Navy Federal Credit Union

Principal Identity and Access Management Engineer

Navy Federal Credit Union$110K — $130K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's Degree in Information Technology or equivalent experience
  • 7-10 years in identity security engineering
  • Expert knowledge in identity security practices like zero trust
  • Hands-on with Active Directory design and management, certified or equivalent
  • Understanding of modern authentication protocols like SAML and OIDC
  • Strong knowledge of Active Directory infrastructure and protocols
  • Experience with Microsoft Entra suite, identity governance, and related technologies

Responsibilities

  • Administer and design identity providers for Active Directory and related services
  • Implement identity federation for both internal and external applications
  • Apply engineering principles to enhance systems
  • Ensure system security and compliance with standards
  • Communicate clear, organized information to support business decisions
  • Conduct engineering tasks aligning with business needs
  • Research and configure new systems and modifications

Benefits

  • Comprehensive health plans
  • Retirement savings options
  • Paid time off and holidays
  • Family leave and support programs
  • Professional development opportunities
Full Job Description
Job Description

Navy Federal Credit Union currently does not provide sponsorship for this role. Applicants must be authorized to work in the United States without the need for current or future sponsorship.

The Principal IAM Engineer is a technical resource with intermediate or master level skills in the architecture, design, configuration, and management of Active Directory, Microsoft Entra, and modern authentication services.

Your success with attaining and performing the required skills and abilities will be enhanced if they consist of the following:

Responsibilities

  • Identity provider administration, design and maintenance for Active Directory Federation Services, Strata Identity Orchestrator, Active Directory Lightweight Directory Services, Entra ID
  • Identity federation implementation (with internal/external workforce applications.
  • Apply engineering principles into the design and enhancement of new and existing systems.
  • Ensure the security and integrity of system and product solutions including compliance with Navy Federal and Information Security principles and practices.
  • Present clear, organized, and concise information to all audiences through a variety of media to enable effective business decisions.
  • Perform engineering tasks and assignments in support of business needs.
  • Perform engineering technology research, procurement, deployment, and configuration for new and modified systems.
  • Perform other duties as assigned.


Qualifications

  • Bachelor's Degree in Information Technology or the equivalent combination of education, training or experience
  • 7-10 years of experience in identity security engineering
  • Expert knowledge of identity security best practices surrounding account separation, JIT, least privilege, zero trust
  • Hands-on experience designing and managing Active Directory infrastructure. As evidenced by at least 1 current certification (Microsoft Certified Solutions Associate, or Microsoft Certified Solutions Expert with a focus on server infrastructure.) or the equivalent experience and training.
  • Solid understanding of design and implementation of modern authentication protocols, such as SAML, OIDC, FIDO, and PIV.
  • Strong foundational knowledge of Active Directory infrastructure, protocols and authentication patterns: Domain Controllers, Group Policy, Sites/Services Topology, Replication, Kerberos
  • Experience with the following:
  • Microsoft Entra suite including:
  • Conditional Access
  • Azure SSO leveraging SAML/OIDC, Service Principals, and Agentic Identities
  • Management of directory identity in Entra and M365, leveraging security policies, PIM, RBAC
  • Identity Governance
  • Defender for Identity
  • Strata (Maverics) Identity Orchestration or similar
  • Active Directory Federation Services
  • Active Directory Lightweight Directory Services (AD-LDS)
  • Microsoft Enterprise PKI leveraging OCSP
  • Azure AD Connect

Desired Qualifications

  • Strong identity security mindset with a proven ability to design and operate identity solutions that prioritize security, compliance, and long-term resilience
  • Advanced PowerShell Scripting techniques. Knowledge of Golang and YAML.

Additional Information

Hours:
  • Monday - Friday, 8:00AM - 4:30PM (Operations will include 24x7 on-call systems support)


Location:
  • 820 Follin Lane, Vienna, VA 22180
  • 5510 Heritage Oaks Drive, Pensacola, FL 32526
  • 141 Security Drive, Winchester, VA 22602
  • 9999 Willow Creek Road San Diego, CA 92131

About Navy Federal Credit Union

Navy Federal Credit Union is a credit union that serves members of the military and their families. The credit union offers a range of financial products and services, including checking and savings accounts, loans, and credit cards. Navy Federal Credit Union was founded in 1933 and is headquartered in Vienna, Virginia. The credit union has more than 9 million members and operates more than 300 branches across the United States and around the world.
Learn more about Navy Federal Credit Union
Size
18,000 employees
Industry
Founded
1933

Similar Jobs

More Jobs at Navy Federal Credit Union

More Information Technology Jobs

Find similar Principal Identity and Access Management Engineer jobs: