Job Description
Senior Identity Engineer
As an Senior Identity Engineer focused on identity architecture and platform engineering within Auto Club Enterprises’ Enterprise Identity Engineering (EIE) team, you will research, design, engineer, integrate, and support secure identity capabilities across on-premises, cloud, and hybrid environments. You will provide hands-on technical leadership for complex identity initiatives and convert architecture into implemented, tested, monitored, and supportable solutions.
The role requires depth in enterprise directories and modern identity protocols, combined with practical engineering ability. You will strengthen platform resilience, reduce single-person dependencies, establish reusable architecture patterns, and advance identity capabilities for workforce, non-human, workload, and AI identities.
What You’ll Do
- Design and engineer identity architectures for authentication, authorization, federation, identity lifecycle, governance, privileged access, secrets, MFA, directories, certificate services, and workload identity.
- Lead research, options analysis, proofs-of-concept, technical design, security review, and implementation planning for new identity products and capabilities.
- Engineer Active Directory and Entra ID solutions across multi-site, multi-forest, cloud, and hybrid environments, including Entra Connect synchronization and heterogeneous authentication.
- Design integrations using SAML 2.0, OAuth 2.0, OpenID Connect, LDAP, SCIM, Kerberos, API-based provisioning, certificates, and secure secrets patterns.
- Improve identity resilience through recovery architecture, threat detection, monitoring, failure-mode analysis, disaster recovery, testing, and operational readiness.
- Engineer and integrate PKI, certificate lifecycle, HSM, MFA, PAM, secrets-management, and federation-agent technologies.
- Define patterns for non-human identity, workload identity, service principals, machine credentials, AI agents, MCP integrations, authorization, auditability, and governance.
- Partner with developers and automation engineers to translate designs into code, pipelines, Infrastructure as Code, automated tests, monitoring, and production deployments.
- Troubleshoot complex cross-platform identity issues through authentication-flow analysis, packet traces, logs, telemetry, and root-cause analysis.
- Create reference architectures, segmentation diagrams, design decisions, standards, runbooks, recovery procedures, test evidence, and handover documentation.
- Mentor engineers, conduct design reviews, lead technical work across teams, and provide remote after-hours support during major outage conditions.
What You’ll Need
- Demonstrated experience designing and implementing enterprise identity solutions, not solely administering existing products.
- Deep knowledge of Active Directory in large multi-site or multi-forest environments, including authentication, Kerberos, trusts, directory dependencies, recovery considerations, and Windows and non-Windows interoperability.
- Strong experience with Entra ID, Entra Connect synchronization, hybrid identity, federation, conditional access concepts, and cloud identity integration.
- Strong knowledge of SAML, OAuth, OpenID Connect, LDAP, SCIM, MFA, PKI, RBAC, least privilege, secrets management, and privileged access patterns.
- Experience creating architecture diagrams, design records, integration patterns, failure-mode analysis, recovery plans, implementation roadmaps, and operational handoff documentation.
- Working development and automation skills in Python or PowerShell, plus experience with APIs, Git, CI/CD, automated testing, and Infrastructure as Code or configuration management.
- Experience engineering highly available, fault-tolerant, monitored, and recoverable enterprise services.
- Ability to independently research an unfamiliar technology, build or guide a proof-of-concept, assess security and business tradeoffs, and recommend a scalable approach.
- Advanced troubleshooting skills using logs, telemetry, protocol traces, packet analysis, and cross-platform dependency mapping.
- Excellent communication and the ability to lead technical decisions and implementation across Architecture, Cybersecurity, Infrastructure, Cloud, Application Development, and business teams.
Preferred Experience
- Semperis Directory Services Protector, Active Directory Forest Recovery, Lightning Intelligence, or comparable identity threat detection and recovery technologies.
- Okta agents or comparable federation, directory integration, and cloud identity provider components.
- Microsoft PKI, Keyfactor, DigiCert Trust Lifecycle Manager, certificate orchestration, Thales Luna HSM, or comparable certificate and cryptographic platforms.
- CyberArk PAM, CyberArk secrets management, Conjur, or comparable privileged access and non-human credential platforms.
- Thales SafeNet Trusted Access, CipherTrust, or comparable MFA and key-management platforms.
- Infoblox DNS, F5 GTM, AD LDS, ManageEngine identity administration and audit products, or comparable enterprise infrastructure services.
- Workload identity, non-human identity governance, AI agent identity, MCP integration security, authorization policy, secrets, and auditability.
- Splunk, Wireshark, ExtraHop, or comparable diagnostic and observability tools.
- Zero Trust architecture, cloud-native identity in Microsoft Azure or AWS, and secure application integration patterns.
#LI-LD1
Remarkable benefits:
- Health coverage for medical, dental, vision
- 401(K) saving plans with company match AND Pension
- Tuition assistance
- Floating holidays and PTO for community volunteer programs
- Paid parental leave
- Wellness programs
- Employee discounts (membership, insurance,
travel, entertainment, services and more!)
Auto Club Enterprises is the largest club within the national AAA federation. We have nearly 17,000 employees in 24 states helping more than 18 million members. The strength of our organization is our employees. Bringing together and supporting different cultures, backgrounds, personalities, and strengths creates a team capable of delivering legendary, lifetime service to our members. When we embrace our diversity – we win. All of Us! With our national brand recognition, long-standing reputation since 1900, and constantly growing membership, we are seeking career-minded, service-driven professionals to join our team.
"Through dedicated employees we proudly deliver legendary service and beneficial products that provide members peace of mind and value.”
AAA is an Equal Opportunity Employer
Our organization participates in E-Verify