SanDisk logo
SanDiskPosted 1 month ago

Staff Security Operations Engineer

HybridIrvine, California, United States

Full TimeSenior LevelLarge

Job Summary

Lead the migration of devices into Microsoft Entra ID, including join and hybrid scenarios, by planning waves, developing runbooks, and coordinating with endpoint and security teams to minimize disruption. Provide engineering-level support for the Entra ID platform, configuring Conditional Access, Identity Protection, and hybrid synchronization via Entra Connect while acting as the technical escalation point for incidents. Manage MFA platforms like Duo and Windows Hello, enforce policies across applications, and support Intune for mobile device compliance. Automate identity tasks using PowerShell and Microsoft Graph, generate compliance reports, and continuously optimize IAM processes to enhance security and user experience.

Required Qualifications

  • BA or BS in Information Technology, Computer Science, Information Security, or a related field
  • Equivalent hands-on experience in IAM may be considered in lieu of a degree
  • 6+ years of experience in IT or Information Security, with a focus on identity and access management
  • 3+ years of direct, hands-on experience with Microsoft Entra ID (Azure AD), including device migration and engineering support
  • Experience working with Duo MFA, Windows Hello for Business, Microsoft Intune, and Active Directory
  • Hands-on experience driving device migrations into Entra ID, including Entra ID join and hybrid Entra ID join
  • Engineering-level experience administering Entra ID, including Conditional Access, Identity Protection, SSO, app registrations, and enterprise applications
  • Experience with Microsoft Entra Connect (Azure AD Connect) for hybrid identity synchronization between on-prem AD and Entra ID
  • Ability to configure, enforce, and troubleshoot Entra ID policies across diverse applications, devices, and systems
  • Experience administering and managing Duo MFA and Windows Hello for Business, or similar authentication platforms
  • Ability to configure, enforce, and troubleshoot MFA policies across diverse applications and systems
  • Knowledge of MS Intune platforms and their integration with IAM systems for device security and policy enforcement
  • Experience managing devices in an enterprise setting, focusing on compliance and access control
  • Experience managing user accounts, group policies, and organizational units in Active Directory
  • Familiarity with hybrid identity environments and synchronization between on-prem AD and Entra ID
  • PowerShell and Microsoft Graph scripting skills to automate identity and device tasks such as provisioning, migration, reporting, and troubleshooting
  • Familiarity with security information and event management (SIEM) tools for monitoring identity-related logs and events
  • Experience generating audit reports for compliance purposes
  • Primary work in the Irvine, California office and/or a home office environment (hybrid)
  • Willing to be on call as needed to support critical identity and device operations
  • Willing to perform work functions across time zones to support global coverage needs

Desired Qualifications

  • Relevant certifications such as Microsoft Certified: Identity and Access Administrator, Microsoft Certified: Endpoint Administrator, Certified Information Systems Security Professional (CISSP), or DUO Security Administrator
  • Python (optional): Familiarity with Python for advanced IAM automation and integration tasks
  • Familiarity with SIEM platforms (e.g., Devo) for monitoring and auditing identity events and security logs

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce