IT SPECIALIST - SR. IT SPECIALIST - Microsoft Entra ID & Active Directory Specialist
About the role
Our team, the Cloud Services team within the Information Technology Center, is responsible for Entra ID (formerly Azure)/M365 cloud services and Active Directory for the Enterprise. The team provides support and implementation services to the entire organization's IT infrastructure. This role combines strategic identity modernization with senior-level operational support, leading multiple identity modernization projects in parallel while serving as the escalation point for complex identity issues that require deep troubleshooting expertise.
Responsibilities
The role involves architecting and implementing Conditional Access, MFA, SSO, and Zero Trust policies, as well as leading identity lifecycle automation and governance. Additional responsibilities include designing secure integrations using OAuth, SAML, and OpenID Connect, hardening privileged access with PIM, PAM, and tiered administration, and evaluating and modernizing legacy identity components such as ADFS and on-premises IAM tooling.
- Provide expert support for Active Directory and Entra ID by managing accounts, groups, group policies, and directory synchronization across hybrid identity infrastructures.
- Architect, configure, and support Conditional Access, MFA, SSO, and Zero Trust access policies in Entra ID.
- Implement and support secure app integrations using OAuth, SAML, and OpenID Connect, including app/enterprise applications, and associated claims and access policies.
- Manage and troubleshoot ADFS and other legacy or transitional identity components to maintain secure access to enterprise and cloud resources.
- Serve as the senior escalation point for identity-related helpdesk tickets, including advanced account provisioning problems, access failures, directory synchronization issues, and application sign-in problems.
- Mentor and support junior administrators and helpdesk staff.
- Conduct regular audits of Active Directory and Entra ID environments to detect, address, and mitigate potential security vulnerabilities.
- Create and maintain documentation related to processes, configurations, and governance policies.
Requirements
Requires a Bachelor's degree in Information Technology or related degree field with relevant experience. In lieu of a Bachelor's degree, 6 years of professional level experience, a high school education or equivalent with related certifications will be considered.
- 2+ years of experience managing enterprise identity platforms, including Active Directory Domain Services and Entra ID (Azure AD), in hybrid environments.
- Demonstrated experience with Conditional Access, MFA, and SSO design and support.
- Experience troubleshooting complex authentication and authorization issues across on-premises and cloud workloads.
- Hands-on experience with Active Directory Federation Services (AD FS) and familiarity with Public Key Infrastructure (PKI) systems, including creating, renewing, and troubleshooting certificates.
- Technical Certifications such as Microsoft Certified Solutions Associate (MCSA) and/or Microsoft Certified Solutions Expert (MCSE) or Microsoft Certified: Azure Administrator Associate, Azure Fundamentals or equivalent are preferred.
Qualifications
A valid/clear driver's license is required. The applicant selected will be subject to a government security investigation and must meet eligibility requirements for access to classified information. The applicant must be a U.S. citizen.
Skills
Relevant Microsoft Certifications are preferred, including experience with OAuth, SAML, and OpenID Connect.
Location
San Antonio, Texas