Summary of Position:
At Alcon, we're passionate about enhancing sight and helping people see brilliantly. With more than 25,000 associates, we innovate fearlessly, champion progress, and act swiftly to impact global eye health. We foster an inclusive culture, recognizing your contributions and offering opportunities to grow your career like never before. Together, we make a difference in the lives of our patients and customers. Are you ready to join us?
This role is part of Alcon's Information Technology function, a team that delivers cutting-edge technology solutions to Alcon associates and customers to help our people and the world see brilliantly.
The Sr. Associate I, Identity & Access Management Security (Science/Tech/Engineering Path), is primarily responsible for supporting the development, deployment, and maintenance of secure IAM systems, ensuring compliance with identity and access management policies, and resolving access control and system vulnerabilities. Specifics include:
- Drive adoption of the strategy for IAM security, aligning with organizational risk management and security goals
- Design secure, enterprise-wide IAM solutions, implementing industry best practices
- Collaborate with IT and business teams to ensure IAM systems meet business needs and compliance requirements, and to optimize IAM processes and improve system security
- Mentor team members to foster a culture of security awareness and innovation
- Support complex risk assessments and work with cross-functional teams to implement security protocols
- Assist in implementing IAM systems, ensuring secure user access and adherence to policies
- Participate in audits of IAM systems to ensure compliance with security and regulatory standards
- Provide technical support for IAM-related issues, troubleshooting access control problems
- Document IAM procedures and provide reports on system performance and security audits
- Support the IAM team in maintaining and optimizing access control and identity management systems, contributing to addressing security vulnerabilities and maintaining compliance
- Handle day-to-day operational tasks, including troubleshooting, issue resolution, application onboarding, and data cleanup for IAM systems.
Key Responsibilities:
We are seeking a highly experienced Senior Active Directory Engineer to lead the design, implementation, and optimization of our enterprise identity infrastructure. This role demands deep technical expertise in Active Directory, Azure AD, Group Policy, and hybrid identity solutions.
Key Requirements/Minimum Qualifications:
Active Directory:
-
Expertise in maintaining complex Active Directory environments including multi-domain forests, trusts, replication, and domain controller placement.
-
6-8 years of total experience with 5+ years of relevant experience.
-
Experience in design and deployment of hybrid identity solutions integrating Azure AD, Intune, and on-prem AD.
-
Domain Controller Management Promotion, decommissioning and health monitoring of DCs.
-
Develop and enforce Group Policy Objects (GPOs) to support enterprise-wide security and configuration standards.
-
Manage and troubleshoot DNS, DHCP, Kerberos, and authentication protocols.
-
Expertise in managing and configuring Azure AD and Azure AD Connect for hybrid cloud environments.
-
Familiarity with PowerShell scripting for automation of Active Directory and server management tasks.
-
Good knowledge in networking, storage, and security within virtualized environments.
-
Experience with disaster recovery and high availability (HA) strategies in a virtualized infrastructure.
-
Managing Azure Entra ID solutions including user provisioning, group management, role-based access control (RBAC), and conditional access policies.
-
Strong knowledge on IAM solutions including authentication, authorization, SSO, MFA, and privileged access management (PAM).
-
Having knowledge on solutions like Saviynt, Secret Server and Okta is plus.
PKI:
-
Strong knowledge on deployment and management of PKI and Managed PKI solutions.
-
Strong knowledge on PKI, HSM, Encryption and Cryptography solution.
Preferred Certifications:
-
MCSE/MCSA or relevant certifications.
Work hours: 8PM – 5AM and 1PM – 10PM and 5AM – 2PM (Rotational bi- weekly).
Rotational weekend on-call.
Employment Scams: Alcon is aware of employment scams which make false use of our company name or leader’s names to defraud job seekers. Alcon does not offer any positions without interview and never asks candidates for money. All our current job openings are displayed here on the Careers section of our website, where you can search for open positions and apply directly.
If you have encountered a job posting or been approached with a job offer that you suspect may be fraudulent, we strongly recommend you do not respond, send money or personal information, and check our website for current job openings.
ATTENTION: Current Alcon Employee/Contingent Worker
If you are currently an active employee/contingent worker at Alcon, please click the appropriate link below to apply on the Internal Career site.
Find Jobs for Employees
Find Jobs for Contingent Worker
Alcon is an Equal Opportunity Employer and takes pride in maintaining a diverse environment. We do not discriminate in recruitment, hiring, training, promotion or other employment practices for reasons of race, color, religion, gender, national origin, age, sexual orientation, gender identity, marital status, disability, or any other reason.