Back to all jobs

L3 Systems Engineer – Identity & Endpoint Platforms

Work from home Full-time role Hiring

A career at Resilience is more than just a job – it’s an opportunity to change the future.

Resilience is a technology-focused biomanufacturing company that’s changing the way medicine is made. We’re building a sustainable network of high-tech, end-to-end manufacturing solutions to better withstand disruptive events, serve scientific discovery, and reach those in need. 

For more information, please visit www.resilience.com

The L3 Systems Engineer – Identity & Endpoint Platforms is a senior individual contributor responsible for the design, implementation, and ongoing administration of Resilience’s core identity and endpoint management platforms. This role owns Okta, Azure/Entra ID, and Microsoft Intune as the subject matter expert and primary engineer, ensuring secure, scalable, and compliant identity and device management across a GxP and non-GxP regulated environment. The role operates under the direction of the Digital Tech Ops leadership and partners closely with Security, IT Operations, and Application teams to support enterprise-wide identity governance, endpoint compliance, and cloud platform integrations.

This position serves as the escalation point for L3 identity and endpoint incidents, leads platform migration and modernization initiatives, and is responsible for maintaining documentation, SOPs, and architectural standards for all platforms in scope.

CORE RESPONSIBILITIES:

  • Design, implement, and maintain Okta SSO and MFA configurations, including authentication policies, SCIM provisioning, RBAC, identity governance, and workflow automation.

  • Administer Azure/Entra ID including enterprise application integrations (SSO, SCIM, OIDC, WS-Fed), Conditional Access policy design, identity lifecycle management, and user provisioning and deprovisioning.

  • Manage Microsoft Intune environments including Autopilot deployment, device configuration profiles, compliance policies, security baselines, and endpoint protection across Windows, iOS, and Android.

  • Administer Microsoft 365 services including Exchange Online, SharePoint, Teams, and OneDrive, managing permissions, mail flow, retention policies, and cloud service integrations.

  • Design and enforce endpoint compliance standards, partnering with the Security team to respond to identity anomalies, implement best-practice security policies, and maintain audit-ready configurations.

  • Develop and maintain PowerShell scripts and automation workflows to streamline identity lifecycle operations, endpoint provisioning, and compliance reporting.

  • Provide advanced L3 troubleshooting for identity systems, endpoint connectivity, collaboration tools, and cloud platform issues across hybrid on-premises and cloud environments.

  • Maintain comprehensive technical documentation, SOPs, and knowledge base articles to standardize identity and endpoint management processes.

  • Collaborate cross-functionally within IT teams to support projects, improve workflows, and drive continuous improvement.

REQUIRED QUALIFICATIONS:

  • Extensive hands-on experience administering Okta, including SSO, MFA, SCIM provisioning, RBAC, identity governance, and application-level security policy design.

  • Strong experience with Azure/Entra ID including Conditional Access policy design, enterprise application management, identity lifecycle management, and hybrid Active Directory environments.

  • Demonstrated expertise with Microsoft Intune, including Autopilot, MDM/MAM policy configuration, device compliance, security baselines, and endpoint protection across Windows and mobile platforms.

  • Proficiency in PowerShell scripting for automation of identity, endpoint, and compliance workflows.

  • Experience leading complex platform migration projects, such as Okta org-to-org, tenant migrations, or MDM platform transitions.

  • Working knowledge of Microsoft 365 administration including Exchange Online, SharePoint, Teams, and OneDrive.

  • Understanding of identity federation standards including SAML, OIDC, WS-Federation, and SCIM.  

PREFERRED QUALIFICATIONS:

  • Experience with Privileged Access Management (PAM) solutions such as CyberArk, BeyondTrust, 1Password, or Keeper. Familiarity with AWS services including Workspaces, IAM, and CloudWatch. Knowledge of ITIL framework and IT service management best practices.

  • Bachelor’s degree in Computer Science, Information Systems, or a related technical field.

  • 5+ years of experience in a systems engineering, identity engineering, or endpoint engineering role within a mid-to-large enterprise environment.

  • Experience working in a regulated environment (GxP, pharma, biotech, or equivalent) is strongly preferred.

WORKING CONDITIONS:

  • This is primarily a remote position. May require occasional evening or weekend work for planned maintenance activities, platform migrations, or system upgrades.Some travel may be required for training, conferences, meetings, or support of other company sites.

Sponsorship or support for work authorization, including visas, is not available for this position.

Resilience is an Equal Employment Opportunity Employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender perception or identity, national origin, age, marital status, protected veteran status, disability status, physical or mental disability, genetic information, or characteristic, or other non-job-related characteristics or other prohibited grounds specified in applicable federal, state, and local laws. Requests for reasonable accommodation can be made at any stage of the recruitment process.

Resilience offers employees a robust total rewards program including an annual cash bonus program, a 401(k) plan with a generous company match and our benefits package which is thoughtfully designed to support our employees with great healthcare (including medical, dental and vision), family building benefits, life and disability insurance, paid vacation, paid holidays, other paid leaves of absence, tuition reimbursement and support for caregiving needs. Our target base pay hiring range for this position is $90,000.00 - $153,750.00 per year. Actual base pay is dependent upon a number of factors, including but not limited to, the candidate’s geographical location, relevant experience, qualifications, skills and knowledge. Excited about Resilience? We encourage you to apply and start a conversation with one of our recruiters. Apply To This Job

More remote roles to explore

SOC Logic Design Engineer

Work from home Full-time role

Senior Project Manager (Public Safety Software) - Remote

Work from home Full-time role

Electrical Controls Engineer - Power

Work from home Full-time role

Account Manager

Work from home Full-time role

Director, Strategic Development

Work from home Full-time role

Senior Seach Engine Optimization Manager

Work from home Full-time role

Travel Project Manager

Work from home Full-time role

Correspondence Dev Lead

Work from home Full-time role

Manager of Commercial Analytics

Work from home Full-time role

Senior SRE

Work from home Full-time role

Analyst, Data Activation

Work from home Full-time role

Experienced Virtual Primary CVS Data Entry Specialist – Remote Opportunity at arenaflex

Work from home Full-time role

Senior Technical Recruiter

Work from home Full-time role

Experienced Online Chat Support Assistant – Customer Service Representative for arenaflex

Work from home Full-time role

Urban Planning Technician /FT – Hybrid/

Work from home Full-time role

[Remote-Position] Overnight Employee Assistance Program (EAP)

Work from home Full-time role

Senior Consultant Cloud & DevOps Engineering (m/w/d)

Work from home Full-time role

Senior Supply Chain Analyst - Clean Energy and Modeling Expert

Work from home Full-time role

RN Nurse Supervisor II - Telehealth Clinical Support - Kelsey-Seybold Clinic - Remote

Work from home Full-time role

Apple Home Advisor – Remote Work Opportunity (USA | $23–$32/Hour)

Work from home Full-time role