Senior Cloud Engineer
Be visionaryTeledyne Technologies Incorporated provides enabling technologies for industrial growth markets that require advanced technology and high reliability. These markets include aerospace and defense, factory automation, air and water quality environmental monitoring, electronics design and development, oceanographic research, deepwater oil and gas exploration and production, medical imaging and pharmaceutical research.We are looking for individuals who thrive on making an impact and want the excitement of being on a team that wins.Job DescriptionTeledyne IT Shared Services is seeking an experienced Senior Cloud Engineer to join the Enterprise Infrastructure Solutions team. This role is responsible for designing, implementing, and administering enterprise cloud and identity platforms that support Teledyne's global workforce and business units. The Senior Cloud Engineer will take ownership of critical identity and access management systems, Microsoft 365 services, enterprise PKI infrastructure, and security governance programs across a complex, multi-tenant environment.The ideal candidate brings deep hands-on expertise in Microsoft cloud technologies, a strong security mindset, and the ability to drive enterprise-scale projects with minimal supervision. Experience supporting acquisition and divestiture activities in a large enterprise environment is a plus.Job Duties & Responsibilities:Identity & Access ManagementServe as a primary administrator for Microsoft Entra ID (Azure AD) and on-premises Active Directory in a hybrid enterprise environmentDesign, implement, and maintain Conditional Access policies to enforce M365 app access controls for Entra-registered and compliant devicesManage device registration and enrollment policies across Workspace ONE-managed and hybrid-joined endpointsSupport and administer SSO integrations via ADFS, SAML, LDAP, and Entra-based federationLead or contribute to migration efforts from legacy ADFS to Azure-native authenticationWindows Hello for BusinessLead enterprise deployment and ongoing management of Windows Hello for BusinessEnforce biometric enrollment policies via GPO and Intune, scoped to eligible security groups and hardwareDevelop and deploy compliance monitoring and remediation scripts to inventory and validate authentication methods across endpointsMicrosoft 365 Platform AdministrationAdminister the enterprise M365 environment including Exchange Online, SharePoint, OneDrive, and TeamsManage M365 licensing, tenant configuration, and service health across commercial and GCC-High environmentsSupport Microsoft Purview sensitivity label management, data governance, and information protection policiesProvide M365 technical leadership during acquisition and divestiture activities including tenant migrations and data transitionsEnterprise PKI & Certificate ManagementImplement and administer CyberArk Venafi as the enterprise certificate lifecycle management platformManage certificate template creation, issuance, and decommissioning of legacy ADCS templatesIntegrate certificate lifecycle workflows with ServiceNow for automated request, approval, and trackingSecurity & Application GovernanceDesign and enforce browser extension governance frameworks including inventory, GPO controls, and ServiceNow-based approval workflowsManage Microsoft Store application control policies and enterprise software distribution securityAdminister CyberArk Workforce Password Management (WPM) at enterprise scaleSupport CMMC, NIST 800-171, and ITAR compliance requirements as they relate to identity and cloud infrastructureRespond to cybersecurity audits, questionnaires, and compliance inquiries related to identity and cloud platformsCollaboration Platform AdministrationAdminister Microsoft Teams and Slack at enterprise scale, including governance, lifecycle management, channel migration, and workspace consolidationEnforce naming conventions and manage workspace hygiene across collaboration platformsAutomation & ScriptingDevelop and maintain PowerShell and Python scripts to automate tasks across identity, cloud, and security domainsLeverage web APIs, reporting tools, and SQL-based queries for monitoring, reporting, and platform integrationDeploy automation and remediation scripts via Intune and endpoint management toolingAcquisition SupportProvide technical leadership for IT integration and separation projects including directory consolidation, tenant migrations, network transitions, and application cutoversCoordinate with internal teams, business leadership, and external partners throughout M&A activitiesJob Qualifications:Bachelor's degree in Computer Science, Information Technology, or a related field; equivalent work experience considered7–10 years of progressive experience in cloud infrastructure, identity management, or enterprise IT engineeringDemonstrated experience managing enterprise Microsoft cloud environments at scaleMicrosoft 365 administration — Exchange Online, SharePoint, OneDrive, Teams, licensing, and tenant managementMicrosoft Entra ID (Azure AD) and on-premises Active Directory configuration and administration in hybrid environmentsAzure cloud platform management including compute, networking, storage, and identity servicesWindows Server administration and Group Policy managementMulti-factor authentication technologies including Microsoft Authenticator, DUO, and FIDO2/Windows HelloCollaboration platform administration — Microsoft Teams and Slack governance at enterprise scaleProficiency in scripting and automation using PowerShell and/or PythonStrong understanding of enterprise security principles, identity governance, and Zero Trust architecturePreferred Qualifications:Experience with enterprise PKI infrastructure and certificate lifecycle management (ADCS, Venafi, or similar platforms)Hands-on experience with CyberArk products (Venafi, Workforce Password Management, or Privileged Access Manager)Familiarity with CMMC, NIST 800-171, or ITAR compliance requirements in an enterprise IT contextExperience with ServiceNow workflow integrationExposure to enterprise browser management and application governance (Microsoft Edge, Island Enterprise Browser, or similar)Experience supporting acquisition, divestiture, or tenant migration projectsRelevant certifications: Microsoft Certified: Identity and Access Administrator Associate, Azure Administrator Associate (AZ-104), Security+ , or equivalentExperience with GCC-High tenants and compliance requirements for defense-sector organizationsTeledyne and all of our employees are committed to conducting business with the highest ethical standards. We require all employees to comply with all applicable laws, regulations, rules and regulatory orders. Our reputation for honesty, integrity and high ethics is as important to us as our reputation for making innovative sensing solutions.Teledyne is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or veteran status, age, or any other characteristic or non-merit based factor made unlawful by federal, state, or local laws.