AWS Identity Engineer

Telework - Remote, United StatesRemoteNormalmid
CybersecurityIdentity Engineer
2 views0 saves0 applied

Quick Summary

Overview

The AWS Identity Engineer provides technical leadership for a large-scale identity and access management migration across an enterprise cloud environment.

Technical Tools
CybersecurityIdentity Engineer

The AWS Identity Engineer provides technical leadership for a large-scale identity and access management migration across an enterprise cloud environment. The role will standardize identity services across AWS accounts, consolidate legacy identity providers into a unified enterprise identity platform, and strengthen secure, consistent access for users, applications, and service accounts.

This hands-on engineer leads the planning, implementation, validation, and cutover activities required to migrate cloud accounts, Active Directory domains, Windows and Linux workloads, AWS WorkSpaces, groups, roles, and service accounts with minimal business disruption. The position partners closely with cloud operations, infrastructure, security, and stakeholder teams to translate complex identity requirements into executable migration plans and sustainable operational standards.

Responsibilities

~1 min read
  • →Lead the technical execution of an enterprise AWS identity standardization initiative, including migration of AWS account console access to a unified identity provider and domain model.
  • →Design and execute the consolidation of multiple legacy identity providers into a single enterprise identity platform, ensuring secure and reliable user authentication and access continuity.
  • →Plan and manage Active Directory and domain migration activities for Windows and Linux EC2 instances, including identity-provider mapping, domain integration, and access validation.
  • →Map, migrate, and validate users, groups, roles, permissions, and service accounts across approximately 20 cloud accounts while preserving appropriate least-privilege access controls.
  • →Oversee AWS WorkSpaces rebuild and migration activities in coordination with the WorkSpaces support team, ensuring alignment to the target identity provider and operational requirements.
  • →Configure, deploy, and maintain Group Policy Objects for Windows WorkSpaces and EC2 instances in partnership with infrastructure and operations teams.
  • →Develop and execute detailed migration runbooks, cutover plans, rollback procedures, validation criteria, and post-cutover support processes to minimize risk and prevent business disruption.
  • →Provide technical leadership, stakeholder communication, and cross-functional coordination throughout migration planning, implementation, testing, issue resolution, and transition to operations.

Requirements

~2 min read
  • Bachelor’s degree in Computer Science, Information Technology, Engineering, Cybersecurity, or a related field; equivalent relevant experience may be considered.
  • At least 12 years of progressive IT experience, including 5 or more years of cloud engineering experience and at least 3 years of hands-on identity and access management experience supporting enterprise-scale environments.
  • Professional-level cloud certification in AWS, Microsoft Azure, Oracle Cloud Infrastructure, or Google Cloud Platform.
  • Expert-level experience with AWS Identity and Access Management, cloud account access controls, identity federation, security groups, and cloud-native identity services.
  • Deep technical knowledge of Microsoft Active Directory, LDAP, domain consolidation and migration, Group Policy Object administration, and identity integration across cloud, server, and workstation environments.
  • Demonstrated experience planning and executing complex identity, domain, user, group, role, and service-account migrations with comprehensive validation testing and cutover management.
  • At least 5 years of experience administering or troubleshooting Windows and Linux operating systems in an engineering, support, or systems administration capacity.
  • U.S. citizenship is required.
  • AWS architect-level certification or advanced certification in identity, security, cloud architecture, or cloud operations.
  • Experience integrating Linux environments, including Red Hat Enterprise Linux and Ubuntu, into enterprise Active Directory environments.
  • Experience supporting cloud or application migrations in a regulated federal IT environment, including security reviews, authorization activities, or NIST 800-53 or NIST 800-171 security control baselines.
  • Familiarity with enterprise boundary concepts, network segmentation, security scanning tools, compliance monitoring, and infrastructure security remediation.

It is the policy of ASM that an individual's race, color, religion, sex, disability, age, sexual orientation or national origin are not and will not be considered in any personnel or management decisions. We affirm our commitment to these fundamental policies.

 

All recruiting, hiring, training, and promoting for all job classifications is done without regard to race, color, religion, sex, disability, or age. All decisions on employment are made to abide by the principle of equal employment.

 

Physical Requirements

The physical requirements described in "Knowledge, Skills and Abilities" above are representative of those which must be met by an employee to successfully perform the primary functions of this job. (For example, "light office duties' or "lifting up to 50 pounds" or "some travel" required.) Reasonable accommodations may be made to enable individuals with qualifying disabilities, who are otherwise qualified, to perform the primary functions.

 

What We Offer

~1 min read

Compensation ranges for ASM Research positions vary depending on multiple factors; including but not limited to, location, skill set, level of education, certifications, client requirements, contract-specific affordability, government clearance and investigation level, and years of experience. The compensation displayed for this role is a general guideline based on these factors and is unique to each role. Monetary compensation is one component of ASM's overall compensation and benefits package for employees.

 

The preceding job description has been designed to indicate the general nature and level of work performed by employees within this classification. It is not designed to contain or be interpreted as a comprehensive inventory of all duties, responsibilities and qualifications required of employees assigned to this job.

Location & Eligibility

Where is the job
Worldwide
Fully remote, anywhere in the world
Who can apply
Same as job location

Listing Details

Posted
September 30, 2026
First seen
September 30, 2026
Last seen
October 5, 2026

Posting Health

Days active
4
Repost count
0
Trust Level
65%
Scored at
October 5, 2026

Signal breakdown

freshnesssource trustcontent trustemployer trust
Newsletter

Stay ahead of the market

Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.

A
B
C
D
Join 12,000+ marketers

No spam. Unsubscribe at any time.

AWS Identity Engineer