About this role
Microsoft Entra ID Engineer II
Washington, DC, United States
Job description
Company and benefits
Job ID
2026-7468
Date posted
09/23/2026
Department
Technology
Salary
$128,700.00 - $143,000.00 Yearly
Overview
AARP is the nation's largest nonprofit, nonpartisan organization dedicated to empowering people 50 and older to choose how they live as they age. With a nationwide presence, AARP strengthens communities and advocates for what matters most to the more than 100 million Americans 50-plus and their families: health and financial security, and personal fulfillment. AARP also works for individuals in the marketplace by sparking new solutions and allowing carefully chosen, high-quality products and services to carry the AARP name. As a trusted source for news and information, AARP produces the nation's largest-circulation publications, AARP The Magazine and the AARP Bulletin.
Information Technology Services is responsible for AARP enterprise-wide technology and information security functions. Services range from infrastructure design and operations, system and software lifecycle implementations, enabling the mobile workforce and protecting AARP network, systems and data. A variety of technologies and practices are used including cloud computing, automation, artificial intelligence and machine learning within highly collaborative Agile teams.
The Engineer II works with cross-functional teams and customers to understand business requirements and translates into technical specifications. They discover the true requirements underlying feature requests and recommend alternative technical approaches. The Engineer II partners with cross-functional technical teams to launch projects and provide ongoing technical support. They collaborate with management to identify opportunities to streamline technology processes and develop new procedures that support the business unit/department.
Responsibilities
- Establishes a technical roadmap for the platform and/or capability strategy and lifecycle that considers value-based outcomes, costs to maintain, supportability, and performance.
- Ensures sound integration, data, security, and business architecture design throughout all stages within the platform and/or capability lifecycle.
- Provides rapid delivery and development of technical solutions that align with business and/or platform desired outcomes.
- Troubleshoots and resolves technical issues related to platform or capability systems, solutions, and services.
- Innovates and drives continuous improvements of implementation methodology and technical service offerings based on customer/employee experiences or other enterprise objectives/outcomes.
- Participates in a Community of Interest for engineers across all capability and platform teams to share information and strengthen understanding of business needs and technology-based business solutions.
- Develops and maintains deep technical knowledge and expertise related to domain area systems, solutions, services, and applications.
Qualifications
- 5+ years of hands-on experience managing Microsoft identity and network services, including Dynamic Host Configuration Protocol (DHCP) and Domain Name System (DNS) services with Microsoft and Infoblox solutions, as well as Secure DNS and content filtering services with Cisco Umbrella and Fortinet FortiGate, for large-scale enterprises with a variety of endpoints (e.g., laptops, servers, networking equipment, IoT devices, etc.).
- 3+ years of hands-on experience engineering and administering Microsoft Entra ID (formerly Azure AD), including Entra tenant configuration, identity and access management, Microsoft 365 Multi-Factor Authentication (MFA), Conditional Access Policies, Enterprise Applications, Single Sign-On (SSO), application registration, and integration with on-premises Active Directory; experience with Privileged Access Management (PAM) solutions such as CyberArk is preferred.
- Demonstrated ability to troubleshoot complex Microsoft Entra ID authentication and identity issues, including SSO failures, Conditional Access, MFA, application integration, identity synchronization, and hybrid authentication; experience with SAML, OpenID Connect, OAuth, and other modern authentication protocols is highly desired.
- Ability to lead and execute iterative migration of on-premises Active Directory environments to Microsoft Entra ID, including hybrid identity configurations, Microsoft Entra Connect/Cloud Sync, and cloud-only identity models.
- Demonstrated proficiency in DevSecOps practices by designing and implementing API-driven automation for the complete user lifecycle, from onboarding through offboarding.
- Demonstrated experience with assessing and documenting existing Active Directory and Entra ID dependencies, including users, groups, service accounts, G