Identity Engineer - Tier 2
Remote Worker
Description

The Identity & Access Engineer performs day-to-day administration and support of client hybrid identity environments spanning on-premises Active Directory and Microsoft Entra ID. This role is accountable to the Director of Operations for account lifecycle accuracy, directory synchronization health, and identity-related incident response within defined authorization boundaries, and operates under the functional oversight of the client's designated identity function owner. 


Duties and Responsibilities

  • Provision and de-provision user and group accounts in on-premises Active Directory, applying correct OU placement per the client's existing structure
  • Execute and maintain established Identity Lifecycle (Joiner/Mover/Leaver) automation, validating that automated actions complete correctly and remediating exceptions
  • Perform password resets and account unlocks across on-premises AD and synchronized Entra ID identities
  • Support multifactor authentication enrollment and troubleshoot routine authentication failures for end users
  • Troubleshoot Group Policy application using existing approved policies, diagnosing precedence, scope, and replication issues without creating or modifying GPOs
  • Monitor and triage Entra Connect synchronization errors and sync health alerts, resolving routine issues and escalating configuration-level causes
  • Assign licenses and perform standard attribute updates within Entra ID
  • Respond to Severity 2 and 3 identity service disruptions including sync delays and login failures, and route suspected security incidents to the defined cybersecurity team per the incident response runbook
  • Request, use, and release just-in-time privileged access in accordance with client PAM procedures, maintaining accurate records of elevated activity
  • Recognize and halt on activities reserved for client authorization, including sync configuration and topology changes; GPO, OU, or schema modification; Conditional Access policy changes; elevated role assignments; PIM/PAM policy configuration; trust and federation changes; and tenant-level authentication method changes
  • Maintain accurate documentation and follow change management procedures without exception in client environments
Requirements
  • 3–5 years administering Active Directory in a production environment, including account lifecycle, OU and group management, and Group Policy troubleshooting
  • Hands-on experience with hybrid identity, specifically Entra Connect (or Azure AD Connect) synchronization, including sync error triage, attribute flow, and understanding of how on-premises changes propagate to the cloud
  • Working knowledge of Microsoft Entra ID administration, including licensing, attribute management, and authentication methods
  • Practical experience supporting multifactor authentication and Conditional Access from an end-user troubleshooting perspective
  • Familiarity with Privileged Identity Management and just-in-time access models, and demonstrated ability to work productively without standing administrative rights
  • Understanding of identity lifecycle automation and the ability to validate and remediate automated provisioning workflows
  • Ability to distinguish an identity service disruption from a potential identity compromise, and to escalate the latter immediately rather than troubleshoot it
  • Experience delivering support in a managed services or multi-client environment, including ticket queue discipline, SLA adherence, and change management
  • PowerShell proficiency for directory administration and reporting
  • Microsoft certifications such as SC-300 (Identity and Access Administrator) or equivalent demonstrated experience preferred

All Sparkhound employees are expected to handle client and company data with care, follow our information security policies, complete required security training, and report any suspected incidents or policy violations promptly. Employees are also responsible for maintaining accurate documentation and following change management procedures when working in client environments.