
Principal Identity Engineer
Hard Rock Digital, LLC2 months ago
Remote, United StatesStaff+
Responsibilities
- Own identity security architecture, standards, authentication methods, and roadmap for Microsoft Entra ID.
- Design and refine Conditional Access policies and advance phishing-resistant, passwordless authentication using passkeys, certificates, and FIDO2.
- Own federation and single sign-on across the SaaS estate using SAML, OIDC, OAuth 2.0, and SCIM.
- Design and maintain privileged access controls with Microsoft Entra PIM, including separate administrator identities, just-in-time elevation, approval workflows, and break-glass safeguards.
- Automate joiner-mover-leaver processes and operate access reviews, entitlement governance, and audit evidence in partnership with GRC.
- Govern service principals, managed identities, workload and federated credentials across AWS, Azure, and GCP.
- Partner on secrets governance, service-to-service authentication, Cloudflare Access, identity signals for detection and response, and customer identity architecture.
- Serve as the identity authority for the Zero Trust program and set the identity roadmap with the CISO.
- Act as the escalation point for identity-related incidents.
Requirements
- 10+ years of experience in identity and access management, security engineering, or a closely related field, or equivalent practical experience.
- Deep hands-on expertise with a modern enterprise identity platform, including Conditional Access, PIM/PAM, authentication methods, and identity governance.
- Strong command of SAML, OIDC, OAuth 2.0, SCIM, and modern multifactor authentication.
- Experience automating identity lifecycle processes and integrating identity across large SaaS and multi-cloud environments.
- Scripting and automation experience with PowerShell, Microsoft Graph API, and Python, plus comfort with Infrastructure as Code.
- Demonstrated experience designing least-privilege and just-in-time access controls in production.
- Excellent written and verbal communication skills across engineering, risk, security, IT, and leadership audiences.
- Fluency with AI and hands-on experience applying AI to security or engineering work.
- Preferred qualifications include regulated-industry experience, CIAM or KYC exposure, passwordless MFA rollouts, familiarity with Identity Threat Detection and Response, and relevant certifications such as Microsoft Identity & Access Administrator or CISSP.
Benefits
- Competitive pay and benefits.
- Flexible vacation allowance.
- Hybrid or remote working environment.
- Startup culture backed by a secure, global brand.
- Diverse and inclusive equal-opportunity workplace.
Tech Stack
Categories
About Hard Rock Digital, LLC
Hard Rock Digital builds and operates the Hard Rock brand’s online sportsbook, real-money casino, and social casino products for U.S. customers, including the Hard Rock Bet app. The company develops an in-house odds and pricing platform and other backend systems that power live wagering. Founded in 2020 and headquartered in Hollywood, Florida, it serves regulated U.S. markets and is aligned with Hard Rock International and the Seminole Tribe of Florida.