Hybrid Principal Authentication Services Engineer

Posted 10 hours ago

Apply now

About the role

  • Principal Authentication Services Engineer at 3M, leading IAM architecture and engineering initiatives. Expert in Zero Trust security and enterprise authentication solutions across a global environment.

Responsibilities

  • Own the engineering design, implementation, and operational health of Microsoft Entra ID, Active Directory, and federated identity services across the enterprise
  • Architect and maintain SSO integrations (SAML, OIDC, OAuth 2.0) across SaaS, on-prem, and hybrid application portfolios
  • Engineer and manage MFA policies, authentication method configurations, and phishing-resistant credential adoption (FIDO2, Windows Hello for Business, certificate-based auth)
  • Lead Conditional Access policy development, testing, and lifecycle governance
  • Define authentication standards, patterns, and reference architectures for new and existing applications -- and own keeping them current
  • Evaluate emerging authentication technologies and drive proof-of-concept efforts that inform roadmap decisions
  • Maintain technical documentation including architecture diagrams, decision records, and runbooks
  • Partner with Security Architecture to align authentication controls with Zero Trust principles and enterprise security policy
  • Support audit and compliance activities by providing technical evidence, control narratives, and remediation guidance
  • Identify gaps in authentication posture and lead engineering remediation efforts
  • Serve as escalation point for complex authentication incidents and engineering challenges
  • Mentor and uplift mid-level engineers on the Authentication Services team
  • Engage with application teams, infrastructure engineering, and security operations as a trusted IAM authority.

Requirements

  • Bachelor’s degree or higher (completed and verified prior to start)
  • Eight (8) years of experience designing, deploying, and managing enterprise Identity and Access Management (IAM) authentication solutions (e.g., Entra ID, Ping Identity, Active Directory) in a private, public, government or military environment
  • Five (5) years of experience working with modern authentication protocols, including SAML, OAuth 2.0, OpenID Connect (OIDC), and FIDO2 in a private, public, government or military environment
  • Five (5) years of experience leading complex architectural initiatives, conditional access hardening, or Zero Trust security programs in a private, public, government or military environment

Benefits

  • Medical, Dental & Vision
  • Health Savings Accounts
  • Health Care & Dependent Care Flexible Spending Accounts
  • Disability Benefits
  • Life Insurance
  • Voluntary Benefits
  • Paid Absences
  • Retirement Benefits

Job title

Principal Authentication Services Engineer

Job type

Experience level

Lead

Salary

$145,676 - $178,049 per year

Degree requirement

Bachelor's Degree

Location requirements

Report this job

See something inaccurate? Let us know and we'll update the listing.

Report job