Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy, and consent to receive emails from Rise
Jobs / Job page
Principal IAM/AD Engineer image - Rise Careers
Job details

Principal IAM/AD Engineer

liETtVLaARqgmMEbYzHNNLIzUPcdfPrwhYtVK7Qa.png Fast Facts

MathWorks is seeking a Principal IAM/AD Engineer to join their Security Operations IAM team, responsible for managing and automating identity operations across on-premise Active Directory and Microsoft Entra ID within a hybrid work model.

liETtVLaARqgmMEbYzHNNLIzUPcdfPrwhYtVK7Qa.png Responsibilities: Key responsibilities include operating and maintaining on-premise Active Directory, implementing Entra ID capabilities, monitoring identity flows, and automating identity operations with PowerShell and APIs.

liETtVLaARqgmMEbYzHNNLIzUPcdfPrwhYtVK7Qa.png Skills: Required skills include extensive experience in enterprise Active Directory operations, proficiency in Microsoft Entra ID, and expertise in automation using PowerShell and APIs.

liETtVLaARqgmMEbYzHNNLIzUPcdfPrwhYtVK7Qa.png Qualifications: A bachelor's degree and 10 years of relevant work experience are required, with additional qualifications in security frameworks and automation tools preferred.

liETtVLaARqgmMEbYzHNNLIzUPcdfPrwhYtVK7Qa.png Location: This position is based in Natick, US, with a hybrid work model.

liETtVLaARqgmMEbYzHNNLIzUPcdfPrwhYtVK7Qa.png Compensation: Not provided by employer. Typical compensation ranges for this position are between $130,000 - $180,000.




Job Summary

<p>MathWorks has a hybrid work model that enables staff members to split their time between office and home. The hybrid model provides the advantage of having both in-person time with colleagues and flexible at-home life optimizations. Learn More: https://www.mathworks.com/company/jobs/resources/applying-and-interviewing.html#onboarding.</p>

Do you design secure, resilient Active Directory at scale and enjoy automating identity operations? Join our Security Operations IAM team responsible for enterprise identity foundations across on‑prem Active Directory and Microsoft Entra ID. We partner with Security Engineering, IT, and Compliance to deliver hardened directory services, modern authentication, ITDR capabilities and Zero Trust controls that enable the business. 

MathWorks nurtures growth, appreciates inclusivity, encourages initiative, values teamwork, shares success, and rewards excellence.

Responsibilities

  • Operate and maintain on‑premises Active Directory: domain controller health, patching, promotion/demotion, replication, sites/subnets, time services, SYSVOL/GPO health, and capacity monitoring. 
  • Implement and manage Entra ID capabilities: Conditional Access, Identity Protection risk policies, PIM, and app registrations/service principals. 
  • Monitor, troubleshoot, and optimize directory synchronization and identity lifecycle flows. 
  • Partner with our SOC to drive a successfulITDRprogram.Helpbuild and tune detections to identify threats such as DCSync, Golden/Silver Ticket, Kerberoasting, pass‑the‑hash/ticket, risky sign‑ins, and impossible travel. 
  • Harden AD and Entra ID: apply baselines, admin tiering, PAW usage, secure delegation, privileged workflow controls, regular access reviews, and identity threat hunting. 
  • Automate identity operations and ITDR tasks with PowerShell and APIs (Graph/Entra): alert enrichment, response runbooks, access certifications, reporting, and drift remediation. 
  • Lead complex troubleshooting and incident response for identity (Kerberos/NTLM, replication, DCSync/Golden/Silver Ticket detections, Conditional Access failures); drive root cause and preventive actions. 
  • Produce runbooks, standards, and change records; mentor team members and collaborate with stakeholders to align IAM operations with business needs. 

Qualifications

  • A bachelor's degree and 10 years of professional work experience (or equivalent experience) is required.

Additional Qualifications

A successful candidate for this role will have a combination of some or all of the following skills/experience:

  • 7+ years in enterprise Active Directory operations and hardening including DC lifecycle management, sites/services, replication, BCDR, and observability. 
  • Hands-on experience with Microsoft Entra ID: Conditional Access, MFA, Identity Protection, PIM, app registration and service principal governance. 
  • Experience operating Azure AD Connect or Cloud Sync in hybrid identity environments. 
  • Identity Governance and Administration experience for provisioning, role/entitlement models, and access certifications. 
  • Proficiency with PowerShell, Python and Microsoft Graph/Entra APIs for automation. 
  • Experience with privileged access models and administrative tiering. 
  • Ability to support after-hours maintenance and incident response as needed. 
  • SSO/Federation: SAML/OIDC/OAuth; SCIM provisioning to SaaS apps. 
  • AD security: trusts, LDAP/LDAPS, constrained delegation, GPO hardening. 
  • PKI and certificates: AD CS, CRL/OCSP, auto enrollment, renewal automation for workloads and service principals/certs. 
  • Backup/Recovery: authoritative restore, forest recovery planning and drills. 
  • IaC/automation: DSC, GPO as Code, Git workflows; CI/CD familiarity for scripts/policies. 
  • Compliance familiarity: CMMC, NIST CSF/800‑53/171, ISO 27001 
MathWorks Glassdoor Company Review
4.5 Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon
MathWorks DE&I Review
No rating Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon
CEO of MathWorks
MathWorks CEO photo
Jack Little
Approve of CEO

Average salary estimate

$155000 / YEARLY (est.)
min
max
$130000K
$180000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

Similar Jobs
Posted 12 hours ago

Onsite IT Support role in Cambridge, MA providing first- and second-level support, workstation setup, and ticket resolution for an international IT services firm.

Photo of the Rise User
Posted 12 hours ago

DYOPATH is hiring a SNOC Engineer II (Security) to lead incident detection and response while improving operational reliability across security, network, systems, and cloud in a remote capacity.

Photo of the Rise User
Saalex Hybrid No location specified
Posted 53 minutes ago

Saalex is hiring a Systems Engineer II to design, integrate, and test enterprise IT systems for Navy LVC environments in Tidewater, VA or San Diego, CA.

Posted 57 minutes ago

Provide white-glove technical support to senior leadership at RRS Group, ensuring secure, reliable devices and flawless meeting/AV experiences across office, remote, and travel settings.

Photo of the Rise User

Contribute to healthcare application delivery as an Associate Technical Analyst by converting business needs into clear technical requirements, supporting testing, defect management, and system improvements.

Photo of the Rise User
Posted 6 hours ago

Provide Tier 1 technical support across corporate, distribution, and retail channels for Abercrombie & Fitch, resolving incidents, fulfilling requests, and helping associates use supported systems and devices.

Photo of the Rise User
Posted 13 hours ago

Adoreal is hiring a hands-on Senior Manager of IT & Engineering to build the IT/security function, lead HIPAA compliance, and provide .NET technical leadership in a hybrid US-remote role with preference for candidates near Chicago, IL.

Photo of the Rise User
Posted 15 hours ago

Lead Elanco's SAP S/4HANA Settlement Management efforts by designing, implementing, and supporting Condition Contract and Settlement Management solutions that enable Pricing, Rebates, and Master Data capabilities across the business.

Photo of the Rise User
Posted 20 hours ago

Crypto.com's Security Team seeks a Security IT Support Engineer to own endpoint lifecycle, patching, access management, and vulnerability remediation while helping teams adopt AI safely.

Photo of the Rise User
Posted 7 hours ago

Crusoe is seeking a Senior Systems Engineer - IAM to lead Okta-based identity lifecycle, automation, and secure access integrations for its global technology infrastructure in San Francisco.

Photo of the Rise User
Saalex Hybrid No location specified
Posted 13 hours ago

Saalex seeks experienced Field Service Engineer II candidates to lead installation, sustainment, and troubleshooting of deployed IT and network systems in operational field environments.

Western Alliance Bank seeks a Principal Engineer II to architect and lead Infrastructure-as-Code and automation strategies for secure, compliant, enterprise-scale Azure environments.

Fortune Brands Hybrid 1 Horizon Way, Deerfield, ILLINOIS
Posted 1 hour ago

Lead and inspire a web technologies team at Fortune Brands to deliver enterprise e-commerce and digital experiences using modern web stacks and best practices.

Our goal is to change the world by accelerating the pace of discovery, innovation, development, and learning in engineering and science. We work to provide the ultimate computing environment for technical computation, visualization, design, simul...

9 jobs
MATCH
Calculating your matching score...
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, hybrid
DATE POSTED
March 29, 2026
Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!