Senior Identity Infrastructure Engineer
We are seeking a highly skilled Authentication & Identity Infrastructure Engineer to join an international Engineering Services division operating across key European financial hubs (including Krakow, Paris, and Brussels). In this role, you will be part of a specialized team dedicated to designing, securing, and maintaining mission-critical identity and access management (IAM) platforms. You will ensure maximum system availability, resilience, and security across a large-scale, complex enterprise environment.
Daily tasks
- Identity & Directory Management: Oversee, configure, and maintain multi-forest and multi-domain Active Directory (AD) environments, LDAP services, and Microsoft Azure Entra ID (global tenant administration).
- Federation & Single Sign-On (SSO): Manage Active Directory Federation Services (ADFS), handling claims, metadata, and token-based authentication to deliver seamless SSO capabilities.
- Multi-Factor Authentication (MFA) & Security: Support and enhance MFA solutions, including Windows Hello for Business and RSA SecurID (RSA Authentication Manager).
- Architecture & Governance: Develop and review technical architecture designs, establish security baselines for authentication systems, and maintain comprehensive technical documentation.
- Automation & Engineering: Leverage PowerShell scripting to automate routine administrative workflows, operational checks, and configuration deployments.
- Compliance & Audit Readiness: Participate in security assessments, vulnerability remediations, and internal/external IT audits to meet strict financial sector compliance standards.
Requirements
Enterprise Experience: Proven track record of designing, supporting, and troubleshooting complex identity and authentication infrastructures within large-scale enterprise environments. Core Active Directory: Deep expertise in Active Directory, forest trust architectures, and advanced troubleshooting. Challenging Authentication Protocols: In-depth understanding of Kerberos, NTLM, SAML, OAuth, and PKI/certificate-based authentication. Cloud & Hybrid Identity: Hands-on experience configuring and managing Microsoft Azure Entra ID (formerly Azure AD). Automation: Advanced PowerShell scripting skills for infrastructure automation and management. General Infrastructure Knowledge: Solid understanding of core IT infrastructure components, including Windows Server OS, virtualization, enterprise networking, and storage systems. Desirable / Nice-to-Have Experience managing RSA Authentication Manager / RSA SecurID ecosystems. Familiarity with ITIL frameworks (Incident, Problem, and Change Management via ServiceNow) and Agile delivery practices. Soft Skills & Operational Mindset Strong analytical and root-cause troubleshooting skills under pressure. Ability to translate complex infrastructure issues into clear, concise summaries for stakeholders. Collaborative team player with excellent communication skills in English.
Must have: Active Directory, Kerberos, SAML, OAuth, PKI, Microsoft Azure, Azure AD, PowerShell, Windows Server, Virtualization, Networking
Nice to have: Storage, ITIL