> Markdown version of [/jobs/ext/1945440-iam-engineer-microsoft-entra-specialist](https://www.wearedevelopers.com/jobs/ext/1945440-iam-engineer-microsoft-entra-specialist). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # IAM Engineer - Microsoft Entra Specialist - **Company:** Trebecon LLC - **Location:** Raleigh, NC, United States - **Experience:** Expert - **Contract:** Temporary to permanent - **Skills:** Microsoft Access, Application Programming Interfaces (APIs), User Authentication, Cloud Computing, Identity and Access Management, OAuth, OpenID, Windows PowerShell, Openid Connect, Azure Active Directory, Security Assertion Markup Language (SAML), Single Sign-On, Enterprise Software Applications, Microsoft InTune - **Published:** August 6, 2026 - **Apply:** https://www.dice.com/job-detail/f6315dbe-421c-4eff-9574-0937248405a9 ## About the Role * 5+ years of hands-on experience administering Microsoft Entra ID (Azure AD) in enterprise environments. * Proven experience leading enterprise-scale Passkey/FIDO2 or passwordless authentication deployments. * Experience decommissioning legacy authentication methods, including SMS, voice, and password-only authentication. * Strong expertise in Microsoft Entra Conditional Access policy design, testing, and staged deployment. * Hands-on experience with Microsoft Entra ID Protection. * Experience with Enterprise Applications, App Registrations, and permission governance. * Strong understanding of SSO, SAML, OpenID Connect (OIDC), OAuth, and SCIM provisioning. * Proficiency with PowerShell and Microsoft Graph API for identity automation. * Experience working in regulated enterprise environments with established compliance and change management processes. * Excellent communication and stakeholder management skills., * Microsoft SC-300 (Identity and Access Administrator) certification or equivalent. * Experience with Microsoft Intune, Microsoft Defender for Cloud Apps, and Microsoft Purview. * Experience with Hybrid Identity, Microsoft Entra Connect (Azure AD Connect), or Cloud Sync. * Experience supporting organizations with 5,000+ users across multiple regions. ## Description We are seeking an experienced Identity & Access Management (IAM) Engineer with deep expertise in Microsoft Entra ID (Azure AD) to support a large global enterprise. This role is ideal for a hands-on identity professional who has successfully delivered enterprise-scale authentication modernization initiatives, including passwordless authentication, Conditional Access, and identity security. The immediate priority is leading the rollout of Microsoft Passkeys and retiring legacy SMS and voice-based authentication methods while ensuring a seamless user experience and strong security posture., * Lead the enterprise deployment of Microsoft Passkeys and passwordless authentication. * Plan and execute the retirement of SMS, voice, and other legacy authentication methods. * Design, implement, and maintain Microsoft Entra Conditional Access policies. * Configure and manage Microsoft Entra ID Protection policies and investigate identity risks. * Administer Enterprise Applications, App Registrations, and application permissions. * Manage application integrations using SSO, SAML, OpenID Connect (OIDC), OAuth, and SCIM. * Develop automation and reporting solutions using PowerShell and Microsoft Graph API. * Partner with security, infrastructure, application, and compliance teams to strengthen identity governance. * Create documentation and follow enterprise change management and audit processes. * Support identity-related security initiatives across a global enterprise environment. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Delegating the chores of authenticating users to Keycloak](https://www.wearedevelopers.com/videos/1558-delegating-the-chores-of-authenticating-users-to-keycloak) - [Going Beyond Passwords: The Future of User Authentication](https://www.wearedevelopers.com/videos/714-going-beyond-passwords-the-future-of-user-authentication) - [Develop enterprise-ready applications for Microsoft Teams with Azure resources on modern web technologies](https://www.wearedevelopers.com/videos/187-develop-enterprise-ready-applications-for-microsoft-teams-with-azure-resources-on-modern-web-technologies) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Where To Find Software Engineering Jobs](https://www.wearedevelopers.com/magazine/396-where-to-find-software-engineering-jobs) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Everything a Developer Needs to Know About MCP with Neo4j](https://www.wearedevelopers.com/magazine/604-everything-a-developer-needs-to-know-about-mcp-with-neo4j) - [Where to Find Entry-Level Software Engineering Jobs](https://www.wearedevelopers.com/magazine/397-where-to-find-entry-level-software-engineering-jobs)