About the Role
The Senior Authentication Services Engineer is a skilled technical contributor within the Identity & Access Management organization, responsible for the engineering, implementation, and operational support of enterprise authentication platforms across a complex global environment. This hands-on role involves implementing authentication solutions, supporting integrations, and contributing to the evolution of authentication services aligned with the Zero Trust security strategy.
Responsibilities
- Engineer, configure, and maintain Microsoft Entra ID, Active Directory, and federated identity services.
- Implement and support SSO integrations (SAML, OIDC, OAuth 2.0) across SaaS, on-prem, and hybrid application portfolios.
- Configure and manage MFA policies, authentication method settings, and phishing-resistant credential rollouts (FIDO2, Windows Hello for Business, certificate-based auth).
- Develop, test, and maintain Conditional Access policies in alignment with security requirements.
- Contribute to authentication standards, patterns, and reference architectures.
- Participate in proof-of-concept efforts for emerging authentication technologies.
- Maintain and update technical documentation including runbooks, configuration records, and architecture diagrams.
- Support alignment of authentication controls with Zero Trust principles and enterprise security policies.
- Provide technical evidence, control narratives, and remediation support for audit and compliance activities.
- Identify and remediate gaps in authentication posture through engineering solutions.
- Monitor authentication platform health and respond to security incidents within the authentication domain.
- Support incident response and troubleshoot complex authentication issues as a technical escalation resource.
- Collaborate with application teams, infrastructure engineering, and security operations to deliver IAM solutions.
- Contribute to knowledge transfer, documentation, and team skill development.
- Participate in on-call rotation for authentication platform support.
- Comply with corporate policies, procedures, and security standards.
- Contribute to a strong Environmental Health and Safety (EHS) culture by following safety policies, identifying hazards, and engaging in continuous improvement.
Requirements
- High School Diploma and 8 years of experience in Information Technology, Computer Science, IAM Engineering, or Information Security in a private, public, government, or military environment.
- OR Bachelor's degree or higher and Six (6) years of experience in Information Technology, Computer Science, IAM Engineering, or Information Security, in a private, public, government, or military environment.
- Must be legally authorized to work in country of employment without sponsorship for employment visa status.
Skills
- Microsoft Entra ID (Conditional Access, PIM, application registrations, hybrid identity)
- Active Directory (domain architecture, Group Policy, trusts, Kerberos, NTLM, AD security hardening)
- MFA implementation (phishing-resistant methods like FIDO2, WHfB)
- Federation protocols (SAML 2.0, OIDC, OAuth 2.0)
- SSO integration support
- PowerShell scripting
- Microsoft Graph API
- Identity security tooling (e.g., Microsoft Defender for Identity, Entra ID Protection, SIEM integrations)
- Windows Hello for Business deployment planning
- FIDO2/YubiKey rollouts
- PAM platforms (e.g., CyberArk)
- IGA platforms and lifecycle event integration
- Cloud Identity (AWS IAM, Azure AD B2B/B2C, multi-cloud identity federation)
- SC-300, AZ-500, or equivalent Microsoft identity certifications (preferred)
- Experience working in large enterprise environments with complex hybrid identity architectures
Location
- Maplewood, MN (On-site)
- Austin, TX (On-site)
Work Type
- On-site (at least 4 days per week)
- Full-time
Experience Level
- Senior
Education Level
- High School Diploma
- Bachelor's degree
Salary/Compensations
- $145,676 - $178,049
Benefits
- Medical, Dental & Vision
- Health Savings Accounts
- Health Care & Dependent Care Flexible Spending Accounts
- Disability Benefits
- Life Insurance
- Voluntary Benefits
- Paid Absences
- Retirement Benefits
About the Company
- 3M is a place where you can collaborate with other curious, creative 3Mers.
- Learn more about 3M’s creative solutions to the world’s problems at www.3M.com or on Instagram, Facebook, and LinkedIn @3M.
Equal Opportunity
- 3M does not discriminate in hiring or employment on the basis of race, color, sex, national origin, religion, age, disability, veteran status, or any other characteristic protected by applicable law.
