Role Summary:
We are seeking a hands-on, detail-oriented Senior Systems Engineer with a strong DevSecOps mindset to operate and support identity and access control mechanisms across hybrid IT and OT environments. This role centers on the day-to-day reliability, compliance, and troubleshooting of Azure-integrated authentication flows and secure access pathways for both human and non-human identities.
You'll be responsible for maintaining Azure App Registrations, enforcing Conditional Access policies, and supporting Azure AD Application Proxy deployments. You'll validate and monitor identity protocols such as SAML, OAuth 2.0, OpenID Connect, and Bearer Tokens - using tools like Postman to test and troubleshoot authentication flows and API access.
This is a high-impact operational role requiring strong protocol fluency, incident resolution skills, and a passion for secure automation in complex environments.
Key Responsibilities (Protocol & Identity Engineering)
- Azure App Registration Operations Integrate, Maintain and troubleshoot Azure AD App Registrations and Enterprise Applications, ensuring service principals and managed identities are correctly configured for secure, automated access.
- Conditional Access Policy Enforcement Monitor and support Conditional Access policies to enforce MFA, device compliance, and risk-based access. Assist in resolving access issues and analyzing sign-in logs for policy impact.
- Azure AD Application Proxy Support Operate and maintain Azure AD App Proxy connectors to enable secure remote access to on-premises apps. Collaborate with network teams to ensure connectivity and authentication flow integrity.
- Postman for Protocol Validation Use Postman to test and validate authentication flows, including OAuth 2.0, OpenID Connect, and SAML. Simulate token requests and troubleshoot API access issues across environments.
- SAML Federation Support Maintain SAML-based integrations with third-party applications. Assist in resolving assertion errors, claim mismatches, and metadata synchronization issues.
- OAuth 2.0 & OpenID Connect Flow Monitoring Support the operation of OAuth and OIDC flows for both human and non-human identities. Ensure token scopes, lifetimes, and refresh behaviors align with policy and compliance requirements.
- Protocol-Level Troubleshooting & Escalation Act as a Tier 3 escalation point for identity-related incidents involving authentication failures, token issues, or access denials. Perform root cause analysis and document resolution steps.