Principal Systems Engineer
Fidelity Investments
- Location
- Durham, NC
- Work model
- On-Site
- Level
- Principal
- Posted
- Aug 26, 2026
Skills
About this role
Job Description
Note: Fidelity will not provide immigration sponsorship for this position.
Position
Description : Provides secure identity management services via Microsoft Entra ID (formerly Azure Active Directory) and Active Directory Domain Services according to Agile methodologies. Works in a combined engineering/operations DevOps model using toolsets -- Jenkins Core, GitHub, Graph Application Programming Interfaces (APIs), Domain Name System (DNS), DHCP, and Public Key Infrastructure (PKI) in a cloud environment (Microsoft Azure or Amazon Web Services (AWS)). Identifies and addresses security vulnerabilities by implementing solutions that protect the firm from external cyber threats. Uses business knowledge to translate the vision for divisional initiatives into business solutions by developing complex or multiple software applications and conducting studies of alternatives. Analyzes and recommends changes in project development policies, procedures, standards, and strategies to development experts and management.
Primary Responsibilities
Crafts and coordinates authentication and authorization solutions in the environment, prioritizing resiliency. Identifies anomalies in the enterprise by analyzing identity transactions and creates configuration guides in securing those transactions by enforcing controls. Defines and leads enterprise-level systems architecture and strategy. Develops and implements scalable infrastructure solutions. Establishes observability standards for all supported applications. Develops and enhances existing functionalities by supporting highly distributed multi-tiered systems at scale. Develops, documents, and revises system design procedures, test procedures, and quality standards. Collaborates with developers to test and push codes or packages out to production. Advises senior leadership on systems engineering best practices. Mentors junior engineers. Performs independent and complex technical and functional analysis for multiple divisional initiatives. Develops innovative solutions to support evolving infrastructure needs. Education and Experience : Bachelor’s degree in Computer Science, Engineering, Information Technology, Information Systems, or a closely related field (or foreign education equivalent) and five (5) years of experience as Principal Systems Engineer (or closely related occupation) designing, developing, and supporting Identity and Access Management (IAM) solutions for enterprise cybersecurity using Microsoft Entra ID within a financial services environment. Or, alternatively, Master’s degree in Computer Science, Engineering, Information Technology, Information Systems, or a closely related field (or foreign education equivalent) and three (3) years of experience as a Principal Systems Engineer (or closely related occupation) designing, developing, and supporting Identity and Access Management (IAM) solutions for enterprise cybersecurity using Microsoft Entra ID within a financial services environment. Skills and Knowledge : Candidate must also possess: Demonstrated Expertise (“DE”) deploying security controls to safeguard the enterprise from cyberattacks (using Microsoft Entra Conditional Access Policies, Microsoft Identity Protection, Microsoft Defender for Identity, Entra ID multifactor/biometric authentication, Windows Group Policy, and Microsoft Entra Password Protection); and providing operational support including infrastructure support, cloud enablement, platform engineering, environment management, and incident management. DE identifying anomalies in Microsoft Entra ID, active directory test, and production environments, and performing workflow automations, using shell scripting (PowerShell, Kusto Query Language, and Python). DE designing and deploying enterprise-grade Hybrid Identity sync engine, using Entra Connect infrastructure following secure deployment practices -- standby server configuration and comprehensive documentation. DE setting up proactive