Kelly Services logo

Principal IAM Engineer

Kelly Services

Natick, MA · HybridJobup to $200K/yrSeen 3 days agoSeen in employer's feed 3 days ago

Most applications go out cold — see where you stand first. No sign-up to start.

Watch jobs like this.

At a glance

Compensation
up to $200K/yr
Location
Natick, MAHybrid
Work Authorization
Not specified

Olive lists jobs from US employers, including remote roles you can work from the United States.

Job overview

A well-established technology organization seeks a Principal IAM/Active Directory Engineer to provide technical leadership across enterprise identity platforms and security services. The role shapes identity and access management strategy, architecture, security, and operations across a complex enterprise environment. It partners with security, cloud, infrastructure, and application teams to deliver scalable, secure, and resilient identity services and strengthen identity security through automation and best practices.

Skills & qualifications

RequiredNice to have

Skills

Active DirectoryMicrosoft Entra IDHybrid IdentityAuthenticationAuthorizationIdentity GovernancePrivileged Access ManagementIdentity SecurityIdentity Threat DetectionRecovery PlanningPlatform HardeningAutomationScriptingAPIsInfrastructure as CodeGit-Based WorkflowsCI/CDOperational AutomationService PrincipalsManaged IdentitiesCertificatesSecretsFederated CredentialsLeast-Privilege AccessApplication Permission GovernanceEnterprise IAMFederationProvisioningModern AuthenticationNISTISO 27001Cloud SecurityApplication Identity ArchitectureAI Identity StrategiesIdentity StandardsGovernance Models

Qualifications

Bachelor's Degree or Equivalent Practical Experience10+ Years Professional Experience

Benefits

Medical Insurance
Dental Insurance
Vision Insurance
Paid Time Off
401(k) Match

Full job description

$130 - $200

Job Description A well-established technology organization is seeking a Principal IAM/Active Directory Engineer to provide technical leadership across enterprise identity platforms and security services. This role will play a critical part in shaping the strategy, architecture, security, and operational excellence of identity and access management capabilities across a complex enterprise environment.

The ideal candidate will be responsible for driving improvements across Active Directory, Microsoft Entra ID, hybrid identity, privileged access, identity governance, and non-human identities. This position partners closely with security, cloud, infrastructure, and application teams to ensure scalable, secure, and resilient identity services that support business growth and modernization initiatives.

This is a highly visible engineering role focused on strengthening identity security, driving automation, and establishing best practices across the organization's identity ecosystem. Required Skills & Experience

  • Bachelor's degree and 10+ years of professional experience or equivalent practical experience

  • Deep expertise with Active Directory and Microsoft Entra ID

  • Strong background supporting hybrid identity environments

  • Experience designing authentication, authorization, and identity governance solutions

  • Knowledge of privileged access management and identity security best practices

  • Experience with identity threat detection, recovery planning, and platform hardening

  • Strong automation and scripting capabilities

  • Experience with APIs, Infrastructure as Code, and Git-based development workflows

  • Hands-on experience with CI/CD methodologies and operational automation

  • Knowledge of service principals, managed identities, certificates, secrets, and federated credentials

  • Experience designing least-privilege access models and application permission governance

Desired Skills & Experience

  • Experience supporting large-scale enterprise IAM environments

  • Familiarity with federation, provisioning, and modern authentication technologies

  • Knowledge of NIST, ISO 27001, and related security frameworks

  • Experience with cloud security and application identity architecture

  • Exposure to identity strategies supporting AI-enabled systems and automation platforms

  • Experience building enterprise-wide identity standards, guardrails, and governance models

What You Will Be Doing Daily Responsibilities

  • Provide technical leadership for enterprise identity and access management platforms

  • Design and enhance authentication, authorization, and identity governance capabilities

  • Improve the security, resilience, and recoverability of identity infrastructure

  • Lead platform hardening, threat detection, and operational readiness initiatives

  • Drive automation efforts to improve reliability, consistency, and scalability

  • Develop identity architecture standards for applications, services, and cloud platforms

  • Partner with security, engineering, and infrastructure teams on strategic identity initiatives

  • Create and maintain engineering best practices across IAM technologies

  • Support governance and compliance requirements related to identity security

  • Mentor team members and influence long-term identity strategy

The Offer

  • Base salary up to $200,000

  • Competitive bonus potential

  • Opportunity to lead enterprise-scale IAM modernization initiatives

  • Collaborative and security-focused engineering environment

You will receive the following benefits

  • Medical Insurance

  • Dental Benefits

  • Vision Benefits

  • Paid Time Off (PTO)

  • 401(k)

Applicants must be currently authorized to work in the US on a full-time basis now and in the future.

Motion Recruitment Partners (MRP) is an Equal Opportunity Employer. All applicants must be currently authorized to work on a full-time basis in the country for which they are applying, and no sponsorship is currently available. Employment is subject to the successful completion of a pre-employment screening. Accommodation will be provided in all parts of the hiring process as required under MRP’s Employment Accommodation policy. Applicants need to make their needs known in advance.

Similar jobs, posted recently

Open roles like this one, listed in the last 30 days.

You've read the whole posting — now see how you match it.