Principal Authentication Services Engineer

3M

Remote

Quick summary

Work type
Remote
Location
Remote
Salary
$145,676–$178,049 / yr
Posted
46 days ago

Market check

Salary context

Competitive pay

How this pay compares to similar roles

Similar $171k
This role $162k
$119k most similar roles pay here $227k

This role pays less than 58% of similar roles. Most pay $142,450–$200,437 — the shaded band above. At the midpoint, this role pays about $162k versus about $171k for comparable roles.

Based on 240 similar postings.

Employer

About 3M

3M is a diversified technology and manufacturing conglomerate producing thousands of products across healthcare, safety, electronics, transportation, and consumer goods. Industry: Diversified Manufacturing

3M currently has 44 open roles on FindRole.

Listed pay typically runs $145,676–$178,049 across 38 roles with salary data.

Most-posted roles

View all roles at 3M

At a glance

TL;DR · Principal Authentication Services Engineer

The Principal Authentication Services Engineer is a senior technical leader in the Identity & Access Management team, responsible for architecting and managing enterprise authentication platforms including Microsoft Entra ID and Active Directory. This role involves designing SSO integrations using modern protocols like SAML, OIDC, and OAuth 2.0, developing MFA policies, and leading Conditional Access policy governance. The engineer will also evaluate emerging technologies to inform the IAM roadmap and collaborate with security teams to ensure alignment with Zero Trust principles. Key skills include extensive experience in enterprise IAM solutions, modern authentication protocols, and architectural leadership in complex environments. This role requires a deep understanding of SaaS, on-premises, and hybrid application portfolios, as well as expertise in FIDO2 and Windows Hello for Business.

What you'll do

  • Own the engineering design and operational health of Microsoft Entra ID, Active Directory, and federated identity services.
  • Architect SSO integrations using SAML, OIDC, OAuth 2.0 for various application portfolios.
  • Manage MFA policies and phishing-resistant credential configurations like FIDO2 and Windows Hello.
  • Lead Conditional Access policy development and lifecycle governance across the enterprise.
  • Evaluate emerging authentication technologies to inform IAM roadmap decisions.

What we're looking for

  • Eight years of experience in designing, deploying, and managing enterprise IAM authentication solutions.
  • Five years of expertise working with modern authentication protocols like SAML, OAuth 2.0, OIDC, and FIDO2.
  • Five years of leadership in complex architectural initiatives, conditional access hardening, or Zero Trust security programs.
  • Ownership of engineering design, implementation, and operational health of Microsoft Entra ID, Active Directory, and federated identity services.
  • Architecting SSO integrations across SaaS, on-premises, and hybrid application portfolios using modern protocols.
  • Leading Conditional Access policy development, testing, and lifecycle governance.

More like this

Similar roles

Principal Information Security Engineer, Identity Security Engineering

JLL (Jones Lang LaSalle)

Remote (TX) 18 days ago $270,000$300,000
Okta CyberArk Active Directory M365 ISO NIST ATT&CK CIAM Zero Trust Privileged Access Management Identity Security Cloud Services SaaS On-premises Appliances Security Policy Compliance Network Security Application Development Teams Security Frameworks
Remote

Principal Application Security Engineer

Upstart

Remote (San Mateo, CA) 143 days ago $190,600$263,900
Java Python Ruby SAST DAST SCA CI/CD API Security Microservices REST GraphQL AWS Kubernetes Terraform GitLab Jenkins GitHub PostgreSQL MongoDB OAuth OpenID Connect OAuth2 JSON Web Tokens PCI DSS ISO 27001 NIST Cybersecurity Framework
Remote

Principal Security Engineer

Zillow

Remote (Remote-Usa, US) 29 days ago $168,600$269,400
AWS GCP Azure Python Threat Modeling Secure Design Reviews Penetration Testing AI Security Data Protection Identity Management Networking Model Abuse Detection Prompt-Based Attacks Unintended System Behavior CI/CD Cloud-Native Security LLM-Enabled Systems
Remote

Principal Engineer - Security Architecture

Target

Remote (7000 Target Pkwy N,Ncd-0375 Brooklyn Park,Mn 55445, US) 3 days ago $168,000$303,000
GCP Kubernetes Python Go Java Cryptography NIST ISO/IEC 27001 CI/CD Docker Terraform AWS Azure SIEM Firewalls IDS/IPS DLP Cloud Armor VPC Service Controls Organization constraints OPA Rego Vertex AI SCC Wiz
Remote Hybrid

Sr. Principal Systems Security Engineer

Northrop Grumman

Vadu01 115 days ago $156,400$234,600
CI/CD NIST 800-53 OWASP Top 10 Risk Management Framework Splunk Python DevOps Agile Cloud Security Event Monitoring Java C C++ Kubernetes AWS Azure GCP Terraform

Principal Information Systems Security Engineer

Leidos

5946 Undisclosed Md Customer Site 21090 39 days ago $154,050$278,475
RMF Risk_Mgmt_Framework NIST_SP_800_Series CNSSI_1253 DoD_8500 Zero_Trust Cloud_Computing CISSP network_security system_security_engineering security_monitoring incident_response