Entra ID & AD Architect
About the role
We are seeking a Entra ID & AD Architect (SME) driving design, security, and operations of hybrid identity. Senior individual contributor owning architecture and escalations. Delivering resilient, scalable identity in collaboration with security and cloud teams.
Responsibilities
- Own the end-to-end architecture for hybrid identity spanning on-premises Active Directory, Entra ID, and Entra Connect / Cloud Sync.
- Design and document target-state identity reference architectures, including authentication flows, trust topologies, forest/domain design, and tenant strategy.
- Configure and optimize Entra ID capabilities: SSO/SAML/OIDC federation, application registrations & enterprise apps, App Proxy, B2B/B2C, dynamic groups, and Entra ID Governance (access reviews, entitlement management, lifecycle workflows).
- Automate identity operations using PowerShell and Microsoft Graph API.
- Partner with SecOps on identity threat detection (Entra ID Protection, Defender for Identity) and incident response for identity-based attacks (Golden Ticket, password spray, token theft, etc.).
- Act as Tier 3 / final escalation for complex identity incidents and outages.
- Establish standards, best practices, and guardrails; review designs from junior engineers and vendor partners.
- Produce high-quality documentation: HLDs/LLDs, runbooks, knowledge articles, and architecture decision records.
- Mentor engineers and uplift the broader team's identity capability through knowledge transfer and design reviews.
Qualifications
- Education – Bachelor in Computer Science or related field.
- Experience – Minimum 15 Years in field.
- Fluency in English Language – written & verbal.
Preferred Qualifications
- Translates complex identity concepts into clear, audience-appropriate language — able to brief executives, write precise documentation, and guide hands-on engineers with equal ease.
- Strong written skills for architecture documents, runbooks, and decision records.
- Congfident, respectful communicator in design reviews, incident bridges, and cross-team negotiations.
- Ownership mindset — treats the identity platform as their own; sees problems through to root-cause resolution rather than handing them off.
- Proactive and self-directed; identifies risks and improvement opportunities without being asked.
- Calm, composed, and decisive under pressure during outages and security incidents.
- Humble and coachable — open to feedback and willing to say "I don't know, let me find out."
Benefits
The exact Salary will be determined based on qualifications, experience and location. If you need a reasonable accommodation for any part of the employment process, please contact us by email at usaccommodations@gf.com and let us know the nature of your request and your contact information. Requests for accommodation will be considered on a case-by-case basis. Please note that only inquiries concerning a request for reasonable accommodation will be responded to from this email address. An offer with GlobalFoundries is conditioned upon the successful completion of pre-employment conditions, as applicable, and subject to applicable laws and regulations.
Pay
$124,000.00 - $208,000.00
Schedule
N/A