Senior Systems Engineer
Description
Central Technology is the force multiplier, accelerating creative opportunity and progress at EA. We're a world-class community of technologists, innovators, strategists, and orchestrators transforming interactive entertainment. Together, we power the platforms, AI-driven tools, live services, and infrastructure that ensure global scale, secure player experiences, and unlock bold new possibilities.
EA Information Technology (EAIT) powers the technology that connects our global workforce and supports every part of our business, from game development to marketing, publishing, security, and player experience. We create secure, scalable solutions that help teams collaborate and innovate in order to create better experiences for players worldwide.
Role Summary
We are looking for an experienced Senior Systems Engineer with deep expertise in both Identity & Access Management (IAM) and Windows Systems Administration to join our Identity Security Operations and Delivery team. You will lead the operations and delivery of enterprise identity solutions, with a primary focus on Microsoft Entra ID and our global hybrid Active Directory deployment. This is a senior operations role where you will secure human and non-human identities, enable enterprise identity lifecycle management, configure application single sign-on and provisioning, enable a Zero Trust security posture, support passwordless (FIDO2) authenticator deployment, and manage complex system integrations. You will be working closely with security, application, and infrastructure stakeholders, reporting to a manager based in Vancouver, Canada. You will be part of EA's IT Security team, within EAIT Global Infrastructure Services.
Location - Vancouver (Hybrid - 3 days)
Responsibilities:
You are a team player who will complete project deliverables, lead troubleshooting sessions, resolve escalated incidents from our support partners, fulfil service requests, implement changes, identify improvements, and prepare documentation.
You will design and deliver end-to-end SSO integrations using SAML 2.0, OpenID Connect (OIDC), and OAuth 2.0 across Entra ID and Okta.
You will Implement and manage SCIM provisioning for SaaS applications, including licensing optimization and deprovisioning hygiene.
You will secure both human and non-human identities, including service accounts, Agentic AI and Application Secrets, through modern authentication protocols.
You will define and maintain authorization models including role-based access control (RBAC), birth right application/groups and nested group strategies.
You will automate identity operations and administration using scripting (eg. Python, PowerShell) and platform APIs (Microsoft Graph).
You will support a hybrid multi-forest Microsoft AD infrastructure, including Windows Server domain controllers and PKI infrastructure, and Entra administration.
You will maintain the identity security posture—identifying and remediating over-privileged access, orphaned accounts, and configuration drift.
Qualifications:
10+ years of IT experience, with 5+ years specializing in Identity & Access Management.
Deep, hands-on expertise with Microsoft Entra ID - Conditional Access, application registrations, enterprise applications, dynamic groups, and identity governance features.
Expert understanding of core IAM protocols: SAML 2.0, OpenID Connect, OAuth 2.0, and SCIM, as well as FIDO2.
Practical experience implementing Zero Trust architectures and passwordless/phishing-resistant authentication.
Scripting and automation ability (Python and/or PowerShell) using platform APIs.
3+ years experience administrating cloud infrastructure in AWS or Azure. (Including familiarity with infrastructure as code, Azure Virtual Desktop, Azure Hybrid AD join, AWS ALB and Route 53, IAM roles, KMS and Certificate manager)
Experience administrating Microsoft Windows Server / Active Directory, PKI and related technologies.
Familiarity with enterprise networking concepts including firewalls, application proxies, load balancers, VPN, the TCP/IP protocol, and other enterprise network technologies.
Bachelor's degree in computer science or information technology with Microsoft SC-300 (Identity & Access Administrator); or equivalent practical experience.
Pay Transparency - North America
