Sr Manager, IAM Authentication

Posted 2 Hours Ago
Be an Early Applicant
Hiring Remotely in New York, NY, USA
Remote or Hybrid
175K-210K Annually
Senior level
AdTech • Cloud • Digital Media • Information Technology • News + Entertainment • App development
NBCUniversal has a rich history of evolving the media and entertainment industry.
The Role
Lead technical and operational delivery of enterprise authentication services across multiple Entra ID tenants and federation platforms (Ping), governing MFA and SSO standards, driving automation, incident response, vendor management, and service reliability. Manage a team of engineers, report KPIs, partner with cybersecurity, architecture, application, and audit teams, and ensure secure, scalable, high-availability authentication for workforce and partner applications.
Summary Generated by Built In
Company Description
NBCUniversal is one of the world's leading media and entertainment companies. We create world-class content, which we distribute across our portfolio of film, television, and streaming, and bring to life through our global theme park destinations, consumer products, and experiences. We own and operate leading entertainment and news brands, including NBC, NBC News, NBC Sports, Telemundo, NBC Local Stations, Bravo, and Peacock, our premium ad-supported streaming service. We produce and distribute premier filmed entertainment and programming through our powerhouse film and television studios, including Universal Pictures, DreamWorks Animation, and Focus Features, and the four global television studios under the Universal Studio Group banner, and operate industry-leading theme parks and experiences around the world through Universal Destinations & Experiences, including Universal Orlando Resort, home to Universal Epic Universe, and Universal Studios Hollywood. NBCUniversal is a subsidiary of Comcast Corporation. Visit www.nbcuniversal.com for more information.
Our impact is rooted in improving the communities where our employees, customers, and audiences live and work. We have a rich tradition of giving back and ensuring our employees have the opportunity to serve their communities. We champion an inclusive culture and strive to attract and develop a talented workforce to create and deliver a wide range of content reflecting our world.
Job Description
As part of the Global Operations & Technology Engineering organization, the Identity & Access Management (IAM) team enables secure, seamless access to enterprise applications, data, and infrastructure across our businesses. We partner with business, technology, and cybersecurity teams to improve user experience, reduce risk, and meet regulatory and audit requirements through modern identity capabilities and strong access governance.
We are seeking a Senior Manager, IAM Authentication to provide technical and operational leadership for enterprise authentication services, including governance and operations across multiple Microsoft Entra ID tenants, Ping and Entra ID federation services, Multi-Factor Authentication (MFA), and Single Sign-On (SSO) for workforce and partner application ecosystems. This leader is accountable for delivering reliable, secure, and scalable authentication capabilities while enabling business agility and a consistent end-user sign-in experience.
This role partners closely with cybersecurity, infrastructure, endpoint engineering, application owners, and risk/audit stakeholders to establish operational objectives, policies, procedures, and work plans for authentication and federation services. The Senior Manager drives a secure-by-design authentication program, handles unforeseen issues and service disruptions with strong tactical decision-making, and applies influence to align stakeholders on desired outcomes while preserving relationships.
Responsibilities:
  • Influence and drive the roadmap and delivery for enterprise authentication services across multiple Microsoft Entra ID tenants, establishing operational objectives and work plans that ensure consistent security controls, lifecycle management, and service reliability.
  • Own and govern federation services, including PingFederate/PingOne components and Entra ID federation configurations, ensuring high availability, secure configuration baselines, certificate/key management, and resilient failover.
  • Establish and enforce MFA and SSO standards for enterprise applications, including onboarding patterns, authentication methods, step-up authentication, and user experience guardrails.
  • Partner with cybersecurity, architecture, and application teams to design and implement conditional access patterns, risk-based access decisions, and modern authentication protocols (e.g., SAML, OIDC/OAuth) where applicable.
  • Partner with IAM Operations, Architecture, and Software Development teams and leadership
  • Provide leadership and direction for day-to-day engineering: incident response, problem management, change management, release planning, maintenance windows, and service reliability objectives for authentication platforms.
  • Drive automation to remove friction from manual processes (e.g., application onboarding, federation configuration validation, certificate rotation, access policy deployment) and improve speed, quality, and traceability.
  • Manage vendor and partner relationships related to authentication and federation technologies; oversee the department budget for tools and services, including licensing and renewals, with an emphasis on operational effectiveness and measurable outcomes.
  • Lead and develop a high-performing team of 4 direct reports and multiple offshore-based staff members; set clear expectations, coach and mentor managers/engineers, conduct performance management, develop succession plans, and foster a culture of accountability, collaboration, and continuous improvement.
  • Develop and report KPIs and operational metrics (e.g., availability, authentication success rates, MFA adoption, onboarding lead time, incident trends) to management and stakeholders, providing clear status, risks, and mitigation plans.
  • Serve as an escalation point for authentication outages and high-severity security events; coordinate communications and remediation across technical and business stakeholders.
  • Experience partnering with risk, audit, and compliance teams to implement and evidence controls.
  • Perform other duties as assigned.

Qualifications
Basic Requirements:
  • Bachelor's degree or equivalent work experience.
  • 8+ years of experience in identity and access management, authentication engineering, or security engineering or architecture.
  • 3+ years of management experience leading technical teams delivering highly available services.
  • Understanding of Microsoft Entra ID (Azure AD), including multi-tenant/complex enterprise environments.
  • Understanding of federation services and SSO integrations (e.g., PingFederate/PingOne and/or comparable federation stacks) and common protocols (SAML 2.0, OIDC, OAuth 2.0).
  • Understanding of MFA methods and authentication assurance.
  • Demonstrated ability to communicate complex security and identity concepts to both technical and executive audiences and influence without direct authority.

Desired Characteristics:
  • Experience designing authentication architecture for large enterprises with multiple identity providers, complex tenant topologies, mergers/acquisitions, and hybrid dependencies.
  • Experience with Entra Conditional Access, Authentication Strengths, Identity Protection, and privileged access concepts (e.g., PAM, PIM) as they relate to securing authentication.
  • Strong background in service management and reliability practices (SRE concepts, SLIs/SLOs, capacity planning, disaster recovery testing).
  • Experience integrating authentication with endpoint/device trust signals and modern device management (e.g., Intune) to support phishing-resistant access patterns.
  • Familiarity with zero trust and least privilege frameworks and how they translate into authentication and access decisioning.
  • Experience building automation and deployment pipelines for identity configuration (e.g., infrastructure / configuration as code for policy and federation settings).
  • Relevant certifications preferred (e.g., CISSP, CISM, Microsoft identity/security certifications, or comparable).
  • Proven ability to develop talent, build cross-functional partnerships, and drive a positive security culture.

Additional Requirements:
  • Fully Remote: This position has been designated as fully remote, meaning that the position is expected to contribute from a non-NBCUniversal worksite, most commonly an employee's residence.

This position is eligible for company sponsored benefits, including medical, dental and vision insurance, 401(k), paid leave, tuition reimbursement, and a variety of other discounts and perks. Learn more about the benefits offered by NBCUniversal by visiting the Benefits page of the Careers website. Salary range: $175k - $210k (bonus eligible)
We are accepting applications for this position on an ongoing basis.
Additional Information
As part of our selection process, external candidates may be required to attend an in-person interview with an NBCUniversal employee at one of our locations prior to a hiring decision. NBCUniversal's policy is to provide equal employment opportunities to all applicants and employees without regard to race, color, religion, creed, gender, gender identity or expression, age, national origin or ancestry, citizenship, disability, sexual orientation, marital status, pregnancy, veteran status, membership in the uniformed services, genetic information, or any other basis protected by applicable law.
If you are a qualified individual with a disability or a disabled veteran, you have the right to request a reasonable accommodation if you are unable or limited in your ability to use or access nbcunicareers.com as a result of your disability. You can request reasonable accommodations by emailing [email protected].
For LA County and City Residents Only: NBCUniversal will consider for employment qualified applicants with criminal histories, or arrest or conviction records, in a manner consistent with relevant legal requirements, including the City of Los Angeles' Fair Chance Initiative For Hiring Ordinance, the Los Angeles County Fair Chance Ordinance for Employers, and the California Fair Chance Act, where applicable.

Skills Required

  • Bachelor's degree or equivalent work experience
  • 8+ years in identity and access management, authentication engineering, or security engineering/architecture
  • 3+ years management experience leading technical teams delivering highly available services
  • Understanding of Microsoft Entra ID (Azure AD) including multi-tenant/complex enterprise environments
  • Understanding of federation services and SSO integrations (e.g., PingFederate/PingOne or comparable) and protocol expertise
  • Knowledge of authentication protocols: SAML 2.0, OIDC, OAuth 2.0
  • Understanding of MFA methods and authentication assurance
  • Ability to communicate complex security and identity concepts to technical and executive audiences and influence without authority
  • Experience designing authentication architecture for large enterprises, multi-IdP and complex tenant topologies
  • Experience with Entra Conditional Access, Authentication Strengths, Identity Protection, and privileged access concepts (PAM, PIM)
  • Background in service management and reliability practices (SRE concepts, SLIs/SLOs, capacity planning, DR testing)
  • Experience integrating authentication with endpoint/device trust signals and device management (e.g., Intune)
  • Experience building automation and deployment pipelines for identity configuration (infrastructure/configuration as code for policy and federation settings)
  • Relevant certifications (CISSP, CISM, Microsoft identity/security certifications or comparable)
  • Proven ability to develop talent, build cross-functional partnerships, and drive positive security culture

What the Team is Saying

Naomi
Grander
Anne
Chris
Dora
Mike
Teela
Steve
Adriane T.
Tim M.
Janikaa J.
Gregory R.
Aaron M.
Gisele
Jesse T.
Noemi Cuin
Abel L.
Melisa C.
Rama Assaf-Smith
Peter Teitelbaum

NBCUniversal Compensation & Benefits Highlights

  • Healthcare Strength Health coverage includes medical, prescription, dental, vision, life and disability, with mental‑health resources, and many benefits start on day one. This breadth and early eligibility point to robust core healthcare support.
  • Parental & Family Support Paid parental leave is outlined at 16 weeks for a primary caregiver and 4 weeks for a non‑primary caregiver, alongside fertility, adoption, and caregiving programs. These offerings indicate strong support for family‑building and caregiving needs.
  • Leave & Time Off Breadth The U.S. time‑off framework includes vacation, company holidays, personal “myDays,” caregiving days, flexible sick time, and compassionate/bereavement leave. This structure provides substantial paid time away and flexibility across personal and family situations.

NBCUniversal Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: New York City, NY
68,000 Employees
Year Founded: 1912

What We Do

From film, television, news, theme parks, interactive media, and streaming, our people are at the center of it all. ​Here, we solve complex and business-critical problems. That’s why we’re looking for people to help us continue our evolution, imagining and delivering the most innovative and disruptive products and services through the latest tech advancements in the industry. ​ Here you can develop solutions. You’ll develop solutions that allow engineers to broadcast live TV from the comfort of their homes. These solutions will enable the use of our collection of hundreds of thousands of distinct intellectual properties across our film, television and streaming brands. Here you can transform. You’ll make decisions and solve complex problems by leveraging insights that come from data, building AI to help enable solutions to optimize every aspect of our content eco-system. Here you can build. You’ll build emerging immersive technologies that are used to power the broadcasts and streaming of global events like the Super Bowl and Olympics. You can create secure, elastic cloud-based services connecting parts of our global platform ecosystem that effect tens of millions of viewers, consumers and businesses that consume and love NBCUniversal’s content. And while you design, build and architect your career, we have the culture to make sure you’re supported. Here you can work and still live your best life! We’re leaders in our fields. We hire smart people and trust them to get the job done. We are never too busy to develop a fellow colleague. We understand our goals – or we ask. When we see something that needs doing – we do it. We make data-driven decisions. We fiercely believe in our talent and their growth. If you're ready to make an impact, here you can.

Why Work With Us

For us, it's more than just a work life. It's a daily passion. We take great pride in our legacy. We find fun in the challenge. We collaborate and inspire others. We're always creating, always solving and always ahead of competition.

Gallery

Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery

NBCUniversal Offices

Hybrid Workspace

Employees engage in a combination of remote and on-site work.

Typical time on-site: Flexible
Company Office Image
HQNew York, NY
Japan
Italy
Germany
China
France
Brazil
Australia
Toronto
Stamford, CT
Spain
Netherlands
Company Office Image
CA
Company Office Image
Dry Creek
Doraville, GA
Company Office Image
Telemundo Center
Singapore
Company Office Image
NBC Sports
Company Office Image
Torridge District, GB
Learn more

Similar Jobs

NBCUniversal Logo NBCUniversal

Associate Product Manager

AdTech • Cloud • Digital Media • Information Technology • News + Entertainment • App development
Remote or Hybrid
New York, NY, USA
68000 Employees
95K-115K Annually

NBCUniversal Logo NBCUniversal

Product Manager

AdTech • Cloud • Digital Media • Information Technology • News + Entertainment • App development
Remote or Hybrid
New York, NY, USA
68000 Employees
110K-145K Annually

NBCUniversal Logo NBCUniversal

Manager, Business Solutions

AdTech • Cloud • Digital Media • Information Technology • News + Entertainment • App development
Remote or Hybrid
New York, NY, USA
68000 Employees
135K-160K Annually

NBCUniversal Logo NBCUniversal

Senior Game Specialist

AdTech • Cloud • Digital Media • Information Technology • News + Entertainment • App development
Remote or Hybrid
New York, NY, USA
68000 Employees
130K-155K Annually

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account