Jobs · Engineering · Minnesota

Senior Authentication Services Engineer

3M · Minnesota, United States · Yesterday
Engineering$146k–$178k/yrFull-time

The Impact You’ll Make in this Role

The Senior Authentication Services Engineer is a skilled technical contributor within the Identity & Access Management organization. This role is responsible for the engineering, implementation, and operational support of enterprise authentication platforms across a complex global environment. Working closely with the Principal Engineer and IAM leadership, you will deliver authentication capabilities, maintain platform health, and contribute to the evolution of authentication services aligned with the broader Zero Trust security strategy. This is a hands-on engineering role with growing technical ownership. You will implement authentication solutions, support integrations across the application portfolio, and contribute to standards and documentation that serve the broader IAM program.

Here, You Will Make an Impact By

Authentication Platform Engineering

  • Engineer, configure, and maintain Microsoft Entra ID, Active Directory, and federated identity services across the enterprise
  • Implement and support SSO integrations (SAML, OIDC, OAuth 2.0) across SaaS, on-prem, and hybrid application portfolios
  • Configure and manage MFA policies, authentication method settings, and phishing-resistant credential rollouts (FIDO2, Windows Hello for Business, certificate-based auth)
  • Develop, test, and maintain Conditional Access policies in alignment with security requirements
  • Contribute to authentication standards, patterns, and reference architectures under guidance from the Principal Engineer
  • Participate in proof-of-concept efforts for emerging authentication technologies
  • Maintain and update technical documentation including runbooks, configuration records, and architecture diagrams

Security & Compliance

  • Support alignment of authentication controls with Zero Trust principles and enterprise security policies
  • Provide technical evidence, control narratives, and remediation support for audit and compliance activities
  • Identify and remediate gaps in authentication posture through engineering solutions
  • Monitor authentication platform health and respond to security incidents within the authentication domain

Collaboration & Operational Excellence

  • Support incident response and troubleshoot complex authentication issues as a technical escalation resource
  • Collaborate with application teams, infrastructure engineering, and security operations to deliver IAM solutions
  • Contribute to knowledge transfer, documentation, and team skill development
  • Participate in on-call rotation for authentication platform support

Your Skills and Expertise

To set you up for success in this role from day one, 3M requires (at a minimum) the following qualifications:

  • High School Diploma (verified and completed prior to start) and 8 years of experience in Information Technology, Computer Science, IAM Engineering, or Information Security in a private, public, government, or military environment.
  • OR Bachelor's degree or higher (verified and completed prior to start) and Six (6) years of experience in Information Technology, Computer Science, IAM Engineering, or Information Security, in a private, public, government, or military environment.

Additional Qualifications That Could Help You Succeed Even Further

  • Microsoft Entra ID: Strong hands-on experience including Conditional Access, PIM, application registrations, and hybrid identity (Entra Connect)
  • Active Directory: Solid working knowledge of domain architecture, Group Policy, trusts, Kerberos, NTLM, and AD security hardening
  • MFA: Experience implementing enterprise MFA solutions including phishing-resistant methods (FIDO2, WHfB)
  • Federation protocols: Working proficiency with SAML 2.0, OIDC, and OAuth 2.0
  • SSO: Experience supporting integrations across enterprise SaaS and on-premises application portfolios
  • Automation: Working knowledge of PowerShell scripting and Microsoft Graph API for identity operations
  • Familiarity with identity security tooling (e.g., Microsoft Defender for Identity, Entra ID Protection, SIEM integrations)
  • Windows Hello for Business: Exposure to WHfB deployment planning or FIDO2/YubiKey rollouts
  • PAM platforms: Familiarity with CyberArk or comparable PAM tools and their intersection with authentication services
  • Exposure to IGA platforms and lifecycle event integration with authentication systems
  • Cloud Identity: Experience with AWS IAM, Azure AD B2B/B2C, or multi-cloud identity federation
  • Certifications: SC-300, AZ-500, or equivalent Microsoft identity certifications (preferred, not required)
  • Experience working in large enterprise environments with complex hybrid identity architectures

Work Location

On-site in Maplewood, MN, or Austin, TX office at least 4 days per week

Travel

May include up to 15% domestic/international

Relocation Assistance

Is not authorized

Pay

The expected compensation range for this position is $145,676 - $178,049, which includes base pay plus variable incentive pay, if eligible. This range represents a good faith estimate for this position. The specific compensation offered to a candidate may vary based on factors including, but not limited to, the candidate's relevant knowledge, training, skills, work location, and/or experience.

Benefits

In addition, this position may be eligible for a range of benefits (e.g., Medical, Dental & Vision, Health Savings Accounts, Health Care & Dependent Care Flexible Spending Accounts, Disability Benefits, Life Insurance, Voluntary Benefits, Paid Absences and Retirement Benefits, etc.). Additional information is available at: https://www.3m.com/3M/en_US/careers-us/working-at-3m/benefits/.

Schedule

This position may require participation in an on-call rotation for authentication platform support.

Similar jobs