Staff Security Operations Engineer - Active Directory (AD) & Azure AD (Entra ID)

  • Full-time
  • Job Type (exemption status): Exempt position - Please see related compensation & benefits details below
  • Business Function: Security Operations
  • Work Location: Penang SDSM Office--LOC_SNDK_Seberang Perai Office

Company Description

Sandisk understands how people and businesses consume data and we relentlessly innovate to deliver solutions that enable today’s needs and tomorrow’s next big ideas. With a rich history of groundbreaking innovations in Flash and advanced memory technologies, our solutions have become the beating heart of the digital world we’re living in and that we have the power to shape.

Sandisk meets people and businesses at the intersection of their aspirations and the moment, enabling them to keep moving and pushing possibility forward. We do this through the balance of our powerhouse manufacturing capabilities and our industry-leading portfolio of products that are recognized globally for innovation, performance and quality.

Sandisk has two facilities recognized by the World Economic Forum as part of the Global Lighthouse Network for advanced 4IR innovations. These facilities were also recognized as Sustainability Lighthouses for breakthroughs in efficient operations. With our global reach, we ensure the global supply chain has access to the Flash memory it needs to keep our world moving forward.

Job Description

This role is primarily focused on the administration, engineering, and operational ownership of the organization’s directory services - Active Directory (AD) and Azure AD (Microsoft Entra ID) - including hybrid identity integration. The Staff Security Operations Engineer serves as the day-to-day technical lead for AD and Entra ID, ensuring their availability, reliability, and security across the organization.

Supporting identity and access management technologies - IAM process automation, incident response and troubleshooting, compliance reporting, and multifactor authentication - make up the secondary scope of the role. This position works cross time zones to support Asia coverage needs.

ESSENTIAL DUTIES AND RESPONSIBILITIES

Active Directory (AD) and Azure AD (Entra ID) (Primary Focus)

  • Serve as the primary administrator and operational owner of the organization’s Active Directory and Microsoft Entra ID directory services.
  • Manage user accounts, security and distribution groups, Group Policy (GPO), and organizational units across the Active Directory environment.
  • Design, implement, and maintain hybrid identity using Azure AD Connect - synchronization between on-premises AD and Entra ID, seamless single sign-on, and password hash sync / pass-through authentication.
  • Administer Microsoft Entra ID, including RBAC, Privileged Identity Management (PIM), Conditional Access, application registrations / enterprise applications, and identity governance.
  • Provide day-to-day operational support, including monitoring directory health and troubleshooting replication, DNS, authentication, and access provisioning issues.
  • Act as the technical escalation point for directory-related incidents, working with vendors and internal teams to identify root causes and implement durable solutions.
  • Maintain documentation, runbooks, and operational procedures for the Active Directory and Entra ID environment.

Multifactor Authentication - Supporting Scope

  • Support the integration of MFA with Active Directory and Entra ID (Duo MFA, Windows Hello for Business, and Conditional Access), enabling the organization’s passwordless and passkey authentication program.
  • Assist with troubleshooting and escalations where directory issues affect authentication and access.

IAM Process Automation

  • Automate directory lifecycle tasks and workflows - joiner / mover / leaver provisioning, group and access management, and reporting - using PowerShell and Microsoft Graph to increase efficiency and reduce manual errors.
  • Continuously evaluate and improve identity and directory processes to enhance security and the user experience.

Incident Response and Troubleshooting

  • Act as the technical escalation point for identity-related incidents involving Active Directory, Entra ID, and hybrid identity synchronization.
  • Investigate, troubleshoot, and resolve directory and access issues, working closely with other teams to identify root causes and implement solutions.

Compliance and Reporting

  • Ensure directory and IAM solutions meet compliance requirements such as SOX, etc.
  • Generate reports for auditing purposes - including access reviews and privileged access - and provide insights into the security posture of identity systems.

Collaboration and Documentation

  • Collaborate with security, IT, and compliance teams to define and implement identity governance frameworks.
  • Develop and maintain comprehensive documentation for all directory and IAM solutions, policies, and procedures.

Training and Knowledge Sharing

  • Provide training to end-users and technical staff on directory services and IAM best practices, focusing on Active Directory and Entra ID.
  • Stay up-to-date with industry trends and emerging technologies to continuously enhance the organization’s directory and IAM capabilities.

Professional Attributes

  • Leadership: Demonstrated ability to assist in leading cross-functional teams and manage technical resources, driving projects and solutions to successful completion.
  • Problem-Solving: Strong analytical and troubleshooting skills with a proactive approach to identifying and resolving issues within complex identity and directory environments.
  • Analytical Skills: Ability to analyze complex IAM issues and apply logical troubleshooting techniques to resolve identity-related problems.
  • Attention to Detail: High accuracy and attention to detail in managing identity policies, systems configurations, and security protocols.
  • Communication: Strong communication skills to collaborate with technical and non-technical stakeholders across the organization.
  • Team Player: Ability to work effectively as part of a cross-functional team, with a focus on supporting the broader IAM strategy.
  • Customer Focused: Demonstrated ability to deliver excellent service to internal and external stakeholders, focusing on user experience without compromising security.
  • Adaptability: Ability to quickly learn and adapt to new tools, technologies, and security practices in a dynamic IT environment.

Qualifications

Required:

  • Active Directory (AD) and Azure AD (Entra ID) (Primary):
    • Experience managing user accounts, group policies, and organizational units in Active Directory.
    • Hands-on experience administering Microsoft Entra ID, including RBAC, PIM, and Conditional Access.
    • Familiarity with hybrid identity environments using Azure AD and Azure AD Connect for synchronization between on-prem and cloud identities.
    • Ability to troubleshoot and resolve AD / Entra ID replication, DNS, authentication, and provisioning issues.
  • Multifactor Authentication (MFA):
    • Experience with the integration of MFA - Duo MFA and Windows Hello for Business - with Active Directory and Entra ID.
    • Ability to support and troubleshoot Conditional Access and authentication policies.
  • PowerShell Scripting:
    • Basic PowerShell scripting skills to automate tasks related to identity management, such as user provisioning, reporting, and troubleshooting.
  • SIEM and Auditing Tools:
    • Familiarity with security information and event management (SIEM) tools for monitoring identity-related logs and events.
    • Experience generating audit reports for compliance purposes.

Programming and Tools

  • Scripting and Programming Languages:
    • PowerShell: Proficiency in using PowerShell (and Microsoft Graph) to automate identity tasks, generate reports, and troubleshoot issues.
    • Python (optional): Familiarity with Python for advanced IAM automation and integration tasks.
  • IAM and Directory Tools:
    • Active Directory & Group Policy: Expertise in administering Active Directory, Group Policy, and organizational units.
    • Microsoft Entra ID: Expertise in administering Entra ID RBAC, PIM, Conditional Access, and identity governance.
    • Azure AD Connect: Experience with synchronization between on-prem AD and Entra ID for seamless hybrid identity management.
    • Duo MFA & Windows Hello for Business: Experience integrating and supporting MFA with Active Directory and Entra ID.
  • Monitoring and Logging:
    • Familiarity with SIEM platforms (e.g., Devo) for monitoring and auditing identity events and security logs.

Preferred:

  • Experience:
    • 6+ years of experience in IT or Information Security, with a focus on identity and access management.
    • 3+ years of direct, hands-on experience administering Active Directory and Microsoft Entra ID, including Azure AD Connect hybrid identity.
    • Experience working with Conditional Access, PIM, Duo MFA, and Windows Hello for Business.
  • Education:
    • BA or BS in Information Technology, Computer Science, Information Security, or a related field. Equivalent hands-on experience in IAM may be considered in lieu of a degree.
    • Relevant certifications such as Microsoft Certified: Identity and Access Administrator, Microsoft Certified: Windows Server Hybrid Administrator, or Certified Information Systems Security Professional (CISSP) are desirable.

Language

  • English proficiency in both speaking and writing.

Logistics

  • Primary work in a general and/or home office environment.
  • Willing to be 24 x 7 on call.
  • Willing to perform work functions cross time zones to support Asia coverage needs.

Additional Information

Sandisk thrives on the power and potential of diversity. As a global company, we believe the most effective way to embrace the diversity of our customers and communities is to mirror it from within. We believe the fusion of various perspectives results in the best outcomes for our employees, our company, our customers, and the world around us. We are committed to an inclusive environment where every individual can thrive through a sense of belonging, respect and contribution.

Sandisk is committed to offering opportunities to applicants with disabilities and ensuring all candidates can successfully navigate our careers website and our hiring process. Please contact us at [email protected] to advise us of your accommodation request. In your email, please include a description of the specific accommodation you are requesting as well as the job title and requisition number of the position for which you are applying.

NOTICE TO CANDIDATES: Sandisk has received reports of scams where a payment is requested on Sandisk’s behalf as a condition for receiving an offer of employment. Please be aware that Sandisk and its subsidiaries will never request payment as a condition for applying for a position or receiving an offer of employment. Should you encounter any such requests, please report it immediately to Sandisk Ethics Helpline or email [email protected].

By clicking the link above or any third-party link within this posting, you are leaving this site and going to a third-party website where the third-party website's terms and privacy policy apply

Privacy Notice