Logo for Sparkhound

Identity Engineer - Tier 2

Role overview

Qualifications

  • 3–5 years administering Active Directory in a production environment
  • Hands-on experience with hybrid identity, specifically Entra Connect synchronization
  • Working knowledge of Microsoft Entra ID administration
  • PowerShell proficiency for directory administration and reporting

Responsibilities

  • Provision and de-provision user and group accounts in on-premises Active Directory
  • Execute and maintain established Identity Lifecycle automation
  • Support multifactor authentication enrollment and troubleshoot authentication failures
  • Monitor and triage Entra Connect synchronization errors

Key facts

  • Remote from: Anywhere
  • Full time
  • Mid-level (2-5 years)
  • English

Hard skills

About the company

Sparkhound logo

Sparkhound

Sparkhound’s story is defined by our clients. For 23+ years, we’ve helped clients turn challenges into opportunities by redefining how companies use technology to solve business problems. We’ve assembled a top-quality team of analysts, developers, strategists, and technologists who thrive on creating value. Our clients’ goals and desired outcomes drive us to deliver impactful digital solutions. And, we take great pride in the success of our clients. Be a part of our story.

Company details

Company size201 - 500

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

Description

The Identity & Access Engineer performs day-to-day administration and support of client hybrid identity environments spanning on-premises Active Directory and Microsoft Entra ID. This role is accountable to the Director of Operations for account lifecycle accuracy, directory synchronization health, and identity-related incident response within defined authorization boundaries, and operates under the functional oversight of the client's designated identity function owner. 

Duties and Responsibilities

  • Provision and de-provision user and group accounts in on-premises Active Directory, applying correct OU placement per the client's existing structure
  • Execute and maintain established Identity Lifecycle (Joiner/Mover/Leaver) automation, validating that automated actions complete correctly and remediating exceptions
  • Perform password resets and account unlocks across on-premises AD and synchronized Entra ID identities
  • Support multifactor authentication enrollment and troubleshoot routine authentication failures for end users
  • Troubleshoot Group Policy application using existing approved policies, diagnosing precedence, scope, and replication issues without creating or modifying GPOs
  • Monitor and triage Entra Connect synchronization errors and sync health alerts, resolving routine issues and escalating configuration-level causes
  • Assign licenses and perform standard attribute updates within Entra ID
  • Respond to Severity 2 and 3 identity service disruptions including sync delays and login failures, and route suspected security incidents to the defined cybersecurity team per the incident response runbook
  • Request, use, and release just-in-time privileged access in accordance with client PAM procedures, maintaining accurate records of elevated activity
  • Recognize and halt on activities reserved for client authorization, including sync configuration and topology changes; GPO, OU, or schema modification; Conditional Access policy changes; elevated role assignments; PIM/PAM policy configuration; trust and federation changes; and tenant-level authentication method changes
  • Maintain accurate documentation and follow change management procedures without exception in client environments
Requirements
  • 3–5 years administering Active Directory in a production environment, including account lifecycle, OU and group management, and Group Policy troubleshooting
  • Hands-on experience with hybrid identity, specifically Entra Connect (or Azure AD Connect) synchronization, including sync error triage, attribute flow, and understanding of how on-premises changes propagate to the cloud
  • Working knowledge of Microsoft Entra ID administration, including licensing, attribute management, and authentication methods
  • Practical experience supporting multifactor authentication and Conditional Access from an end-user troubleshooting perspective
  • Familiarity with Privileged Identity Management and just-in-time access models, and demonstrated ability to work productively without standing administrative rights
  • Understanding of identity lifecycle automation and the ability to validate and remediate automated provisioning workflows
  • Ability to distinguish an identity service disruption from a potential identity compromise, and to escalate the latter immediately rather than troubleshoot it
  • Experience delivering support in a managed services or multi-client environment, including ticket queue discipline, SLA adherence, and change management
  • PowerShell proficiency for directory administration and reporting
  • Microsoft certifications such as SC-300 (Identity and Access Administrator) or equivalent demonstrated experience preferred

All Sparkhound employees are expected to handle client and company data with care, follow our information security policies, complete required security training, and report any suspected incidents or policy violations promptly. Employees are also responsible for maintaining accurate documentation and following change management procedures when working in client environments.

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

Related jobs

Other jobs at Sparkhound

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.