Senior Identity Infrastructure Engineer
Duration: 5+ Months | Location: Wayzata, MN (Hybrid – 1-2 days onsite)
About the role
Every Turnberry consultant belongs to a practice, an internal group of consultants and leaders with shared experience and expertise. Each of these practices aligns to one of the core services Turnberry offers to clients. As a Senior Identity Infrastructure Engineer, you will join Turnberry's Digital Modernization practice, where technology and strategy combine to deliver exceptional digital experiences, empowering organizations to thrive in today's digital market.
Responsibilities
- Design, engineer, operate, and secure Active Directory forests, domains, trusts, organizational units, Group Policy, and domain controllers
- Partner with IAM and PAM teams to design and support privileged access controls, including administrative group structures and delegated administration models
- Monitor, troubleshoot, and remediate Active Directory health issues, including authentication failures, replication, DNS dependencies, domain controller availability, and account state incidents
- Support integrations between Active Directory and identity governance, access request, authentication, and certification platforms
- Develop and maintain standards, runbooks, and operational documentation for Active Directory services and domain controller operations
- Participate in change management, incident response, audits, and continuous improvement initiatives aligned to the IAM roadmap and security strategy
- Develop integration patterns with AWS to facilitate authentication with AD using LDAP or Kerberos
- Develop application development patterns encouraging app devs to leverage Kerberos over just LDAP
Qualifications
- Hands-on experience administering Microsoft Active Directory in large, complex enterprise environments
- Strong understanding of Active Directory security principles, delegation models, and privileged group management
- Experience operating Active Directory as part of an integrated Identity and Access Management (IAM) ecosystem
- Proven troubleshooting skills across authentication, replication, DNS, account lifecycle, and access issues
- Experience working with AWS and any of its Active Directory implementation options (e.g., Managed AD, self-hosted, etc.)
- Experience integrating Active Directory with identity governance or privileged access management platforms
- Experience supporting global, multi-domain, or multi-region Active Directory environments
Pay
The salary range for this role is $120,000 to $170,000 or the hourly equivalent. Pay is based on several factors including education, work experience, and certifications.
Benefits
- Comprehensive healthcare package (medical, dental, vision)
- Disability and group term life insurance
- Health and flexible spending accounts
- Utilization bonus
- 401(k) with match
- Flexible time off for salaried employees
- Parental leave for salaried employees
- Flexible work arrangements
All benefits are subject to eligibility requirements.