IAM Engineer
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+3 more
Job description
The client is seeking an experienced IAM Engineer to lead enterprise-wide passkey and phishing-resistant MFA initiatives, harden Conditional Access policies, and govern application identity across a large global Microsoft Entra environment., Lead the enterprise rollout of Microsoft Entra passkeys and FIDO2, migrating users away from SMS, voice, and other legacy authentication methods. Build and execute the passkey enrollment strategy, covering Windows Hello for Business, Microsoft Authenticator, hardware security keys, and Temporary Access Pass (TAP). Design, test, stage, implement, and maintain Conditional Access policies, beginning with privileged and high-risk accounts before expanding org-wide. Review and secure enterprise applications and App Registrations within Entra, including OAuth/OIDC, SAML, SCIM, SSO, permissions, and lifecycle management. Monitor sign-in and user risk through Entra ID Protection, investigate potentially compromised identities, and drive remediation. Automate bulk changes, reporting, and migration activities using PowerShell and Microsoft Graph API. Partner with the SOC, help desk, application owners, developers, compliance, and leadership teams, and produce documentation on authentication adoption, Conditional Access, and identity risk., Job Title: Infrastructure Security Engineer Location-Type: Remote with required travel (minimum monthly, travel expenses covered by the client), OR Local Hybrid, Charlotte, NC (onsite as needed) Start Date: ASAP Duration: Contract, 6 months, with poten…
Requirements
5 years of hands-on Microsoft Entra ID/Azure AD experience in an enterprise environment. Demonstrated end-to-end passkey/FIDO2 implementation experience taken into full production, not limited to a pilot or POC. Deep Conditional Access experience, including designing, testing, staging, implementing, troubleshooting, and optimizing policies. Enterprise application integration experience with SSO, SAML, OIDC/OAuth, and SCIM, with strong App Registration and least-privilege permissions governance. Hands-on Entra ID Protection experience covering sign-in risk, user risk, compromised identities, and remediation workflows. Strong PowerShell and Microsoft Graph API skills for identity automation, large-scale changes, and reporting. Strong communication skills with the ability to collaborate across security, engineering, compliance, and business stakeholders in a formal change-management environment.
Preferred Qualifications: Microsoft SC-300: Identity and Access Administrator certification. Experience supporting 5,000 identities in a global or multi-region Microsoft tenant. Experience with Entra Connect/Cloud Sync and legacy Active Directory-to-cloud migrations. Familiarity with Microsoft Intune for device-based identity controls. Exposure to Microsoft Defender for Cloud Apps, Microsoft Purview, or Global Secure Access. Experience designing formal identity governance frameworks, audit documentation, and compliance reporting. Prior work in a highly regulated enterprise environment. *, 5 years of hands-on Microsoft Entra ID/Azure AD experience in an enterprise environment. Demonstrated end-to-end passkey/FIDO2 implementation experience taken into full production, not limited to a pilot or POC. Deep Conditional Access experience, including designing, testing, staging, implementing, troubleshooting, and optimizing policies. Enterprise application integration experience with SSO, SAML, OIDC/OAuth, and SCIM, with strong App Registration and least-privilege permissions governance. Hands-on Entra ID Protection experience covering sign-in risk, user risk, compromised identities, and remediation workflows. Strong PowerShell and Microsoft Graph API skills for identity automation, large-scale changes, and reporting. Strong communication skills with the ability to collaborate across security, engineering, compliance, and business stakeholders in a formal change-management environment.
Preferred Qualifications: Microsoft SC-300: Identity and Access Administrator certification. Experience supporting 5,000 identities in a global or multi-region Microsoft tenant. Experience with Entra Connect/Cloud Sync and legacy Active Directory-to-cloud migrations. Familiarity with Microsoft Intune for device-based identity controls. Exposure to Microsoft Defender for Cloud Apps, Microsoft Purview, or Global Secure Access. Experience designing formal identity governance frameworks, audit documentation, and compliance reporting. Prior work in a highly regulated enterprise environment.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on mondo.gosnaphop.comGood distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence
Navigating the AI Shift
Fully Remote Software Engineer Jobs