Hiring.Camp

Identity Engineer - Active Directory

Ralliant

·

Today

Location
KA,IN, IN · IN
Workplace
Remote
Type
Full-time
Department
Engineering
Seniority
Director
Experience
10+ years
Education
Master
Source
Eightfold

Description

Role description

The Identity Engineer is responsible for administering, securing, and supporting the enterprise's directory services and public key infrastructure (PKI) environment, with a primary focus on Microsoft Active Directory Certificate Services (AD CS), certificate lifecycle management, and hybrid directory architecture (multiple Active Directory domains and Microsoft Entra ID). This role ensures secure, reliable identity infrastructure that underpins authentication, encryption, and trust across the enterprise.

This role acts as both a platform administrator and a technical troubleshooter, resolving complex directory, certificate, and authentication issues across on-premises, cloud, and hybrid environments. The engineer partners closely with Security, Infrastructure, and Application teams to maintain a healthy directory and PKI foundation, issue and manage certificates, and respond quickly to incidents affecting directory availability or certificate trust.

The role is hands‑on and execution‑focused while embracing the Ralliant Business System (RBS) by embedding operational discipline, staff training, and continuous improvement into tools, workflows, and standard work so endpoint management is scalable, measurable, and repeatable. The role operates in service to the enterprise and operating companies, ensuring standardized Identity practices while adapting to regional and business-specific needs.

Key responsibilities

  • Administer and maintain Active Directory Certificate Services (AD CS), including root and issuing certificate authorities, certificate templates, and enrollment policies.
  • Manage the end-to-end certificate lifecycle, including issuance, renewal, revocation (CRL/OCSP), and expiration monitoring across internal and public-facing systems.
  • Administer and maintain directory services (Active Directory, LDAP), including forest/domain architecture, replication health, group policy, OU structure, and schema management.
  • Manage hybrid identity synchronization via Azure AD Connect/Entra Connect, including sync rules, attribute flow, and troubleshooting synchronization failures.
  • Support Microsoft Entra ID administration where it intersects with directory and certificate-based authentication, including certificate-based authentication (CBA), conditional access, and device trust.
  • Configure and manage SSL/TLS certificate deployment for servers, applications, and network devices, ensuring proper chain validation and trust store management.
  • Troubleshoot and resolve complex directory and certificate-related connectivity issues, including DNS resolution, Kerberos/NTLM authentication, LDAPS binding, and certificate chain validation.
  • Support authentication and authorization troubleshooting across Active Directory/LDAP, SAML, MFA, and SSO integrations as they relate to directory and certificate trust.
  • Develop PowerShell and Python/REST API scripts to automate certificate issuance/renewal, directory reporting, and PKI health monitoring.
  • Monitor and analyze AD CS, directory, and network logs, supporting SIEM integration, PKI health monitoring, and incident response.
  • Apply directory and PKI security best practices, supporting compliance with frameworks such as SOX, PCI-DSS, NIST, and ISO 27001.
  • Partner with Security, Infrastructure, and Application teams to plan certificate authority hierarchy, directory architecture changes, and migrations across enterprise and OpCo environments.
  • Document procedures, configurations, and incident reports, and train end users and application teams on certificate request processes and directory best practices.
  • Plan and execute directory and PKI disaster recovery procedures, including CA backup/restore and directory forest recovery readiness.

Qualifications

  • Bachelor's degree recommended; equivalent experience considered.
  • 10+ years of experience in cybersecurity, systems administration, or identity and access management, with 5\+ years hands-on experience administering Active Directory Certificate Services (AD CS) and enterprise PKI.
  • Strong understanding of PKI architecture, including certificate authority hierarchy (root/issuing CAs), certificate templates, CRL/OCSP, and key management.
  • Deep working knowledge of Active Directory and LDAP, including forest/domain design, replication, group policy, and schema administration.
  • Experience with hybrid identity synchronization (Entra Connect or equivalent) and Microsoft Entra ID, including conditional access and certificate-based authentication.
  • Proficiency in DNS, Kerberos/NTLM authentication, and certificate chain troubleshooting across on-premises and cloud environments (AWS, Azure, GCP).
  • Experience with SAML, MFA, and SSO authentication and authorization troubleshooting as it relates to directory and certificate trust.
  • Scripting experience in PowerShell and Python, with working knowledge of REST APIs and certificate automation tooling.
  • Experience with log analysis and SIEM integration, incident response, and root cause analysis for directory and PKI environments.
  • Knowledge of compliance frameworks (SOX, PCI-DSS, NIST, ISO 27001) and zero trust security principles.
  • Microsoft Certified: Identity and Access Administrator (SC-300) or equivalent certification preferred; cloud platform or security certifications (AWS, Azure, GCP, CISSP, CISM, Security+) a plus.
  • Strong communication and documentation skills, with the ability to explain technical concepts to non-technical stakeholders and train end users and application teams.
  • Ability to operate effectively across enterprise and OpCo environments, balancing global consistency with local context across multiple time zones and cultures.
  • Alignment with Ralliant values and the Ralliant Business System (RBS), including continuous improvement, transparency, and ownership.

#LI-MG1

Ralliant Corporation Overview

Ralliant, originally part of Fortive, now stands as a bold, independent public company driving innovation at the forefront of precision technology. With a global footprint and a legacy of excellence, we empower engineers to bring next-generation breakthroughs to life — faster, smarter, and more reliably. Our high-performance instruments, sensors, and subsystems fuel mission-critical advancements across industries, enabling real-world impact where it matters most. At Ralliant we’re building the future, together with those driven to push boundaries, solve complex problems, and leave a lasting mark on the world.

We Are an Equal Opportunity Employer. Ralliant Corporation and all Ralliant Companies are proud to be equal opportunity employers. We value and encourage diversity and solicit applications from all qualified applicants without regard to race, color, national origin, religion, sex, age, marital status, disability, veteran status, sexual orientation, gender identity or expression, or other characteristics protected by law. Ralliant and all Ralliant Companies are also committed to providing reasonable accommodations for applicants with disabilities. Individuals who need a reasonable accommodation because of a disability for any part of the employment application process, please contact us at [email protected].

Bonus or Equity

This position is also eligible for bonus as part of the total compensation package.

Skills

PythonAWSAzureGCPCybersecuritySIEMRESTSOXComplianceISO 27001CISSP

Similar Jobs

30

Identity Engineer - Active Directory

Ralliant·Karnataka, India·Hybrid

Today

Senior Engineer, Identity Access Management (IAM Engineer)

Kroll·Manila, Philippines

Today

Identity Engineer - Privilege Access

Ralliant·Karnataka, India·Hybrid

Today

Identity Engineer - Privilege Access

Ralliant·KA +1·Remote

Today

Identity Automation Engineer

Ralliant·Karnataka, India·Hybrid

Today

Identity Automation Engineer

Ralliant·KA +1·Remote

Today

Engineer, Workforce Identity and Access Management - Sailpoint

Cardinalhealth·Philippines-Bonifacio Global City-Taguig

Today

Engineer, Workforce Identity & Access Management - Okta

Cardinalhealth·Philippines-Bonifacio Global City-Taguig·Hybrid

Today

Associate - Identity & Security Operations Engineer

Oaktree·Oaktree Hyderabad, India

Today

Platform Engineer, IAM Identity Gov. & Admin

Mdlz·Remote Worker - Poland +1·Remote

Today

Staff Software Engineer - Identity and Verifications Team

LinkedIn·Mountain View, CA·Hybrid

1d ago

Senior Backend Developer - Identity and Access Management (IAM)

Fullscript·Ottawa, ON +2·Remote

1d ago

One Identity PAM Engineer

Exequt·Riyadh

1d ago

Azure Cloud Engineer (Platform & Identity)

Xerxes Global·Bloomington, Minnesota

1d ago

Information Security Identity and Access Engineer

Psecu·Elmerton Ave, US·Onsite

1d ago

M365 & Identity Engineer, Lead

Pae·US-VA-Richmond, US·Remote

1d ago

Staff Software Engineer - Identity

Capitalone·McLean, VA +2

1d ago

Identity and Access Management (IAM) Engineer (Senior)

Interclypse Inc.·Annapolis Junction, MD·Onsite

1d ago

Identity and Access Management (IAM) Engineer

Interclypse Inc.·Annapolis Junction, MD·Onsite

1d ago

Identity and Access Management (IAM) Engineer (Mid)

Interclypse Inc.·Annapolis Junction, MD·Onsite

1d ago

Principal Engineer, Identity & Access Management

Questrade Financial Group·Israel

2d ago

Principal Engineer, Identity & Access Management

Questrade Financial Group·Israel

2d ago

Software Development Engineer, Items and Offers Platform, Identity Performance and Defect Detection

Amazon·Remote

2d ago

Software Development Engineer, Items and Offers Platform, Identity Performance and Defect Detection

Amazon·Remote

2d ago

Staff Software Engineer, Backend (Identity Decisioning)

Affirm·Remote Canada·Remote

2d ago

Staff Software Engineer, Backend (Identity Decisioning)

Affirm·Remote US·Remote

2d ago

Sr Identity & Access Management Engineer (IAM)

earlywarningservices·Chicago, US·Hybrid

2d ago

Software Engineer, Identity

Hadrian Automation·Los Angeles, CA·Onsite

2d ago

Senior/Lead - Cyber Security - IAM Engineer - Identity and Governance

Fico·Work from Home, US·Remote

2d ago

IT Security & Identity Engineer

Neuralink·Austin, Texas

5d ago