For more than 100 years, Modine has solved the toughest thermal management challenges for mission-critical applications. Our purpose of Engineering a Cleaner, Healthier World™ means we are always evolving our portfolio of technologies to provide the latest heating, cooling, and ventilation solutions. Through the hard work of more than 11,000 employees worldwide, our Climate Solutions and Performance Technologies segments advance our purpose with systems that improve air quality, reduce energy and water consumption, lower harmful emissions, enable cleaner running vehicles, and use environmentally friendly refrigerants. Modine is a global company headquartered in Racine, Wisconsin (U.S.), with operations in North America, South America, Europe, and Asia. For more information about Modine, visit modine.com.
Position Description
The Senior Directory Services & Cloud Identity Specialist serves as a senior-level technical authority and hands-on subject matter expert responsible for the architecture, security, lifecycle governance, and operational resilience of enterprise identity ecosystems and cloud infrastructure.
This role requires a proactive, highly autonomous go-getter who thrives in dynamic environments, takes immediate ownership of complex challenges, and actively identifies architectural gaps before they impact the business. Bridging hybrid Active Directory Domain Services (AD DS) and Microsoft Entra ID, this engineer will lead identity modernization, automate critical operational workflows via PowerShell and DevOps practices, manage Azure subscriptions and core SaaS platforms, and serve as the tier-3/4 escalation authority across enterprise collaboration and infrastructure services.
Key Responsibilities
- Identity, Directory Services & Access Management (IAM / CIAM)
-
- Hybrid Identity Architecture: Design, implement, optimize, and maintain enterprise Active Directory (AD DS), Azure AD Connect / Entra Cloud Sync, and Microsoft Entra ID across hybrid multi-domain and multi-tenant environments.
- Access Federation & SSO: Architect and administer Single Sign-On (SSO), SAML 2.0 / OIDC integrations, Entra Application Proxy, and enterprise federation with third-party SaaS and line-of-business applications.
- Identity Governance & Lifecycle: Implement and maintain automated user lifecycle provisioning (JML: Joiner/Mover/Leaver workflows), Entra ID Governance, Access Reviews, Privileged Identity Management (PIM), and dynamic role-based access control (RBAC).
- Zero Trust & Security Posture: Define and enforce Conditional Access Policies, Multi-Factor Authentication (MFA), passwordless authentication mechanisms, and Active Directory Fine-Grained Password Policies to maintain a robust Zero Trust security posture.
- Cloud Infrastructure & SaaS Management
-
- Azure Subscription & Resource Governance: Administer enterprise Azure subscriptions, management groups, Resource Groups, Azure Policy, cost optimization, and virtual networking (VNets, NSGs, private endpoints).
- SaaS Administration & Collaboration Support: Oversee tenant-level configurations, cross-tenant synchronization, security baselines, and escalated troubleshooting for Microsoft 365 services—with deep administrative focus on Microsoft Teams and SharePoint (Online & Hybrid/On-Premises).
- Public Key Infrastructure (PKI): Oversee Microsoft Certificate Authority (AD CS), certificate lifecycle management, and secure enrollment services (NDES/SCEP).
- DevOps Automation, Scripting & Initiative
-
- Advanced PowerShell Automation: Build, maintain, and document production-grade PowerShell modules, automation runbooks, and API-driven scripts (Graph API, Azure CLI) to eliminate manual administration tasks and automate cross-platform syncs.
- Continuous Improvement & Problem Discovery: Proactively identify legacy technical debt, performance bottlenecks, and security vulnerabilities across directory and cloud services without waiting for task assignment.
- Infrastructure as Code (IaC): Drive modern automation practices utilizing ARM/Bicep templates or Terraform for repeatable Azure resource deployments.
- Escalations, Collaboration & Mentorship
-
- Tier 3/4 Escalation Authority: Serve as the definitive escalation tier for complex directory, authentication, sync, and M365 infrastructure issues, interfacing directly with Helpdesk, Local Tech Support, Infosec, and engineering teams.
- Vendor & Project Leadership: Partner with external technology vendors, lead enterprise migration and divestiture initiatives, and author detailed technical documentation, architectural diagrams, and standard operating procedures (SOPs).
- Technical Mentorship: Guide and upskill junior system administrators, desktop engineers, and support personnel.
Required Education & Qualifications
- Experience: 8+ years of progressive engineering experience in enterprise Windows Server, Active Directory, and Microsoft Cloud / Identity ecosystems.
- Directory & Cloud Identity: Deep, proven expertise in Active Directory Domain Services (AD DS), Group Policy (GPO), DNS/DHCP, Kerberos/NTLM authentication, and Microsoft Entra ID (Azure AD).
- Scripting & Automation: Advanced proficiency in PowerShell scripting (including Graph PowerShell SDK, REST APIs, and background job handling) for large-scale enterprise administration.
- Federation & IAM: Extensive hands-on experience configuring SSO, SAML, OAuth, Conditional Access, PIM, and SCIM-based identity provisioning.
- Cloud Platform Governance: Practical administration experience with Microsoft Azure (Subscriptions, IAM/RBAC, Resource Governance, Networking, and Log Analytics/Sentinel).
- Mindset & Initiative: Self-directed problem solver with a proven track record of wearing multiple hats, driving unassigned initiatives to completion, and navigating ambiguity in fast-paced enterprise environments.
- Communication & Interpersonal Skills: Excellent written and verbal communication skills with the ability to articulate complex technical architectures to leadership and mentor operational support teams.
Preferred / "Nice to Have" Qualifications
- Multi-Cloud & GCP Experience:
-
- Hands-on administration or foundational experience with Google Cloud Platform (GCP), including Google Cloud IAM, Cloud Identity, and Workload Identity Federation with Microsoft Entra ID / Active Directory.
- Familiarity with GCP Zero Trust access controls, Cloud Identity-Aware Proxy (IAP), and hybrid multi-cloud networking.
- Enterprise Collaboration: Strong operational administration and migration experience with Microsoft Teams and SharePoint Online / Server (permissions, site architectures, and external sharing policies).
- Migration & Coexistence Tools: Experience utilizing enterprise identity/mailbox migration platforms (e.g., Quest On Demand Migration / Migration Manager, BitTitan, or native cross-tenant sync).
- Hybrid Messaging: Experience supporting hybrid Microsoft Exchange environments (Exchange Online and Exchange Server).
- Industry Certifications (Highly Desirable):
-
- Microsoft Certified: Identity and Access Administrator Associate (SC-300)
- Microsoft Certified: Azure Administrator Associate (AZ-104)
- Microsoft Certified: Cybersecurity Architect Expert (SC-100) or Azure Solutions Architect Expert (AZ-305)
Education Requirements
- Bachelor’s degree in Information Technology, Computer Science, Computer Engineering, or a related technical discipline (or equivalent relevant professional experience).
Why Choose Modine?
Health & Well-being:
- Day One
- Competitive health, dental & vision insurance coverage
- Employee Assistance Program
- After 90 days of continuous employment
- Maternity Leave (12 weeks at 100% pay)
- 8 weeks of short term disability leave paid at 100%
- 4 weeks of paid parental leave paid at 100%
- Paternity Leave (4 weeks at 100% pay)
Financial Benefits:
- 401k Retirement plan and company paid match
- Life Insurance
- Health Savings Account (HSA) with employer contribution
- Flexible Spending Accounts (FSA)
- Short Term Disability (company paid)
- Long Term Disability
Work-Life Balance:
- Competitive time-off policies
- Tuition Reimbursement
To view full benefits information: MyModine Benefits
Modine is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, veteran status, or any other characteristic protected by law. Modine provides a competitive benefit package, which could include paid vacation, short term disability, 401(k), health, dental, vision, life insurance, flex spending benefits, tuition reimbursement, Health Savings Account and much more. Human Resources will provide more detail upon your hiring.
#LI-RR1
#LI-Remote
The salary range for this position is estimated in good faith to be $93,000-$163,000. The specific offer will depend on the candidate’s qualifications, experience, and other job-related considerations but will be within the stated range. Where required by applicable law, a general description of benefits and other compensation offered for this role is also provided or made available.
This position is not eligible for any form of sponsorship (e.g. OPT or H1B visa status) now or in the future. Only individuals authorized to work in the United States now and for the foreseeable future will be considered for this position.