IAM Engineer

Generative Ai
Salem, NH, United States
1 day ago

Role details

Contract type
Temporary to permanent
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$145,600.0 - $156,000.0
Working hours
Regular working hours

Tech stack

Active Directory Application Programming Interfaces (APIs) Microsoft Azure Cloud Computing DevOps OAuth OpenID Windows PowerShell Azure Active Directory Security Assertion Markup Language (SAML) Single Sign-On Enterprise Application Integration
+3 more
Cloud Platform System Microsoft InTune Cloud Migration

Job description

The client is seeking an experienced IAM Engineer to lead enterprise-wide passkey and phishing-resistant MFA initiatives, harden Conditional Access policies, and govern application identity across a large global Microsoft Entra environment., Lead the enterprise rollout of Microsoft Entra passkeys and FIDO2, migrating users away from SMS, voice, and other legacy authentication methods. Build and execute the passkey enrollment strategy, covering Windows Hello for Business, Microsoft Authenticator, hardware security keys, and Temporary Access Pass (TAP). Design, test, stage, implement, and maintain Conditional Access policies, beginning with privileged and high-risk accounts before expanding org-wide. Review and secure enterprise applications and App Registrations within Entra, including OAuth/OIDC, SAML, SCIM, SSO, permissions, and lifecycle management. Monitor sign-in and user risk through Entra ID Protection, investigate potentially compromised identities, and drive remediation. Automate bulk changes, reporting, and migration activities using PowerShell and Microsoft Graph API. Partner with the SOC, help desk, application owners, developers, compliance, and leadership teams, and produce documentation on authentication adoption, Conditional Access, and identity risk., Job Title: Infrastructure Security Engineer Location-Type: Remote with required travel (minimum monthly, travel expenses covered by the client), OR Local Hybrid, Charlotte, NC (onsite as needed) Start Date: ASAP Duration: Contract, 6 months, with poten…

Requirements

5 years of hands-on Microsoft Entra ID/Azure AD experience in an enterprise environment. Demonstrated end-to-end passkey/FIDO2 implementation experience taken into full production, not limited to a pilot or POC. Deep Conditional Access experience, including designing, testing, staging, implementing, troubleshooting, and optimizing policies. Enterprise application integration experience with SSO, SAML, OIDC/OAuth, and SCIM, with strong App Registration and least-privilege permissions governance. Hands-on Entra ID Protection experience covering sign-in risk, user risk, compromised identities, and remediation workflows. Strong PowerShell and Microsoft Graph API skills for identity automation, large-scale changes, and reporting. Strong communication skills with the ability to collaborate across security, engineering, compliance, and business stakeholders in a formal change-management environment.

Preferred Qualifications: Microsoft SC-300: Identity and Access Administrator certification. Experience supporting 5,000 identities in a global or multi-region Microsoft tenant. Experience with Entra Connect/Cloud Sync and legacy Active Directory-to-cloud migrations. Familiarity with Microsoft Intune for device-based identity controls. Exposure to Microsoft Defender for Cloud Apps, Microsoft Purview, or Global Secure Access. Experience designing formal identity governance frameworks, audit documentation, and compliance reporting. Prior work in a highly regulated enterprise environment. *, 5 years of hands-on Microsoft Entra ID/Azure AD experience in an enterprise environment. Demonstrated end-to-end passkey/FIDO2 implementation experience taken into full production, not limited to a pilot or POC. Deep Conditional Access experience, including designing, testing, staging, implementing, troubleshooting, and optimizing policies. Enterprise application integration experience with SSO, SAML, OIDC/OAuth, and SCIM, with strong App Registration and least-privilege permissions governance. Hands-on Entra ID Protection experience covering sign-in risk, user risk, compromised identities, and remediation workflows. Strong PowerShell and Microsoft Graph API skills for identity automation, large-scale changes, and reporting. Strong communication skills with the ability to collaborate across security, engineering, compliance, and business stakeholders in a formal change-management environment.

Preferred Qualifications: Microsoft SC-300: Identity and Access Administrator certification. Experience supporting 5,000 identities in a global or multi-region Microsoft tenant. Experience with Entra Connect/Cloud Sync and legacy Active Directory-to-cloud migrations. Familiarity with Microsoft Intune for device-based identity controls. Exposure to Microsoft Defender for Cloud Apps, Microsoft Purview, or Global Secure Access. Experience designing formal identity governance frameworks, audit documentation, and compliance reporting. Prior work in a highly regulated enterprise environment.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on mondo.gosnaphop.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:35 min

Setting up passwordless federated identity configuring OpenID Connect patterns

Marcel Lupo · LIVE

1:30 min

Operating developer-friendly identity infrastructure using Affinity Elements

Adam Larter Adam Larter · WWC 2024

2:17 min

Mapping the maturity roadmap for scaled devops adoption

Dominik Krichbaum Dominik Krichbaum · WWC Europe 2026

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · WWC Europe 2026

2:22 min

Adapting OpenID Connect for decentralized data sharing

Adam Larter Adam Larter · WWC 2024

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · WWC Europe 2026

Videos

See all

Related articles

See all