Senior Full Stack Engineer – IAM
Argano · Canada
About The Role
The Identity & Access Management (IAM) – Directory Services team is responsible for building and operating a secure, standardized, and automated enterprise identity foundation across The Walt Disney Company. We provide the authoritative directory platforms that enable authentication, authorization, and access governance for both human and non‑human identities.
Our mission is to move identity governance from manual, reactive processes to automated, policy‑driven enforcement, ensuring identities are secure, compliant, and healthy by default across their lifecycle. We partner closely with security, infrastructure, and application teams to eliminate legacy risk, reduce operational toil, and enable modern, cloud‑first identity capabilities at enterprise scale.
What You’ll Do
Application & Automation Engineering
- Design, build, and maintain secure, enterprise-scale web applications using .NET (C#) on the backend and Angular on the frontend.
- Develop and deliver RESTful APIs and microservices that integrate with Active Directory, Entra ID, and enterprise identity platforms.
- Build self-service portals and workflows that replace manual identity operations with automated, policy-driven processes.
- Write clean, testable, well-documented code and participate in code reviews, CI/CD pipelines, and automated testing.
Non-Human Identity (NHI) Onboarding & Management
- Automate the onboarding, lifecycle, and decommissioning of non-human identities — service accounts, managed identities, application registrations, certificates, and secrets.
- Build tooling for NHI discovery, ownership attestation, credential rotation, and expiry notification.
- Implement guardrails and approval workflows that ensure every NHI has a valid owner, justification, and least-privilege entitlement set.
AD Group Management & Access Automation
- Develop automation for Active Directory group lifecycle management — creation, naming standards, nesting rules, ownership, membership review, and cleanup of stale or orphaned groups.
- Implement RBAC-based, request-and-approve access models with time-bound and just-in-time membership patterns.
- Integrate group management with Entra ID, ITSM, and identity governance platforms.
Governance, Compliance & Reporting Automation
- Automate governance and compliance policy enforcement for Active Directory and Entra ID, including drift detection, automated remediation, and exception handling.
- Build dashboards and compliance reporting that give owners, auditors, and leadership continuous visibility into identity posture.
- Translate security standards and audit requirements into codified, testable policy checks.
Collaboration & Delivery
- Partner with identity engineers, security architects, and application teams to gather requirements and deliver iteratively.
- Produce runbooks, technical documentation, and knowledge transfer materials so solutions remain supportable beyond the contract term.
Work Location: This is an onsite position based in Burbank, California. Candidates must be able to work onsite.
Required Qualifications & Skills
- 8+ years of professional software engineering experience building and shipping web applications.
- Strong, hands-on expertise in:
- .NET / .NET Core, C#, ASP.NET Web API
- Angular (modern versions), TypeScript, HTML/CSS
- REST API design, SQL Server / relational data modeling
- PowerShell scripting for identity and directory automation
- Demonstrated experience automating against Active Directory and/or Microsoft Entra ID (Azure AD) — LDAP, Microsoft Graph API, directory objects, groups, and service principals.
- Experience with Git-based source control, CI/CD pipelines, and automated testing.
- Ability to work independently in a complex enterprise environment and deliver production-ready outcomes within a fixed contract timeline.
- Strong communication skills, with the ability to explain technical design to both engineers and non-technical stakeholders.
Preferred Qualifications
- Experience building identity governance, IAM, or access-request automation solutions.
- Familiarity with non-human identity management, secrets management (e.g., Azure Key Vault, HashiCorp Vault), and certificate lifecycle automation.
- Experience with Azure cloud services, Azure Functions, Logic Apps, or equivalent serverless automation.
- Exposure to PIM/PAM platforms and privileged access models.
- Experience with compliance and audit-driven engineering (SOX, PCI, SOC 2, or similar control environments).
- Working knowledge of containers, Kubernetes, or infrastructure-as-code (Terraform, Bicep).
- Relevant Microsoft certifications (e.g., SC-300, AZ-204, AZ-500).
Required Education
- Bachelor’s degree in Computer Science, Information Systems, Software, Electrical or Electronics Engineering, or comparable field of study, and/or equivalent work experience
Similar roles you might like
See all →This is an external listing. JobSpring does not represent or verify the employer. Report this listing
