Staff Identity Engineer (Radiant One)
- Full-time
- Business Segment: Operations & Technology
- Compensation: USD 125000 - USD 155000 - yearly
Company Description
NBCUniversal is one of the world's leading media and entertainment companies. We create world-class content, which we distribute across our portfolio of film, television, and streaming, and bring to life through our global theme park destinations, consumer products, and experiences. We own and operate leading entertainment and news brands, including NBC, NBC News, NBC Sports, Telemundo, NBC Local Stations, Bravo, and Peacock, our premium ad-supported streaming service. We produce and distribute premier filmed entertainment and programming through our powerhouse film and television studios, including Universal Pictures, DreamWorks Animation, and Focus Features, and the four global television studios under the Universal Studio Group banner, and operate industry-leading theme parks and experiences around the world through Universal Destinations & Experiences, including Universal Orlando Resort, home to Universal Epic Universe, and Universal Studios Hollywood. NBCUniversal is a subsidiary of Comcast Corporation. Visit www.nbcuniversal.com for more information.
Our impact is rooted in improving the communities where our employees, customers, and audiences live and work. We have a rich tradition of giving back and ensuring our employees have the opportunity to serve their communities. We champion an inclusive culture and strive to attract and develop a talented workforce to create and deliver a wide range of content reflecting our world.
Job Description
Join the NBCUniversal Identity and Access Management team as a Staff Engineer focused on Identity Provisioning and Directory Services. This role owns the architecture, design, and evolution of our directory virtualization and provisioning capabilities that underpin identity correlation, authentication, and provisioning across NBCU's enterprise workforce. This is a hands-on role: you will design solutions, provide input to technical direction, mentor other engineers, and partner across IAM, security architecture, and application teams to solve complex, large-scale directory and provisioning challenges.
Responsibilities
- Design, deploy, and tune Identity Fabric environments, including replication topology, ACIs, high-availability configuration, and performance optimization at enterprise scale
- Identity provisioning workflows spanning provisioning, and custom connector development, extending beyond out-of-box configuration to build and debug bespoke integrations
- Lead directory consolidation, migration, and hybrid identity initiatives (e.g., multi-forest AD, Azure AD/Entra integration) where Radiant Logic serves as an abstraction and correlation layer
- Serve as a technical escalation point for complex production issues involving directory replication, provisioning failures, and identity correlation conflicts, driving root cause analysis and durable fixes
- Partner with IAM governance (SailPoint), security architecture, and application teams to align directory and provisioning capabilities with broader identity strategy
- Set technical direction and best practices for directory and provisioning engineering; mentor senior and mid-level engineers on the team
- Build automation and tooling (Python/PowerShell) to reduce manual operational overhead and improve reliability of provisioning and directory services
- Document architecture decisions, design tradeoffs, and operational runbooks for supportability across the team
- Evaluate and influence roadmap decisions for the directory and provisioning technology stack
Qualifications
Basic Requirements
- Bachelor's degree in Computer Science, Information Security, or related field, or equivalent work experience
- 8+ years of hands-on experience in enterprise Identity and Access Management, with a concentration in identity provisioning and directory services
- Hands-on production experience with Radiant Logic RadiantOne, including virtual directory design and identity correlation/aggregation
- Hands-on production experience with Ping Directory (or PingDirectoryProxy), including replication and performance tuning
- Deep working knowledge of LDAP/LDAPS fundamentals: schema design, referrals, and replication conflict resolution
- Experience designing and building provisioning workflows and connectors (SCIM, JIT, custom connector development)
- Scripting experience in JavaScript, Python and PowerShell for automation, tooling, and provisioning
- Demonstrated ability to make and articulate architectural tradeoffs, and to set technical direction for other engineers
- Ability to work effectively in a remote-first team environment
Desired Characteristics
- Experience with SailPoint IdentityIQ or other IGA platforms, and collaborating with governance teams
- Experience with hybrid identity architectures (Azure AD/Entra ID) and multi-forest Active Directory environments
- Exposure to broader security architecture concepts: PAM boundaries, service account lifecycle, and privileged directory access
- Experience leading directory consolidation or large-scale migration projects
- Prior experience mentoring engineers or informally setting technical direction across a team
Additional Requirements:
Fully Remote: This position has been designated as fully remote, meaning that the position is expected to contribute from a non-NBCUniversal worksite, most commonly an employee’s residence.
This position is eligible for company sponsored benefits, including medical, dental and vision insurance, 401(k), paid leave, tuition reimbursement, and a variety of other discounts and perks. Learn more about the benefits offered by NBCUniversal by visiting the Benefits page of the Careers website. Salary range: $125,000 - $155,000 (bonus eligible)
We are accepting applications for this position on an ongoing basis.
Additional Information
As part of our selection process, external candidates may be required to attend an in-person interview with an NBCUniversal employee at one of our locations prior to a hiring decision. NBCUniversal's policy is to provide equal employment opportunities to all applicants and employees without regard to race, color, religion, creed, gender, gender identity or expression, age, national origin or ancestry, citizenship, disability, sexual orientation, marital status, pregnancy, veteran status, membership in the uniformed services, genetic information, or any other basis protected by applicable law.
If you are a qualified individual with a disability or a disabled veteran, you have the right to request a reasonable accommodation if you are unable or limited in your ability to use or access nbcunicareers.com as a result of your disability. You can request reasonable accommodations by emailing [email protected].
For LA County and City Residents Only: NBCUniversal will consider for employment qualified applicants with criminal histories, or arrest or conviction records, in a manner consistent with relevant legal requirements, including the City of Los Angeles' Fair Chance Initiative For Hiring Ordinance, the Los Angeles County Fair Chance Ordinance for Employers, and the California Fair Chance Act, where applicable.
By clicking the link above or any third-party link within this posting, you are leaving this site and going to a third-party website where the third-party website's terms and privacy policy apply