Job Description:

Note: Fidelity will not provide immigration sponsorship for this position.

Position Description:

Provides secure identity management services via Microsoft Entra ID (formerly Azure Active Directory) and Active Directory Domain Services according to Agile methodologies. Works in a combined engineering/operations DevOps model using toolsets -- Jenkins Core, GitHub, Graph Application Programming Interfaces (APIs), Domain Name System (DNS), DHCP, and Public Key Infrastructure (PKI) in a cloud environment (Microsoft Azure or Amazon Web Services (AWS)). Identifies and addresses security vulnerabilities by implementing solutions that protect the firm from external cyber threats. Uses business knowledge to translate the vision for divisional initiatives into business solutions by developing complex or multiple software applications and conducting studies of alternatives. Analyzes and recommends changes in project development policies, procedures, standards, and strategies to development experts and management.

Primary Responsibilities:

  • Crafts and coordinates authentication and authorization solutions in the environment, prioritizing resiliency.
  • Identifies anomalies in the enterprise by analyzing identity transactions and creates configuration guides in securing those transactions by enforcing controls.
  • Defines and leads enterprise-level systems architecture and strategy.
  • Develops and implements scalable infrastructure solutions.
  • Establishes observability standards for all supported applications.
  • Develops and enhances existing functionalities by supporting highly distributed multi-tiered systems at scale.
  • Develops, documents, and revises system design procedures, test procedures, and quality standards.
  • Collaborates with developers to test and push codes or packages out to production.
  • Advises senior leadership on systems engineering best practices.
  • Mentors junior engineers.
  • Performs independent and complex technical and functional analysis for multiple divisional initiatives.
  • Develops innovative solutions to support evolving infrastructure needs.

Education and Experience:

Bachelor’s degree in Computer Science, Engineering, Information Technology, Information Systems, or a closely related field (or foreign education equivalent) and five (5) years of experience as Principal Systems Engineer (or closely related occupation) designing, developing, and supporting Identity and Access Management (IAM) solutions for enterprise cybersecurity using Microsoft Entra ID within a financial services environment.

Or, alternatively, Master’s degree in Computer Science, Engineering, Information Technology, Information Systems, or a closely related field (or foreign education equivalent) and three (3) years of experience as a Principal Systems Engineer (or closely related occupation) designing, developing, and supporting Identity and Access Management (IAM) solutions for enterprise cybersecurity using Microsoft Entra ID within a financial services environment.

Skills and Knowledge:

Candidate must also possess:

  • Demonstrated Expertise (“DE”) deploying security controls to safeguard the enterprise from cyberattacks (using Microsoft Entra Conditional Access Policies, Microsoft Identity Protection, Microsoft Defender for Identity, Entra ID multifactor/biometric authentication, Windows Group Policy, and Microsoft Entra Password Protection); and providing operational support including infrastructure support, cloud enablement, platform engineering, environment management, and incident management.
  • DE identifying anomalies in Microsoft Entra ID, active directory test, and production environments, and performing workflow automations, using shell scripting (PowerShell, Kusto Query Language, and Python).
  • DE designing and deploying enterprise-grade Hybrid Identity sync engine, using Entra Connect infrastructure following secure deployment practices -- standby server configuration and comprehensive documentation.
  • DE setting up proactive monitoring using monitoring tools (System Center Operations Manager (SCOM), Splunk, Grafana, and Azure Monitor).

#PE1M2

#LI-DNI

Fidelity’s Onsite Working Model
Fidelity is transitioning to a full-time onsite working model through a phased rollout across regions and roles. Currently, some roles and locations require 100% onsite presence, while others require less. Onsite expectations are likely to evolve as the rollout continues. This transition does not apply to fully remote roles.

Certifications:

Category:

Information Technology

Please be advised that Fidelity’s business is governed by the provisions of the Securities Exchange Act of 1934, the Investment Advisers Act of 1940, the Investment Company Act of 1940, ERISA, numerous state laws governing securities, investment and retirement-related financial activities and the rules and regulations of numerous self-regulatory organizations, including FINRA, among others. Those laws and regulations may restrict Fidelity from hiring and/or associating with individuals with certain Criminal Histories.