
Staff Cloud Identity Platform Engineer
General Motors1 day ago
Remote, United States or Warren, MI, USAStaff+
Base Salary
$160k - $246k/yr
Responsibilities
- Design, configure, implement, and operate Microsoft Entra ID for workforce and application identity.
- Implement Microsoft Entra External ID for external users, partners, and application experiences, including registration, authentication, federation, user journeys, and authorization.
- Integrate applications using OAuth 2.0, OpenID Connect, SAML, and other identity standards.
- Support SSO, MFA, Conditional Access, RBAC, privileged access, identity governance, access reviews, service principals, managed identities, and identity lifecycle processes.
- Define and manage identity-platform SLIs, SLOs, error budgets, availability targets, federation health, provisioning reliability, and recovery performance.
- Apply SRE practices including observability, incident response, resilience engineering, capacity planning, dependency mapping, toil reduction, and post-incident reviews.
- Apply Azure infrastructure fundamentals covering subscriptions, resource organization, networking, Key Vault, monitoring, logging, backup, disaster recovery, and governance.
- Automate identity and cloud-platform activities using PowerShell, Azure CLI, Microsoft Graph, Bicep, Terraform, or comparable technologies.
- Contribute to infrastructure as code, continuous delivery, automated testing, policy as code, progressive delivery, change validation, and rollback practices.
- Design and validate high-availability, failover, recovery, and business-continuity patterns for identity services.
- Maintain runbooks, playbooks, service documentation, architecture records, and operational-readiness checklists.
- Partner with cybersecurity, infrastructure, application, architecture, privacy, compliance, and product teams on technical dependencies and operational risks.
Requirements
- Bachelor’s degree in computer science, information technology, cybersecurity, engineering, or a related field, or equivalent experience.
- At least five years of experience in identity and access management, cloud engineering, cybersecurity, infrastructure, software engineering, SRE, or a related technical discipline.
- Hands-on experience with Microsoft Entra ID and experience with Microsoft Entra External ID or a comparable external-user identity platform.
- Working knowledge of Azure infrastructure fundamentals, including networking, Key Vault, monitoring, logging, resiliency, and governance.
- Experience translating security, reliability, and application requirements into identity architectures, configurations, integrations, or engineering solutions.
- Experience supporting production services through monitoring, alerting, troubleshooting, incident response, change management, root-cause analysis, and reliability practices.
- Understanding of SRE concepts including SLIs, SLOs, error budgets, incident management, post-incident reviews, automation, and toil reduction.
- Strong understanding of identity security, least privilege, separation of duties, zero-trust concepts, and secure integration patterns.
- Experience with scripting, automation, APIs, infrastructure as code, or policy as code.
- Ability to assess operational risk, prioritize reliability improvements, make sound technical decisions during incidents, and communicate with technical and non-technical stakeholders.
- Preferred experience with AWS, Google Cloud Platform, AWS IAM, AWS Organizations, AWS KMS, Amazon Cognito, Google Cloud IAM, Google Cloud Identity, or Google Cloud KMS.
- Preferred experience with identity governance, entitlement management, privileged identity management, access reviews, joiner-mover-leaver processes, customer identity, application modernization, Microsoft Graph, observability, resiliency testing, disaster recovery, capacity planning, or performance engineering.
- Microsoft certifications such as Identity and Access Administrator Associate, Azure Administrator Associate, or Cybersecurity Architect Expert are preferred.
- Experience with large, complex, or highly regulated enterprise identity platforms and cross-functional collaboration is preferred.
Benefits
- Remote role; the selected candidate may be based anywhere in the country of work and is not expected to report to a GM worksite unless directed by their manager.
- Medical, dental, vision, Health Savings Account, Flexible Spending Accounts, retirement savings plan, sickness and accident benefits, life insurance, paid vacation and holidays, tuition assistance, employee assistance program, and GM vehicle discounts.
- Relocation benefits are available for candidates who qualify under company policy.
- Bonus potential is available through an incentive pay program based on company, job-level, and individual performance.
About General Motors
General Motors designs, manufactures, and sells cars, trucks, and electric vehicles for consumers and commercial fleets under brands including Chevrolet, GMC, Cadillac, and Buick. A public company on the NYSE headquartered in Detroit and founded in 1908, it operates globally and is developing EVs on its Ultium battery platform. Revenue comes from vehicle and parts sales, connected services such as OnStar, and financing through GM Financial.