Principal Engineer
Saur Energy International · Location, WV · 3 days ago
Full-time
About the role
This Principal Engineer role serves as the principal technical owner for global IAM and directory services platforms supporting enterprise, partner, and customer-facing applications. The position ensures continuity, resilience, and long-term sustainability of identity services—across humans, machines, and AI—that the business depends on every day. Identity is a Tier-0 dependency, and this role directly protects the organization from identity-driven downtime and degraded user access, over-privileged or unmanaged AI, robotic, and service identities, increased risk during mergers, acquisitions, and integrations, delays or failures in Zero Trust adoption, and compliance exposure and erosion of trust.
Responsibilities
- Act as the principal technical owner for global IAM and directory services platforms supporting enterprise, partner, and customer-facing applications.
- Define, document, and evolve end-to-end IAM architecture, including Active Directory (enterprise-scale, hybrid, multi-region), Entra ID / Azure AD (including B2C and external identities), Oracle Unified Directory (OUD), and Linux and Unix authentication and authorization integrations.
- Establish reference architectures, engineering standards, and operational patterns for identity platforms.
- Design for high availability, fault tolerance, disaster recovery, and regional resilience.
- Ensure continuous availability of authentication and authorization services by proactively managing identity dependencies.
- Own directory synchronization, federation, and authentication flows across hybrid environments.
- Eliminate architectural and operational single points of failure.
- Prevent identity issues that could result in global user access degradation, business application downtime, and customer- and partner-facing access disruption.
- Make identity the primary control plane for Zero Trust initiatives.
- Enforce least privilege, strong authentication, and continuous verification.
- Design and implement RBAC, ABAC, and policy-based authorization models.
- Strengthen directory security posture by addressing privileged access exposure, legacy protocols and weak authentication mechanisms, and inconsistent policy enforcement and configuration drift.
- Reduce identity-based attack paths and systemic access risk.
- Architect and secure non-human identities, including AI agent identities, Robotic Process Automation (RPA) identities, and service accounts, workloads, APIs, and system identities.
- Define lifecycle management, authentication, authorization, and rotation strategies for machine identities.
- Prevent credential sprawl, over-privileged access, and unmanaged secrets.
- Ensure AI and robotic identities adhere to Zero Trust, least privilege, and auditable access principles.
- Integrate non-human identity controls into enterprise IAM governance and monitoring.
- Improve identity integration across enterprise applications, partner platforms, and customer-facing (B2C) ecosystems.
- Ensure seamless, low-friction authentication experiences without compromising security.
- Enable scalable access models for human and non-human identities.
- Serve as the IAM technical lead for M&A initiatives.
- Assess acquired company identity architectures, directory services, and authentication models.
- Design and execute secure identity integration, consolidation, or coexistence strategies.
- Mitigate access risk during transitions while maintaining business continuity.
- Ensure acquired environments align with enterprise IAM, Zero Trust, and security standards.
- Ensure knowledge continuity and eliminate dependency on individual resources.
- Define a multi-year IAM and directory services roadmap aligned with enterprise architecture and Zero Trust maturity.
- Evaluate emerging identity technologies, protocols, and access models, including AI-driven identity use cases.
- Mentor engineers and elevate IAM engineering maturity across the organization.
Required Qualifications
- 12+ years of experience in Identity & Access Management, directory services, or security platform engineering.
- Proven experience supporting global, highly available, business-critical identity systems.
Technical Expertise
- Architectural-level expertise in Active Directory (enterprise and hybrid environments), Entra ID / Azure AD (including B2C), Oracle Unified Directory (OUD), and Linux and Unix authentication mechanisms.
- Strong understanding of authentication and authorization flows, identity federation and synchronization, RBAC, ABAC, and policy-driven access models, and Zero Trust and identity-centric security architecture.
- Hands-on experience with identity protocols: SAML 2.0, OAuth 2.0, OpenID Connect (OIDC), Kerberos, LDAP/LDAPS, SCIM, RADIUS, SSH key-based authentication, PAM (Pluggable Authentication Modules) for Linux, certificate-based authentication (X.509), and modern API-based identity integrations, etc.
- Experience with automation and integration: PowerShell, Python, APIs, infrastructure-as-code preferred.
Architectural & Leadership Skills
- Ability to design for availability, resilience, and failure scenarios.
- Strong systems thinking and long-term technical judgment.
- Proven ability to influence architecture and strategy across teams without formal authority.
- Comfortable operating in ambiguous, high-impact environments.
Preferred Qualifications
- Experience supporting customer-facing digital platforms at global scale.
- Cloud IAM experience across Azure, AWS, and/or GCP.
- Familiarity with identity governance, privileged access, and compliance frameworks.
- Experience working with globally distributed teams, including India-based engineering support models.
- Prior experience supporting identity integration during M&A activities.