The Clearing House logo

M365 Engineer - Entra

Posted 24 days ago

OfficeCharlotte Office

Position summary:

We are seeking a highly skilled Microsoft 365 and Entra Identity Administrator to serve as the technical owner of our Microsoft cloud identity platform. This position will be responsible for the day-to-day administration, maintenance, optimization, governance, and security of Microsoft Entra ID, Conditional Access, authentication services, identity lifecycle management, and enterprise application integrations. The ideal candidate will possess deep expertise in modern identity and access management technologies, including SAML, OAuth, OpenID Connect (OIDC), Multifactor Authentication (MFA), and Single Sign-On (SSO), while maintaining strong knowledge of Active Directory, DNS, DHCP, Group Policy, and hybrid identity architecture. Experience supporting cloud platforms such as AWS is highly desirable.


About The Clearing House: The Clearing House Payments Company L.L.C. is a bank-owned industry utility that shapes the payments landscape and provides infrastructure for safe, reliable, and efficient payments. We see an economy where everyone is connected and a future where modern payments make life easier. The Clearing House operates four payment systems: a high-value wire-transfer system (the CHIPS® network), the country’s first and largest instant payments system (the RTP® network), an automated clearinghouse network (the EPN® network), and a check image exchange network (the Image Exchange Network). TCH also operates a bank account number tokenization service, runs a payments association known as the TCH Payments Authority, and maintains the rules for private-sector check image exchange through its ECCHO® business line. 


 

Responsibilities

  • Serve as the primary administrator and technical owner of the Microsoft Entra ID environment.
  • Administer and maintain user lifecycle management, identity governance, authentication methods, and directory services.
  • Design, implement, and maintain enterprise identity and access management solutions.
  • Configure, support, and troubleshoot Single Sign-On (SSO) integrations utilizing SAML 2.0, OAuth 2.0, OpenID Connect (OIDC), and other modern authentication protocols.
  • Administer Enterprise Applications, App Registrations, service principals, and API permissions within Microsoft Entra.
  • Manage and optimize Multifactor Authentication (MFA) solutions, including Microsoft Authenticator, authentication strengths, passwordless authentication, and self-service password reset capabilities.
  • Develop and maintain Conditional Access policies aligned with security, compliance, and business requirements.
  • Monitor identity-related health, security posture, and access trends while proactively identifying opportunities for improvement and optimization.
  • Partner with application owners, cybersecurity teams, and vendors to integrate applications securely with Microsoft Entra ID.
  • Maintain and troubleshoot hybrid identity solutions including Entra Connect and Active Directory synchronization services
  • Administer and maintain Active Directory infrastructure, including users, groups, organizational units (OUs), delegation models, and directory services.
  • Design, implement, and troubleshoot Group Policy Objects (GPOs) to support security, compliance, and operational requirements.
  • Manage and maintain hybrid identity infrastructure supporting synchronization between Active Directory and Microsoft Entra ID.
  • Administer and troubleshoot Microsoft Entra Connect, synchronization services, identity provisioning, and directory-related issues.
  • Manage and maintain DNS and DHCP services supporting enterprise authentication and application connectivity.
  • Perform certificate lifecycle management activities, including certificate renewals, replacements, and troubleshooting for authentication, federation, and secure communications.
  • Support Public Key Infrastructure (PKI) and certificate-based authentication solutions where applicable.
  • Assist with identity-related disaster recovery planning, testing, and operational readiness activities.
  • Collaborate with infrastructure, cybersecurity, and application teams to ensure secure and reliable identity services across on-premises and cloud environments.
  • Monitor and maintain the health, availability, and performance of identity-related infrastructure components.
  • undefined

 

Qualifications


  • Strong expertise in Microsoft 365 administration, Microsoft Entra ID, hybrid identity, and directory services.
  • Deep understanding of authentication and federation technologies including SAML 2.0, OAuth 2.0, OpenID Connect (OIDC), Single Sign-On (SSO), and Multifactor Authentication (MFA).
  • Experience administering and troubleshooting Enterprise Applications, App Registrations, service principals, and API permissions within Microsoft Entra
  • Strong understanding of Conditional Access, authentication methods, identity governance, and modern identity security practices.
  • Advanced knowledge of Active Directory, Group Policy, DNS, DHCP, Microsoft Entra Connect, and hybrid identity architectures.
  • Experience managing and troubleshooting identity synchronization between Active Directory and Microsoft Entra ID.
  • Knowledge of Public Key Infrastructure (PKI), certificate lifecycle management, and certificate-based authentication services.
  • Proficiency with PowerShell automation and Microsoft Graph API administration.
  • Knowledge of disaster recovery planning, testing, and validation methodologies, with willingness to participate in recovery exercises when required.
  • Experience supporting Microsoft Intune, endpoint management, and device-based access controls is a plus.
  • Familiarity with AWS identity integrations, IAM, and Amazon Route 53 DNS administration is preferred.
  • Must be comfortable working within a strict and highly governed change management environment.
  • Must be committed to maintaining security, risk, and compliance controls within a regulated industry environment.
  • Ability to create and maintain technical documentation, operational procedures, and knowledge transfer materials.
  • Demonstrated ability to troubleshoot complex technical issues, take ownership of problems, and drive resolutions through completion.
  • Excellent communication, analytical, and problem-solving skills.
  • Strong attention to detail, organizational skills, and operational discipline.

 

Work Conditions & Expectations

  • Hybrid Schedule: 3 days onsite (Charlotte NC preferred, occasional asks to report to Winston-Salem NC as needed); On-site work requirements can change at any time.
  • Operational Flexibility: Ability to perform after-hours changes and participate in on-call rotations when required.
  • Dynamic Environment: Work involves frequent troubleshooting, collaboration across teams, and adapting to evolving technologies.
  • Security & Compliance: Must adhere to strict Change Management processes and participate in security reviews as needed.
  • Standard Office Setup: Role primarily uses standard IT equipment (laptops, conferencing tools, monitoring systems) with occasional interaction with server rooms or networking hardware.
The Clearing House logo
The Clearing House
View company page

The Clearing House Payments Company L.L.C. owns and operates core payments system infrastructure in the United States that clear and settle more than $2 trillion each business day through wire, ACH, check image, and instant payments. The company operates the RTP® network, launched in 2017, which supports the immediate clearing and settlement of payments, along with the ability to exchange related payment information across the same secure channel. The Clearing House is the only private-sector instant payments, ACH, and wire operator in the United States, representing 98% of instant payments volume and half of all commercial ACH and wire volume. Its affiliate, The Clearing House Association L.L.C., the country’s oldest banking trade association, is a nonpartisan organization that provides informed advocacy and thought leadership on critical payments-related issues.

Employees
717
Industry
Financial Services
Headquarters
New York, NY
Company location
1114 Avenue of the Americas, New York, NY 10036, US
Specialties
Payments, Advocacy, and Thought Leadership

Key team members

Apply smarter with Jobr

Jobr aggregates jobs directly from company career portals — no middlemen. Our team applies on your behalf with AI-tailored resumes, reviewed by a human before submission.

Direct from company career pages
AI-personalised cover letters
Human review before every submit
Application tracking & follow-ups