Principal IAM/AD Engineer (36396-MMCC)

Natick, MA

Job Description

Summary

MathWorks has a hybrid work model that enables staff members to split their time between office and home. The hybrid model provides the advantage of having both in-person time with colleagues and flexible at-home life optimizations. Learn More: https://www.mathworks.com/company/jobs/resources/applying-and-interviewing.html#onboarding.

Do you design secure, resilient Active Directory at scale and enjoy automating identity operations? Join our Security Operations IAM team responsible for enterprise identity foundations across onprem Active Directory and Microsoft Entra ID. We partner with Security Engineering, IT, and Compliance to deliver hardened directory services, modern authentication, ITDR capabilities and Zero Trust controls that enable the business.

MathWorks nurtures growth, appreciates inclusivity, encourages initiative, values teamwork, shares success, and rewards excellence.


Responsibilities



  • Operate and maintain onpremises Active Directory: domain controller health, patching, promotion/demotion, replication, sites/subnets, time services, SYSVOL/GPO health, and capacity monitoring.








  • Implement and manage Entra ID capabilities: Conditional Access, Identity Protection risk policies, PIM, and app registrations/service principals.








  • Monitor, troubleshoot, and optimize directory synchronization and identity lifecycle flows.








  • Partner with our SOC to drive a successfulITDRprogram.Helpbuild and tune detections to identify threats such as DCSync, Golden/Silver Ticket, Kerberoasting, passthehash/ticket, risky signins, and impossible travel.








  • Harden AD and Entra ID: apply baselines, admin tiering, PAW usage, secure delegation, privileged workflow controls, regular access reviews, and identity threat hunting.








  • Automate identity operations and ITDR tasks with PowerShell and APIs (Graph/Entra): alert enrichment, response runbooks, access certifications, reporting, and drift remediation.








  • Lead complex troubleshooting and incident response for identity (Kerberos/NTLM, replication, DCSync/Golden/Silver Ticket detections, Conditional Access failures); drive root cause and preventive actions.








  • Produce runbooks, standards, and change records; mentor team members and collaborate with stakeholders to align IAM operations with business needs.





Qualifications

A successful candidate for this role will have a combination of some or all of the following skills/experience:



  • 7+ years in enterprise Active Directory operations and hardening including DC lifecycle management, sites/services, replication, BCDR, and observability.






  • Hands-on experience with Microsoft Entra ID: Conditional Access, MFA, Identity Protection, PIM, app registration and service principal governance.








  • Experience operating Azure AD Connect or Cloud Sync in hybrid identity environments.








  • Identity Governance and Administration experience for provisioning, role/entitlement models, and access certifications.








  • Proficiency with PowerShell, Python and Microsoft Graph/Entra APIs for automation.








  • Experience with privileged access models and administrative tiering.








  • Ability to support after-hours maintenance and incident response as needed.








  • SSO/Federation: SAML/OIDC/OAuth; SCIM provisioning to SaaS apps.








  • AD security: trusts, LDAP/LDAPS, constrained delegation, GPO hardening.








  • PKI and certificates: AD CS, CRL/OCSP, auto enrollment, renewal automation for workloads and service principals/certs.








  • Backup/Recovery: authoritative restore, forest recovery planning and drills.








  • IaC/automation: DSC, GPO as Code, Git workflows; CI/CD familiarity for scripts/policies.








  • Compliance familiarity: CMMC, NIST CSF/80053/171, ISO 27001





Required Qualifications
  • A bachelor's degree and 10 years of professional work experience (or equivalent experience) is required.

The MathWorks, Inc. is an equal opportunity employer. We evaluate qualified applicants without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, veteran status, and other protected characteristics. The EEO is the Law poster is available here.MathWorks participates in E-Verify. View the E-Verify posters here.PDN-a03948c6-31c5-489b-970f-c11be1ad3b2f
Summary

MathWorks has a hybrid work model that enables staff members to split their time between office and home. The hybrid model provides the advantage of having both in-person time with colleagues and flexible at-home life optimizations. Learn More: https://www.mathworks.com/company/jobs/resources/applying-and-interviewing.html#onboarding.

Do you design secure, resilient Active Directory at scale and enjoy automating identity operations? Join our Security Operations IAM team responsible for enterprise identity foundations across onprem Active Directory and Microsoft Entra ID. We partner with Security Engineering, IT, and Compliance to deliver hardened directory services, modern authentication, ITDR capabilities and Zero Trust controls that enable the business.

MathWorks nurtures growth, appreciates inclusivity, encourages initiative, values teamwork, shares success, and rewards excellence.


Responsibilities



  • Operate and maintain onpremises Active Directory: domain controller health, patching, promotion/demotion, replication, sites/subnets, time services, SYSVOL/GPO health, and capacity monitoring.








  • Implement and manage Entra ID capabilities: Conditional Access, Identity Protection risk policies, PIM, and app registrations/service principals.








  • Monitor, troubleshoot, and optimize directory synchronization and identity lifecycle flows.








  • Partner with our SOC to drive a successfulITDRprogram.Helpbuild and tune detections to identify threats such as DCSync, Golden/Silver Ticket, Kerberoasting, passthehash/ticket, risky signins, and impossible travel.








  • Harden AD and Entra ID: apply baselines, admin tiering, PAW usage, secure delegation, privileged workflow controls, regular access reviews, and identity threat hunting.








  • Automate identity operations and ITDR tasks with PowerShell and APIs (Graph/Entra): alert enrichment, response runbooks, access certifications, reporting, and drift remediation.








  • Lead complex troubleshooting and incident response for identity (Kerberos/NTLM, replication, DCSync/Golden/Silver Ticket detections, Conditional Access failures); drive root cause and preventive actions.








  • Produce runbooks, standards, and change records; mentor team members and collaborate with stakeholders to align IAM operations with business needs.





Qualifications

A successful candidate for this role will have a combination of some or all of the following skills/experience:



  • 7+ years in enterprise Active Directory operations and hardening including DC lifecycle management, sites/services, replication, BCDR, and observability.






  • Hands-on experience with Microsoft Entra ID: Conditional Access, MFA, Identity Protection, PIM, app registration and service principal governance.








  • Experience operating Azure AD Connect or Cloud Sync in hybrid identity environments.








  • Identity Governance and Administration experience for provisioning, role/entitlement models, and access certifications.








  • Proficiency with PowerShell, Python and Microsoft Graph/Entra APIs for automation.








  • Experience with privileged access models and administrative tiering.








  • Ability to support after-hours maintenance and incident response as needed.








  • SSO/Federation: SAML/OIDC/OAuth; SCIM provisioning to SaaS apps.








  • AD security: trusts, LDAP/LDAPS, constrained delegation, GPO hardening.








  • PKI and certificates: AD CS, CRL/OCSP, auto enrollment, renewal automation for workloads and service principals/certs.








  • Backup/Recovery: authoritative restore, forest recovery planning and drills.








  • IaC/automation: DSC, GPO as Code, Git workflows; CI/CD familiarity for scripts/policies.








  • Compliance familiarity: CMMC, NIST CSF/80053/171, ISO 27001





Required Qualifications
  • A bachelor's degree and 10 years of professional work experience (or equivalent experience) is required.

The MathWorks, Inc. is an equal opportunity employer. We evaluate qualified applicants without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, veteran status, and other protected characteristics. The EEO is the Law poster is available here.MathWorks participates in E-Verify. View the E-Verify posters here.PDN-a03948c6-31c5-489b-970f-c11be1ad3b2f

About MathWorks

MathWorks is the leading developer of mathematical computing software. MATLAB, the language of engineers and scientists, is a programming environment for algorithm development, data analysis, visualization, and numeric computation. Simulink is a block diagram environment for simulation and Model-Based Design of multidomain and embedded engineering systems. Engineers and scientists worldwide rely on these product families to accelerate the pace of discovery, innovation, and development in automotive, aerospace, electronics, financial services, biotech-pharmaceutical, and other industries. MATLAB and Simulink are also fundamental teaching and research tools in the world's universities and learning institutions. Founded in 1984, MathWorks employs more than 5,000 people in 16 countries, with headquarters in Natick, Massachusetts, USA.

Mission: Our goal is to change the world by accelerating the pace of discovery, innovation, development, and learning in engineering and science.

We work to provide the ultimate computing environment for technical computation, visualization, design, simulation, and implementation. We use this environment to provide innovative solutions in a wide range of application areas.


Related Jobs

Apply For This Job
Principal IAM/AD Engineer (36396-MMCC)
MathWorks
Natick, MA
Oct 28, 2025
Your Information
First Name *
Last Name *
Email Address *
This email belongs to another account. Please use a diferent email address or Sign In.
Zip Code *
Password *
Confirm Password *
Create your Profile from your Resume
By clicking the Apply button, you agree to the terms of use and privacy policy and consent to receive emails from us about job opportunities, career resources, and other relevant updates. You can unsubscribe at any time.
Supercharge Your Resume with AI

Boost your resume with AI-driven enhancements. The tool analyzes and refines your content, highlighting your strengths and tailoring it for maximum impact. Get personalized suggestions and apply improvements instantly to stand out in the job market.

©2025 International Association of Women.
Powered by TalentAlly.