Summary
A senior identity engineering opportunity is available for an expert who can modernize complex enterprise directory environments and move them from manual administration toward automated, version-controlled cloud architectures. You will design and operate domains, forests, trust relationships, and authentication services while building infrastructure-as-code workflows, CI/CD automation, and hybrid identity integrations. The role combines deep directory engineering with cloud security, troubleshooting, and continuous authentication health across complex environments.
Highlights
Lead modernization of large-scale enterprise identity infrastructure with hands-on ownership of hybrid cloud identity, automation, infrastructure as code, and security. The role offers strong benefits during the contract, including fully paid medical and dental coverage, paid time off, holidays, and an immediate retirement-plan match, with potential for extension or conversion.
Description
Senior IAM Engineer (Active Directory & Cloud)
Summary
This role exists to lead the modernization and ongoing engineering of a large-scale enterprise identity infrastructure.
The engineer will transition legacy Active Directory environments away from manual administration toward modern, automated cloud identity architectures integrated across Amazon Web Services (AWS) and Microsoft Entra ID.
Most of the week will involve hands-on Active Directory engineering, designing identity patterns, and writing automated infrastructure-as-code scripts to manage domains, forests, trust relationships, and conditional access policies.
Success in this position requires replacing manual administration with documented, version-controlled identity configurations and ensuring continuous authentication health across hybrid environments.
Responsibilities
Design, engineer, and operate enterprise Active Directory forests, domains, trust relationships, and domain controllers.Automate Active Directory administration using Infrastructure as Code (IaC) tools including Terraform and Ansible.Build and maintain version-controlled identity configurations within Git repositories using GitOps and CI/CD pipelines.Develop AWS integration patterns facilitating secure identity authentication using LDAP and Kerberos protocols.Support Microsoft Entra ID integration and configure conditional access policies across hybrid cloud environments.Troubleshoot complex Tier-3 Active Directory health issues involving authentication, replication, and DNS dependencies.
Required Experience
6+ years of hands-on Active Directory engineering experience in large, multi-domain enterprise environments.Demonstrated experience automating infrastructure management using Terraform or Ansible.Hands-on experience implementing CI/CD pipelines and GitOps workflows for directory management.Strong working knowledge of AWS identity integrations, including AWS Managed Microsoft AD or self-hosted AD.Expertise managing Microsoft Entra ID, hybrid directory sync, and conditional access policies.
Preferred Experience
Experience developing application authentication patterns using Kerberos over basic LDAP.Deep understanding of privileged access management (PAM) and delegated administration security models.Knowledge of cloud security frameworks supported by active AZ-500 or Security+ certifications.
This is an 8-month contract opportunity with our Kansas City, MO client, with the potential for extensions or conversion to a full-time position if additional headcount is approved.
TriCom offers 100% paid employee medical and dental benefits, paid time off, paid holidays, and a 401(k) with an immediate company match during the contract period.
H-1B visa sponsorship is not available for this position.
No third-party candidates, please.