Lead IAM ENGINEER

Intone Networks
Salem, NH, United States
1 day ago

Role details

Contract type
Temporary contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours
Job source

Tech stack

Microsoft Windows Application Programming Interfaces (APIs) Application Integration Architecture User Authentication Cloud Computing Configuration Management Hardware Security Module Identity and Access Management Microsoft Security Essentials OAuth OpenID Windows PowerShell
+8 more
Openid Connect Azure Active Directory Phishing Security Assertion Markup Language (SAML) Systems Integration Enterprise Application Integration Enterprise Software Applications Microsoft InTune

Job description

This is a high-level role - looking for a Lead type candidate that also has some architecture/design experience.

  • Design and lead the enterprise rollout of Microsoft Entra passkey) support, including device-bound and synced passkey strategies.
  • Configure Authentication Methods policies to enable passkeys alongside existing MFA/authentication methods, sequenced with the legacy authentication method deprecation, 1. Microsoft Passkeys for Enterprise (Passwordless Authentication)
  • Design and lead the enterprise rollout of Microsoft Entra passkey support, including device-bound and synced passkey strategies.
  • Configure Authentication Methods policies to enable passkeys alongside existing MFA/authentication methods, sequenced with the legacy authentication method deprecation described in Section 2.
  • Define enrollment strategy for end users (self-service registration, Temporary Access Pass provisioning, admin-assisted enrollment for high-privilege accounts).
  • Evaluate compatibility across platforms (Windows Hello for Business, mobile authenticator apps, hardware security keys) and browser/device support matrices.
  • Partner with helpdesk/security awareness teams on rollout communications, training, and support escalation paths.
  • Monitor adoption metrics and authentication method usage reporting post-deployment.
  1. Deprecation of SMS and Voice Authentication (Phishing-Resistant MFA) * Retire SMS and voice call as permitted authentication methods tenant-wide, establishing phishing-resistant MFA as the enterprise standard. * Baseline current registration and usage of SMS and voice methods by user population, region, role, and device type. * Define and enforce Conditional Access Authentication Strengths to require phishing-resistant methods, with staged scoping that begins with privileged and high-risk accounts and expands to the full user base. * Build and govern the exception framework for populations where passkeys are not immediately viable. * Partner with the Global Service Desk to harden identity verification and account recovery procedures.

  2. Entra Conditional Access Policy Design & Management * Architect, build, and maintain Conditional Access policies governing sign-in risk, device compliance, location, application sensitivity, and user/group scoping. * Manage policy lifecycle using report-only mode, staged rollout, and What If tool validation prior to enforcement. * Design break-glass/emergency access account exclusions and safeguards to prevent tenant lockout. * Integrate Conditional Access with device compliance (Intune), session controls (Conditional Access App Control), sign-in risk (Entra ID Protection), and Global Secure Access, where applicable. * Continuously review and optimize policies to reduce gaps, redundant rules, and conflicting conditions across a large, distributed policy set. * Document policy intent, scope, and exceptions for audit and compliance purposes.

  3. Enterprise Application Permissions & Integrations * Review, govern, and remediate OAuth/OpenID Connect and SAML application permissions across the enterprise application portfolio. * Assess delegated vs. application permissions requested by first- and third-party apps; apply least-privilege principles and admin consent workflows. * Configure and maintain admin consent policies, permission classifications, and periodic access reviews for enterprise applications. * Support integration of enterprise SaaS applications via SSO (SAML/OIDC), provisioning (SCIM), and federation, coordinating with application owners and vendors. * Identify and remediate risky or over-privileged application grants (e.g., via Entra ID reporting or Defender for Cloud Apps). * Maintain an accurate inventory/catalog of enterprise applications, owners, and permission scopes.

Requirements

  • Must have enterprise level experience - multi-region environments with 5,000+ identities, or in highly regulated enterprises., We are seeking an experienced Microsoft Identity Management contractor to design, implement, and harden identity security controls across a global enterprise tenant. This role is hands-on and delivery-focused, covering enterprise passkey deployment, the retirement of SMS and voice authentication in favor of phishing-resistant MFA, Conditional Access policy engineering, application integration governance, and identity risk detection. The ideal candidate has deep, current expertise in the Microsoft Entra ID platform and is comfortable operating in a large, multi-region enterprise with strict compliance and change-management requirements., * 5+ years of hands-on experience administering Microsoft Entra ID (Azure AD) in an enterprise environment.
  • Demonstrated experience leading an organization-wide passkey/FIDO2 rollout to full production at enterprise scale, including Windows Hello for Business, with direct ownership of enrollment campaigns and accountability for adoption outcomes.
  • Demonstrated experience retiring legacy authentication methods (SMS, voice, password-only) in a production tenant.
  • Strong working knowledge of Conditional Access policy design, testing, and staged enforcement in complex, multi-region tenants.
  • Practical experience with enterprise application integration (SSO, SAML/OIDC, SCIM provisioning) and OAuth permission governance.
  • Experience managing App Registration lifecycle and enterprise application security standards.
  • Proficiency with Entra ID Protection, including risk policy configuration and investigation workflows.
  • Proficiency with PowerShell and the Microsoft Graph API for identity automation, bulk migration operations, and adoption/compliance reporting at scale.
  • Familiarity with related Microsoft security tooling (Microsoft Defender for Cloud Apps, Microsoft Purview, Intune) as they intersect with identity controls.
  • Strong understanding of enterprise change management, documentation, and compliance/audit expectations.
  • Excellent communication skills for cross-functional coordination (security, helpdesk, application owners, compliance)., * Microsoft certifications such as SC-300 (Identity and Access Administrator) or equivalent.
  • Prior experience in large, multi-region environments with 5,000+ identities, or in highly regulated enterprises.
  • Familiarity with hybrid identity (Entra Connect/Cloud Sync) and legacy AD-to-cloud migration considerations.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:35 min

Setting up passwordless federated identity configuring OpenID Connect patterns

Marcel Lupo · LIVE

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · WWC Europe 2026

1:29 min

Evaluating phishing emails that leverage artificial time constraints

Mauro Verderosa · LIVE

1:20 min

Identifying multi-disciplinary talent for developer experience engineering roles

Hazal Mestci +1 · Coffee With Developers

2:22 min

Adapting OpenID Connect for decentralized data sharing

Adam Larter Adam Larter · WWC 2024

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · WWC Europe 2026

Videos

See all

Related articles

See all