Principal Systems Engineer

Fidelity
Fidelity

Software Engineering

Durham, NC, USA

Posted on Aug 26, 2026

Job Description:

Note: Fidelity will not provide immigration sponsorship for this position.

Position Description:

Provides secure identity management services via Microsoft Entra ID (formerly Azure Active Directory) and Active Directory Domain Services according to Agile methodologies. Works in a combined engineering/operations DevOps model using toolsets -- Jenkins Core, GitHub, Graph Application Programming Interfaces (APIs), Domain Name System (DNS), DHCP, and Public Key Infrastructure (PKI) in a cloud environment (Microsoft Azure or Amazon Web Services (AWS)). Identifies and addresses security vulnerabilities by implementing solutions that protect the firm from external cyber threats. Uses business knowledge to translate the vision for divisional initiatives into business solutions by developing complex or multiple software applications and conducting studies of alternatives. Analyzes and recommends changes in project development policies, procedures, standards, and strategies to development experts and management.

Primary Responsibilities:

  • Crafts and coordinates authentication and authorization solutions in the environment, prioritizing resiliency.
  • Identifies anomalies in the enterprise by analyzing identity transactions and creates configuration guides in securing those transactions by enforcing controls.
  • Defines and leads enterprise-level systems architecture and strategy.
  • Develops and implements scalable infrastructure solutions.
  • Establishes observability standards for all supported applications.
  • Develops and enhances existing functionalities by supporting highly distributed multi-tiered systems at scale.
  • Develops, documents, and revises system design procedures, test procedures, and quality standards.
  • Collaborates with developers to test and push codes or packages out to production.
  • Advises senior leadership on systems engineering best practices.
  • Mentors junior engineers.
  • Performs independent and complex technical and functional analysis for multiple divisional initiatives.
  • Develops innovative solutions to support evolving infrastructure needs.

Education and Experience:

Bachelor’s degree in Computer Science, Engineering, Information Technology, Information Systems, or a closely related field (or foreign education equivalent) and five (5) years of experience as Principal Systems Engineer (or closely related occupation) designing, developing, and supporting Identity and Access Management (IAM) solutions for enterprise cybersecurity using Microsoft Entra ID within a financial services environment.

Or, alternatively, Master’s degree in Computer Science, Engineering, Information Technology, Information Systems, or a closely related field (or foreign education equivalent) and three (3) years of experience as a Principal Systems Engineer (or closely related occupation) designing, developing, and supporting Identity and Access Management (IAM) solutions for enterprise cybersecurity using Microsoft Entra ID within a financial services environment.

Skills and Knowledge:

Candidate must also possess:

  • Demonstrated Expertise (“DE”) deploying security controls to safeguard the enterprise from cyberattacks (using Microsoft Entra Conditional Access Policies, Microsoft Identity Protection, Microsoft Defender for Identity, Entra ID multifactor/biometric authentication, Windows Group Policy, and Microsoft Entra Password Protection); and providing operational support including infrastructure support, cloud enablement, platform engineering, environment management, and incident management.
  • DE identifying anomalies in Microsoft Entra ID, active directory test, and production environments, and performing workflow automations, using shell scripting (PowerShell, Kusto Query Language, and Python).
  • DE designing and deploying enterprise-grade Hybrid Identity sync engine, using Entra Connect infrastructure following secure deployment practices -- standby server configuration and comprehensive documentation.
  • DE setting up proactive monitoring using monitoring tools (System Center Operations Manager (SCOM), Splunk, Grafana, and Azure Monitor).

#PE1M2

#LI-DNI

Fidelity’s Onsite Working Model
Fidelity is transitioning to a full-time onsite working model through a phased rollout across regions and roles. Currently, some roles and locations require 100% onsite presence, while others require less. Onsite expectations are likely to evolve as the rollout continues. This transition does not apply to fully remote roles.

Certifications:

Category:

Information Technology

Please be advised that Fidelity’s business is governed by the provisions of the Securities Exchange Act of 1934, the Investment Advisers Act of 1940, the Investment Company Act of 1940, ERISA, numerous state laws governing securities, investment and retirement-related financial activities and the rules and regulations of numerous self-regulatory organizations, including FINRA, among others. Those laws and regulations may restrict Fidelity from hiring and/or associating with individuals with certain Criminal Histories.

Apply

All fields are required. Candidates should limit the number of roles they apply to at any given time.

Benefits that balance life and work

From our fully paid parent leave to our on-site health and wellness centers, our benefits support the belief that more balance you have, the better you can achieve your goals.

Benefits

Company overview

Company overview

At Fidelity, we are passionate about making our financial expertise broadly accessible and effective in helping people live the lives they want. We are a privately held company that places a high degree of value in creating and nurturing a work environment that attracts the best talent and reflects our commitment to our associates. We are proud of our diverse and inclusive workplace where we respect and value our associates for their unique perspectives and experience.

Reasonable accommodations

Fidelity will reasonably accommodate applicants with disabilities who need adjustments to participate in the application or interview process. To initiate a request for an accommodation contact the HR Accommodation Team by sending an email to accommodations@fmr.com, or by calling 800-835-5099, prompt 2, option 3.

Equal opportunity employer

Fidelity Investments is an equal opportunity employer. We believe that the most effective way to attract, develop, and retain a diverse workforce is to build an enduring culture of inclusion and belonging.

Applicant screening

At Fidelity, we value honesty, integrity, and the safety of our associates and customers within a heavily regulated industry. Certain roles may require candidates to go through a preliminary credit check during the screening process. Candidates who are presented with a Fidelity offer will need to go through a background investigation and may be asked to provide additional documentation as requested. This investigation includes but is not limited to a criminal, civil litigations and regulatory review, employment, education, and credit review (role dependent). These investigations will account for 7 years or more of history, depending on the role. Where permitted by federal or state law, Fidelity will also conduct a pre-employment drug screen, which will review for the following substances: Amphetamines, THC (marijuana), cocaine, opiates, phencyclidine.

Return to job search

Similar Jobs