MathWorks logo

Principal Identity Security Engineer - AD & MS Entra ID

MathWorks

Natick, MAHybridJob$145–231K/yrPosted 5mo agoSeen in employer's feed 4 days ago

Most applications go out cold — see where you stand first. No sign-up to start.

At a glance

Compensation
$145–231K/yr
Location
Natick, MAHybrid
Work Authorization
US work authorization required

Requirements

Credentials this posting asks for.

Bachelor's degree

Job overview

MathWorks is hiring a Principal Identity Security Engineer - AD & MS Entra ID. MathWorks seeks a Principal Identity Security Engineer to lead the evolution of core identity platforms, designing authentication and authorization capabilities, strengthening security resilience, and establishing engineering practices that improve automation and reliability across hybrid and non‑human identity services.

Key focus areas include Provide technical leadership for evolution of core identity platforms and capabilities, Design and improve authentication, authorization, privileged access, and identity governance capabilities, and Lead efforts to strengthen security, resilience, and recoverability of enterprise identity services.

Successful candidates bring Bachelor's Degree Or Equivalent Experience, 10 Years Professional Work Experience, and Experience Operating Azure AD Connect Or Cloud Sync. Important skills include Active Directory Operations, Microsoft Entra ID, Conditional Access, Identity Protection, PIM, and Enterprise Applications.

Skills & qualifications

RequiredNice to have

Skills

Active Directory OperationsMicrosoft Entra IDConditional AccessIdentity ProtectionPIMEnterprise ApplicationsApp RegistrationsService PrincipalsManaged IdentitiesAuthentication ControlsAuthorization PoliciesNon-Human Identity GovernanceWorkload IdentitiesCertificatesSecrets ManagementFederated CredentialsApplication PermissionsAzure AD ConnectCloud SyncProvisioningSailPointIdentity Threat Detection and ResponseSecure BaselinesAdmin TieringPrivileged Access ControlsSecure DelegationPowerShellPythonMicrosoft GraphEntra APIsGit WorkflowsCI/CD PipelinesConfiguration-as-CodePolicy-as-CodeDevOpsSecDevOpsSource ControlPeer ReviewAutomated ValidationDrift DetectionSecure Deployment WorkflowsLoggingSecrets HandlingRollback PlanningIAM Patterns for AI-Enabled SystemsAgentic WorkflowsIdentity OwnershipAccess BoundariesAuditabilityLifecycle GovernanceActive DirectoryHybrid IdentityFederationAuthentication TechnologiesPrivileged AccessAdministrative TieringIdentity Threat DetectionRecovery PlanningIdentity HardeningSecretsScriptingAPIGit-Based WorkflowsCI/CD PracticesDelegated PermissionsConsent ModelsLeast-Privilege Access DesignNISTISO 27001AI-Enabled SystemsAutomation Platforms

Qualifications

Bachelor's Degree10 Years Professional Work Experience

Full job description

Team: Information Technology

Location: US-MA-Natick

Salary Range: USD 231,300 - 144,600

Job Summary

MathWorks has a hybrid work model that enables staff members to split their time between office and home. The hybrid model provides the advantage of having both in-person time with colleagues and flexible at-home life optimizations. Learn More: https://www.mathworks.com/company/jobs/resources/applying-and-interviewing.html#onboarding.

Do you enjoy solving complex identity challenges and building secure, scalable platforms that enable the business?

Join our Identity and Access Management team, where you will work on enterprise identity foundations across Active Directory, Microsoft Entra ID, hybrid identity, privileged access, and non-human identities. You will partner across security, cloud, IT, and application teams to strengthen identity platforms, improve access controls, and support secure patterns for applications, services, and emerging AI-enabled systems.

In this role, you will help shape the security, reliability, and governance of core identity services while using automation and engineering practices to make those services more scalable, consistent, and resilient.

MathWorks nurtures growth, appreciates inclusivity, encourages initiative, values teamwork, shares success, and rewards excellence.

Responsibilities

  • Provide technical leadership for the evolution of core identity platforms and capabilities, including Active Directory, Microsoft Entra ID, hybrid identity, and non-human identities.

  • Design and improve authentication, authorization, privileged access, and identity governance capabilities across human and non-human identities.

  • Lead efforts to strengthen the security, resilience, and recoverability of enterprise identity services through platform hardening, threat detection, operational readiness, and recovery planning.

  • Establish and promote engineering practices that improve automation, consistency, reliability, and operational excellence across identity platforms.

  • Define scalable identity patterns and engineering guardrails for applications, services, AI-enabled systems, and automation platforms in partnership with security, cloud, IT, and application teams.

Minimum Qualifications

  • A bachelor's degree and 10 years of professional work experience (or equivalent experience) is required.

Additional Qualifications

A successful candidate will have experience in many of the following areas:

  • Enterprise identity platform experience, including Active Directory, Microsoft Entra ID, hybrid identity, federation, provisioning, and authentication technologies.

  • Identity security experience, including privileged access, administrative tiering, identity threat detection and response, recovery planning, and identity hardening practices.

  • Workload and non-human identity experience, including service principals, managed identities, certificates, secrets, application permissions, and federated credentials.

  • IAM engineering and automation experience, including scripting, APIs, configuration-as-code, Git-based workflows, and CI/CD practices.

  • Application identity and permission governance experience, including app registrations, delegated and application permissions, consent models, and least-privilege access design.

  • Familiarity with regulatory and security frameworks such as NIST, ISO 27001, and similar standards.

  • Familiarity with emerging identity patterns supporting AI-enabled systems, automation platforms, and agentic workflows.

You've read the whole posting — now see how you match it.