AD, Azure AD and PKI Architect
Job Summary
Your work days are brighter here.
Were obsessed with making hard work pay off for our people our customers and the world around us. As a Fortune 500 company and a leading AI platform for managing people money and agents were shaping the future of work so teams can reach their potential and focus on what matters most. The minute you join youll feel it. Not just in the products we build but in how we show up for each other. Our culture is rooted in integrity empathy and shared enthusiasm. Were in this together tackling big challenges with bold ideas and genuine care. We look for curious minds and courageous collaborators who bring sun-drenched optimism and drive. Whether youre building smarter solutions supporting customers or creating a space where everyone belongs youll do meaningful work with Workmates whove got your return well give you the trust to take risks the tools to grow the skills to develop and the support of a company invested in you for the long haul. So if you want to inspire a brighter work day for everyone including yourself youve found a match in Workday and we hope to be a match for you too.
About the Team
The Identity and Access management team manages the identity suite including Okta Delinea AD Entra ID and KeyFactor. Team manages employees customers and partners identity in IAM system.About the Role
The ideal candidate brings deep hands-on expertise in Windows Active Directory Entra ID hybrid identity authentication and authorization protocols certificate lifecycle management and identity-related incident resolution. They will partner with infrastructure security application endpoint and service-management teams to deliver resilient scalable identity services.
Key Responsibilities
Active Directory and Hybrid Identity Engineering
- Design deploy configure and maintain enterprise Active Directory Domain Services including forests domains sites organizational units trusts DNS integration Group Policy replication and domain controller lifecycle management.
- Engineer and support hybrid identity integration between on-premises AD and Microsoft Entra ID including Microsoft Entra Connect Sync or Cloud Sync password hash synchronization pass-through authentication federation where applicable and seamless single sign-on.
- Develop and maintain logical AD designs delegation models administrative tiering privileged access controls naming standards and lifecycle processes.
- Monitor and troubleshoot AD replication DNS authentication domain controller health Group Policy processing directory synchronization and identity-related service degradation.
- Plan and execute upgrades migrations consolidations domain controller replacements disaster-recovery testing and capacity improvements with minimal business disruption.
- Implement secure configuration baselines and hardening controls aligned to organizational standards and recognized security practices.
- Administer and engineer Microsoft Entra ID capabilities including users groups administrative roles enterprise applications app registrations service principals managed identities and directory settings.
- Design and operate identity access patterns for cloud and hybrid applications using SSO SAML OAuth 2.0 OpenID Connect SCIM provisioning and modern authentication.
- Implement and maintain Conditional Access policies multifactor authentication passwordless authentication authentication methods self-service password reset Identity Protection and risk-based access controls.
- Support privileged identity management processes role activation access reviews entitlement management and least-privilege access models.
- Partner with application owners to onboard applications to Entra ID resolve authentication and provisioning issues and improve the security posture of enterprise applications.
- Manage directory synchronization and identity lifecycle workflows including joiner mover leaver group management and access-provisioning integrations.
- Evaluate and implement relevant Microsoft Entra capabilities to enhance identity security governance and operational efficiency.
- Design deploy administer and support enterprise PKI services including Microsoft Active Directory Certificate Services (AD CS) certification authorities certificate templates enrollment policies CRL and AIA distribution points OCSP and key archival/recovery where required.
- Manage the complete certificate lifecycle for internal and public certificates: request issuance renewal revocation discovery inventory monitoring and retirement.
- Engineer certificate-based authentication and encryption solutions for users devices servers applications network infrastructure and services.
- Configure and support auto-enrollment certificate template permissions certificate policies enrollment agents and secure key-management practices.
- Maintain root and subordinate CA hierarchy offline root CA procedures CA backup and recovery processes HSM integrations where applicable and documented key-ceremony controls.
- Resolve certificate-chain trust revocation TLS/SSL smart-card device application and network authentication issues.
- Establish proactive certificate-expiry monitoring and automation to reduce service interruption risk.
- Identify identity and PKI risks lead remediation activities and support security audits vulnerability management compliance assessments and incident investigations.
- Analyze identity authentication directory and certificate logs to investigate incidents and provide root-cause analysis and corrective actions.
- Build and maintain automation using PowerShell Microsoft Graph API REST APIs and other appropriate tooling for administration reporting provisioning compliance checks and operational tasks.
- Develop operational dashboards health checks alerting and reporting for AD Entra ID synchronization services authentication and certificate infrastructure.
- Produce and maintain high-quality architecture diagrams technical standards runbooks knowledge articles implementation plans and recovery procedures.
- Participate in on-call support major incident response change management problem management and post-incident reviews as required.
- Collaborate with cybersecurity cloud engineering endpoint engineering network application and service-management teams to deliver integrated solutions.
About You
- Active Directory (AD DS): Multi-forest/multi-domain topologies Group Policy Architecture Trust relationships Sites & Services Kerberos/NTLM authentication flows and AD security hardening (Tiered Administration model).
- Microsoft Entra ID (Azure AD): Advanced Conditional Access Entra Connect/Cloud Sync Entra ID Protection PIM Workload Identities B2B/B2C and Microsoft Graph.
- Keyfactor Ecosystem: Deep hands-on experience with Keyfactor Command Orchestrators Certificate Managers and Keyfactor API integration.
- PKI & Cryptography: Deep understanding of Public Key Infrastructure principles X.509 certificates CRL/OCSP validation CA hierarchy design SSH key governance and HSM management.
- Automation & Scripting: Expert level in PowerShell Python or Bash alongside RESTful API integration for identity and PKI orchestration.
- Protocol Mastery: Deep knowledge of SAML OAuth OIDC Kerberos LDAP SCEP EST ACME and TLS/SSL.
- Experience: 10 years in Enterprise IAM/Infrastructure Engineering with at least 5 years in a dedicated Lead or Solution Architect capacity.
- Communication: Ability to articulate complex cryptographic and identity concepts to C-level executives security teams and application developers.
- Strategic Problem Solving: Proven track record of executing large-scale PKI transitions and AD/Entra ID modernizations in complex global environments.
Keyfactor Certifications: Keyfactor Certified Professional / Engineer.
Microsoft Certifications:
Microsoft Certified: Identity and Access Administrator Associate (SC-300).
Microsoft Certified: Cybersecurity Architect Expert (SC-100).
Azure Solutions Architect Expert (AZ-305).
Industry Security Certifications: CISSP CISM or Certified PKI Professional (CPKIP).
Our Approach to Flexible Work
With Flex Work were combining the best of both worlds: in-person time and remote. Our approach enables our teams to deepen connections maintain a strong community and do their best work. We know that flexibility can take shape in many ways so rather than a number of required days in-office each week we simply spend at least half (50%) of our time each quarter in the office or in the field with our customers prospects and partners (depending on role). This means youll have the freedom to create a flexible schedule that caters to your business team and personal needs while being intentional to make the most of time spent together. Those in our remote home office roles also have the opportunity to come together in our offices for important moments that matter.
Workday is committed to providing reasonable accommodations for qualified individuals during our application process in order to perform one or more essential functions of their job as well as regarding the use of AI tools for employment decision-making to any degree. Please see below for more details including how to request an accommodation as a qualified veteran due to a disability or for religious reasons or as otherwise provided under applicable law.
Workday prohibits taking adverse action against any candidate or employee for reporting a possible violation of this policy requesting one or more work accommodations exercising a privacy right or cooperating in an investigation in accordance with applicable law. Any employee who retaliates against a candidate or employee for doing so may be subject to disciplinary action up to and including termination of employment to the fullest extent allowable under applicable law.
If you require a reasonable accommodation you may email as far in advance as possible.
Are you being referred to one of our roles If so ask your connection at Workday about our Employee Referral process!
At Workday we value our candidates privacy and data security. Workday will never ask candidates to apply to jobs through websites that are not Workday Careers.
Please be aware of sites that may ask for you to input your data in connection with a job posting that appears to be from Workday but is not.
In addition Workday will never ask candidates to pay a recruiting fee or pay for consulting or coaching services in order to apply for a job at Workday.
Required Experience:
Staff IC