log analysis
- Application onboarding
- Troubleshooting and operational tasks
- Build reusable automation solutions that improve operational efficiency, accuracy, scalability, and security.
- Identify opportunities to automate recurring support and administration activities.
7. T3 Production Support & Troubleshooting
- Act as the highest-level technical escalation point for complex AD, SSO, IAM, and authentication incidents.
- Analyze application, identity, authentication, and infrastructure logs to identify root causes.
- Perform advanced troubleshooting across multiple technology layers.
- Lead technical resolution of P1/P2 production incidents when required.
- Perform detailed RCA, corrective actions, and preventive actions.
- Identify recurring issues and implement permanent solutions.
- Work closely with L1/L2 support teams to provide technical guidance and knowledge transfer.
- Participate in incident, problem, change, and release management processes.
8. Enterprise Application & SSO Integration
- Integrate enterprise and SaaS applications with Entra ID and PingOne.
- Analyze application authentication requirements and recommend appropriate identity protocols.
- Support SSO onboarding, configuration, testing, and production deployment.
- Troubleshoot issues related to SAML assertions, claims, certificates, redirects, tokens, endpoints, and authentication policies.
- Collaborate with application owners, developers, security teams, and vendors to resolve integration issues.
- Ensure application integrations follow enterprise security and architecture standards.
9. Monitoring & Operational Excellence
- Monitor the health, availability, and performance of enterprise identity platforms.
- Analyze authentication and sign-in logs to identify abnormal patterns and recurring issues.
- Establish proactive monitoring and alerting for critical identity services.
- Develop dashboards and reports for identity-platform health and operational metrics.
- Identify opportunities to improve platform availability, reliability, security, and performance.
- Maintain technical documentation, knowledge articles, SOPs, troubleshooting guides, and operational runbooks.
10. Identity Architecture & Industry Trends
- Understand enterprise-scale IAM and SSO architecture and the interaction between identity, applications, infrastructure, and security.
- Provide technical recommendations for improving identity-platform architecture.
- Evaluate new identity technologies, security capabilities, and automation opportunities.
- Stay current with industry developments in:
- Zero Trust
- Cloud IAM
- Passwordless authentication
- Identity threat detection
- Privileged Identity Management
- Adaptive authentication
- Modern authentication protocols
- Identity governance
- AI-assisted security and automation
- Contribute to continuous improvement of enterprise identity services.
Must-Have Technical Skills
- Strong hands-on experience with Microsoft Active Directory.
- Strong experience with Microsoft Entra ID / Azure AD.
- Hands-on experience with PingOne / Ping Identity.
- Strong experience in enterprise SSO and IAM.
- Strong understanding of SAML 2.0, OAuth 2.0, OIDC, LDAP, Kerberos, and WS-Federation.
- Advanced troubleshooting and T3-level production support experience.
- Strong knowledge of authentication, authorization, federation, MFA, and Conditional Access.
- Experience with hybrid AD / Entra identity environments.
- Experience troubleshooting Entra Connect / Azure AD Connect.
- Strong understanding of enterprise security and IAM best practices.
- Strong PowerShell and/or Python scripting skills.
- Experience with REST APIs and automation.
- Strong experience with log analysis, RCA, incident management, and problem management.
- Experience supporting large-scale enterprise deployments.
- Strong analytical, troubleshooting, and problem-solving skills.
Good-to-Have Skills
- Experience with Microsoft Entra ID Governance.
- Microsoft Entra Privileged Identity Management (PIM).
- Experience with Microsoft Defender for Identity.
- Knowledge of SCIM provisioning.
- Experience with identity governance and access reviews.
- Knowledge of Zero Trust architecture.
- Experience with passwordless authentication / FIDO2.
- Experience with API-based identity integrations.
- Knowledge of Azure or AWS cloud security.
- Experience with IAM monitoring and observability tools.
- Knowledge of certificate management and PKI.
- Experience with CI/CD and DevSecOps.
- Exposure to AI-assisted tools for automation, troubleshooting, and operational efficiency.
Expected Architecture Skills
The candidate should be capable of understanding and troubleshooting enterprise identity architectures similar to:
User → Application → SSO → Identity Provider → Authentication → MFA / Conditional Access → Token / Assertion → Authorization → Application
with supporting components such as:
Active Directory + Entra ID + PingOne + Enterprise Applications + MFA + Identity Synchronization + LDAP/Kerberos + Monitoring + Automation + Security Controls
The candidate should be able to explain:
- Authentication and authorization flows
- SSO and federation architecture
- SAML/OAuth/OIDC implementation and troubleshooting
- AD and Entra integration
- PingOne application integration
- Identity synchronization and lifecycle
- Security and least-privilege considerations
- High availability and enterprise scalability
- Incident and failure scenarios
- Automation opportunities
- Security risks and mitigation strategies
Experience Level
- 7–12 years of overall experience in Active Directory, IAM, SSO, or identity engineering/support.
- Strong experience operating in a T3 / L3 escalation environment.
- At least 4–6 years of hands-on experience with enterprise IAM/SSO technologies.
- Strong hands-on experience with Entra ID and/or PingOne.
- Experience supporting large-scale enterprise identity deployments.
- Candidates with strong enterprise IAM expertise, excellent troubleshooting capabilities, and deep security knowledge may be considered even if their experience differs slightly from the stated range.
What We Expect
We are looking for an engineer who can support, troubleshoot, secure, automate, and continuously improve enterprise identity platforms, not someone limited to basic AD administration or ticket-based support.
The candidate should be capable of handling the complete identity-support lifecycle:
Incident → Investigation → Authentication Flow Analysis → Root Cause → Resolution → RCA → Automation → Preventive Action → Continuous Improvement
The ideal candidate will take ownership of maintaining secure, highly available, scalable, and reliable enterprise identity services, particularly platforms such as Microsoft Entra ID and PingOne, while continuously improving the environment through automation, security enhancements, and modern IAM practices.
Get IAM and Email Security Program jobs like this→
New roles from thousands of companies land hourly, straight from their careers pages. Get the freshest matches by email so you never miss one.
Email me new jobsSimilar jobs




New
Senior Enterprise Architect, AI and Frontier Security
Remote · Poland-eligible
✓ From careers page· 59m ago
Frequently asked questions
How do I apply for IAM and Email Security Program at Enterprise Minds?
You can view the full description and apply for IAM and Email Security Program at Enterprise Minds on EchoJobs: https://echojobs.io/job/enterprise-minds-iam-and-email-security-program-ug170826-89l9z.