Infrastructure Engineer
Listed on 2026-02-09
-
IT/Tech
Cybersecurity, Systems Engineer, IT Support
Overview
Founded in 1999, Audax Group is a leading alternative investment manager with offices in Boston, New York, San Francisco, London and Hong Kong. With approximately $42 billion of assets under management and more than 475 employees, Audax is a leading capital partner for middle market companies, operating through three business lines:
Audax Private Equity, Audax Private Debt, and Audax Strategic Capital.
The Infrastructure Engineer (Identity & Access Management) is a senior individual contributor responsible for designing, implementing, and operating the firm’s identity and access management capabilities. This role serves as the subject matter expert for Entra , Conditional Access, SSO, MFA, and Zscaler ZPA, enabling secure access to enterprise systems through zero trust and least privilege principles.
Responsibilities- Identity and Access Architecture and Operations
- Design, implement, and operate enterprise identity and access management solutions aligned with zerotrust, least privilege, and risk-based access principles.
- Define, maintain, and enforce standards for SSO, MFA, Conditional Access, and access governance across cloud and on-premises systems.
- Serve as the technical authority for identity-driven access patterns, authentication architectures, secure access workflows, and identity life cycles.
- Administer Entra , including tenant configuration, identity settings, and access policies.
- Design, implement, and manage Conditional Access policies based on user risk, device posture, and access context.
- Deliver and operate SSO integrations for SaaS and internal applications, including onboarding, testing, rollout, troubleshooting, and ongoing support.
- Configure and manage Entra Applications, including assignment scoping, permission governance, and access models.
- Govern Microsoft Graph API access, including permission scoping and consent workflows.
- Administer Zscaler ZPA for private application access, connectivity policies, and operational support, partnering with application owners to enable secure access.
- Administer and support Meraki switching and wireless access points, including configuration, monitoring, and lifecycle management.
- Manage network access controls and firewall policies using Forti Gate to support identity-aware access.
- Troubleshoot network connectivity and access issues across wired, wireless, and remote access environments, collaborating with security and infrastructure teams as needed.
- Conduct periodic access reviews and partner with system owners to remediate access gaps and policy violations.
- Participate in annual third-party cyber and risk assessments, addressing identity and access related findings.
- Develop operational metrics and reporting to communicate platform health, access risks, and improvement areas to management.
- Maintain documentation, standards, and procedures for identity and access services.
- Serve as the primary escalation point for identity and access related incidents, outages, and security events, coordinating response and remediation with Information Security and Infrastructure teams.
- Expert level experience administering Entra , including tenant configuration, identity settings, and access policy management.
- Expert level experience designing and maintaining Conditional Access policies aligned to risk-based access and least privilege principles.
- Strong experience delivering and operating SSO and MFA at enterprise scale.
- Strong experience configuring Entra Applications, including assignment scoping and permission governance.
- Experience governing Microsoft Graph API permissions, including scoping, consent workflows, and least privilege controls.
- Hands-on experience administering Zscaler ZPA.
- Working knowledge of OAuth, OpenID Connect, SAML, and LDAP.
- Working knowledge of networking fundamentals related to authentication and access control.
- Strong troubleshooting skills across authentication, authorization, and access flows.
- Familiarity with Microsoft Intune.
- Familiarity with Microsoft Purview.
- Power Shell scripting and automation experience.
- Bachelor’s degree…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).