**Company Description**
Sandisk understands how people and businesses consume data and we relentlessly innovate to deliver solutions that enable today's needs and tomorrow's next big ideas. With a rich history of groundbreaking innovations in Flash and advanced memory technologies, our solutions have become the beating heart of the digital world we're living in and that we have the power to shape.
Sandisk meets people and businesses at the intersection of their aspirations and the moment, enabling them to keep moving and pushing possibility forward. We do this through the balance of our powerhouse manufacturing capabilities and our industry-leading portfolio of products that are recognized globally for innovation, performance and quality.
Sandisk has two facilities recognized by the World Economic Forum as part of the Global Lighthouse Network for advanced 4IR innovations. These facilities were also recognized as Sustainability Lighthouses for breakthroughs in efficient operations. With our global reach, we ensure the global supply chain has access to the Flash memory it needs to keep our world moving forward.
**Job Description**
This role is primarily focused on driving the Microsoft Entra ID device migration and providing Entra ID engineering support across the organization. The Staff Security Operations Engineer serves as a key technical driver for migrating devices into Entra ID and as a hands-on engineering resource for the Entra ID (Azure AD) platform. Supporting identity and access management technologies - multi-factor authentication (Duo MFA and Windows Hello for Business), mobile device management, and Active Directory - make up the secondary scope of the role.
**Essential Duties and Responsibilities:**
+ **Entra ID Device Migration (Primary Focus):**
+ Drive and lead the migration of devices into Microsoft Entra ID, including Entra ID join and hybrid Entra ID join scenarios.
+ Plan, schedule, and execute device migration waves from on-premises Active Directory / hybrid configurations to Entra ID, with minimal disruption to end users.
+ Develop migration runbooks, rollback plans, validation checklists, and success criteria for each migration phase.
+ Coordinate with endpoint, IT, and security teams to align device readiness, Conditional Access, and compliance requirements ahead of migration.
+ Troubleshoot device join, registration, enrollment, and Conditional Access issues encountered during migration.
+ Track migration progress, report on adoption metrics, and continuously refine the migration approach.
+ **Entra ID Engineering Support (Primary Focus):**
+ Provide engineering-level administration and operational support for the Microsoft Entra ID (Azure AD) platform.
+ Configure and manage Conditional Access policies, Identity Protection, single sign-on (SSO), app registrations, and enterprise applications.
+ Support hybrid identity using Microsoft Entra Connect (Azure AD Connect), ensuring reliable synchronization between on-premises AD and Entra ID.
+ Act as the technical escalation point for Entra ID incidents, identifying root causes and implementing durable solutions.
+ Automate Entra ID administration, reporting, and provisioning tasks using PowerShell and Microsoft Graph.
+ Maintain documentation, runbooks, and operational procedures for the Entra ID environment.
+ **Multi-Factor Authentication (MFA) Management (Secondary Focus):**
+ Administer and manage the organization's MFA platforms, including **Duo MFA** and **Windows Hello for Business** .
+ Implement and enforce MFA policies across the organization, ensuring integration with various applications and systems.
+ Monitor MFA performance, troubleshoot issues, and handle escalations related to authentication failures or policy violations.
+ **Mobile Device Management (MDM) (Secondary Focus):**
+ Support the administration of the Intune platform security, Conditional Access and Compliance, and RBAC/PIM/MAA Governance.
+ Work with IT teams to ensure all mobile devices comply with organizational security policies and access controls.
+ **Active Directory (AD) (Secondary Focus):**
+ Provide support for Active Directory, managing user accounts, group policies, and organizational units.
+ Support hybrid identity integration between on-premises AD and Entra ID using Microsoft Entra Connect.
+ Troubleshoot and resolve issues related to AD/Entra ID authentication and access provisioning.
+ **IAM Process Optimization:**
+ Continuously evaluate and improve IAM processes related to Entra ID, device migration, MFA, and AD to enhance security and user experience.
+ Automate routine identity management tasks and workflows to increase efficiency and reduce manual errors.
+ **Incident Response and Troubleshooting:**
+ Act as the technical escalation point for identity-related incidents involving Entra ID, device migration, Duo MFA, Windows Hello for Business, and other IAM systems.
+ Investigate, troubles