Lockton

Sr Identity Engineer

Lockton$110K — $130K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years of experience in identity management and security, particularly with Microsoft Entra ID and Active Directory.
  • Proven expertise in designing and implementing Conditional Access and MFA systems.
  • Familiarity with zero trust architecture and application identity management.
  • Strong understanding of Microsoft Graph API and permissions model.
  • Experience in incident response and operational governance in identity services.

Responsibilities

  • Engineer and secure Microsoft Entra ID operations in a hybrid environment.
  • Implement Conditional Access policies to enforce MFA and Zero Trust principles.
  • Manage onboarding of enterprise applications ensuring least-privilege access.
  • Create and govern App Registrations with robust lifecycle management.
  • Define and uphold identity security guardrails for privileged access scenarios.
  • Design modern authentication methods aligned with organizational standards.
  • Act as a senior escalation point for identity-related incidents and access issues.

Benefits

  • Collaborative work environment with cross-departmental partnerships.
  • Opportunities for continuous learning and professional development.
  • Involvement in high-impact security and identity initiatives.
  • Flexibility in remote and hybrid work arrangements.
  • Access to cutting-edge technologies and tools in identity governance.
Full Job Description
Job Summary:

The Senior Identity Engineer - Operations designs, operates, and secures Microsoft Entra ID and its integrations across the enterprise. This role owns identity governance, Conditional Access, privileged access, application identities, and modern authentication controls, while serving as a senior escalation point for complex access and authentication issues. The engineer partners with security, platform, and regional teams to maintain resilient, least-privilege identity services and audit-ready operational standards.

Requirements:

Engineer, operate, and secure Microsoft Entra ID in an enterprise environment, including hybrid identity with Active Directory and Entra Connect, directory health, monitoring, and incident response.

Design, implement, and maintain Conditional Access policies enforcing MFA, device trust, sign-in risk, and Zero Trust principles across access scenarios.

Design and enforce identity standards that eliminate network-based trust assumptions, ensuring MFA and risk-based access controls are consistently applied.

Review, approve, and operationalize admin consent for third-party enterprise application integrations across the tenant.

Own enterprise application and service principal onboarding, enforcing least-privilege access models and secure authentication patterns.

Create, manage, and govern App Registrations, including secret and certificate lifecycle management, rotation standards, and expiration monitoring.

Design and enforce least-privilege Microsoft Graph permission models for applications and identity automation.

Define and maintain standards that prevent interactive sign-in for service accounts, leveraging Conditional Access and non-interactive authentication models.

Define and enforce identity security guardrails for privileged access, MFA requirements, service accounts, and break-glass scenarios.

Implement and govern Microsoft Entra Privileged Identity Management (PIM) for administrative roles, just-in-time elevation, approval workflows, access reviews, and privileged access monitoring.

Design and administer Microsoft Entra Administrative Units to delegate identity and user management with scoped administrative control across regions, business units, and support teams.

Operate and evolve modern authentication and MFA methods globally, aligning with Microsoft Entra Authentication Methods and organizational security standards.

Support and standardize passwordless authentication approaches, including FIDO2 and hardware security keys, across regions and business units.

Support B2B, B2C, cross-tenant, and external identity scenarios for partners, vendors, and client-facing platforms.

Partner with platform, security, and Azure engineering teams to design and deliver secure Azure access models, role assignments, and identity integrations.

Act as the escalation point for complex identity-related incidents, authentication failures, and access issues.

Produce audit-safe documentation and evidence supporting security, compliance, and regulatory requirements.

Demonstrate a strong understanding of Microsoft 365 (M365) and its identity integrations with Entra ID, including authentication flows, access controls, and tenant-level governance considerations.

#LI-JM

About Lockton

Lockton Companies is the world's largest privately held insurance brokerage firm, providing insurance, risk management, employee benefits and retirement services. The company was founded in 1966 and is headquartered in Kansas City, Missouri. Lockton has more than 7,500 associates in over 100 offices worldwide. The company serves clients in a variety of industries, including construction, healthcare, hospitality, manufacturing, real estate, and technology. Lockton is known for its innovative solutions and exceptional customer service.
Learn more about Lockton
Size
7,500 employees
Industry
Founded
1966

Similar Jobs

More Jobs at Lockton

More Information Technology Jobs

Find similar Sr Identity Engineer jobs: