> Markdown version of [/jobs/ext/2027961-iam-engineer](https://www.wearedevelopers.com/jobs/ext/2027961-iam-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # IAM Engineer - **Company:** Generative Ai - **Location:** Salem, NH, United States (Remote available) - **Experience:** Expert - **Salary:** $145,600.0 - $156,000.0 - **Contract:** Temporary to permanent - **Skills:** Active Directory, Application Programming Interfaces (APIs), Microsoft Azure, Cloud Computing, DevOps, OAuth, OpenID, Windows PowerShell, Azure Active Directory, Security Assertion Markup Language (SAML), Single Sign-On, Enterprise Application Integration, Cloud Platform System, Microsoft InTune, Cloud Migration - **Published:** August 11, 2026 - **Apply:** https://mondo.gosnaphop.com/jobs/l/login/c8336608-98ca-11ec-8029-42010a8a0008/4162e8d2-9596-11f1-ae0d-024201c20d84/false?applyId=b4d6c6ff-9507-11f1-9509-02420a6c7775&apply=true&returnUrl=%2Fjobs%2Fl%2Frecruiting%2Fjobapplication%2Fb4d6c6ff-9507-11f1-9509-02420a6c7775%2F4162e8d2-9596-11f1-ae0d-024201c20d84%2Ffalse%3Fstep%3D1 ## About the Role 5 years of hands-on Microsoft Entra ID/Azure AD experience in an enterprise environment. Demonstrated end-to-end passkey/FIDO2 implementation experience taken into full production, not limited to a pilot or POC. Deep Conditional Access experience, including designing, testing, staging, implementing, troubleshooting, and optimizing policies. Enterprise application integration experience with SSO, SAML, OIDC/OAuth, and SCIM, with strong App Registration and least-privilege permissions governance. Hands-on Entra ID Protection experience covering sign-in risk, user risk, compromised identities, and remediation workflows. Strong PowerShell and Microsoft Graph API skills for identity automation, large-scale changes, and reporting. Strong communication skills with the ability to collaborate across security, engineering, compliance, and business stakeholders in a formal change-management environment. Preferred Qualifications: Microsoft SC-300: Identity and Access Administrator certification. Experience supporting 5,000 identities in a global or multi-region Microsoft tenant. Experience with Entra Connect/Cloud Sync and legacy Active Directory-to-cloud migrations. Familiarity with Microsoft Intune for device-based identity controls. Exposure to Microsoft Defender for Cloud Apps, Microsoft Purview, or Global Secure Access. Experience designing formal identity governance frameworks, audit documentation, and compliance reporting. Prior work in a highly regulated enterprise environment. *, 5 years of hands-on Microsoft Entra ID/Azure AD experience in an enterprise environment. Demonstrated end-to-end passkey/FIDO2 implementation experience taken into full production, not limited to a pilot or POC. Deep Conditional Access experience, including designing, testing, staging, implementing, troubleshooting, and optimizing policies. Enterprise application integration experience with SSO, SAML, OIDC/OAuth, and SCIM, with strong App Registration and least-privilege permissions governance. Hands-on Entra ID Protection experience covering sign-in risk, user risk, compromised identities, and remediation workflows. Strong PowerShell and Microsoft Graph API skills for identity automation, large-scale changes, and reporting. Strong communication skills with the ability to collaborate across security, engineering, compliance, and business stakeholders in a formal change-management environment. Preferred Qualifications: Microsoft SC-300: Identity and Access Administrator certification. Experience supporting 5,000 identities in a global or multi-region Microsoft tenant. Experience with Entra Connect/Cloud Sync and legacy Active Directory-to-cloud migrations. Familiarity with Microsoft Intune for device-based identity controls. Exposure to Microsoft Defender for Cloud Apps, Microsoft Purview, or Global Secure Access. Experience designing formal identity governance frameworks, audit documentation, and compliance reporting. Prior work in a highly regulated enterprise environment. ## Description The client is seeking an experienced IAM Engineer to lead enterprise-wide passkey and phishing-resistant MFA initiatives, harden Conditional Access policies, and govern application identity across a large global Microsoft Entra environment., Lead the enterprise rollout of Microsoft Entra passkeys and FIDO2, migrating users away from SMS, voice, and other legacy authentication methods. Build and execute the passkey enrollment strategy, covering Windows Hello for Business, Microsoft Authenticator, hardware security keys, and Temporary Access Pass (TAP). Design, test, stage, implement, and maintain Conditional Access policies, beginning with privileged and high-risk accounts before expanding org-wide. Review and secure enterprise applications and App Registrations within Entra, including OAuth/OIDC, SAML, SCIM, SSO, permissions, and lifecycle management. Monitor sign-in and user risk through Entra ID Protection, investigate potentially compromised identities, and drive remediation. Automate bulk changes, reporting, and migration activities using PowerShell and Microsoft Graph API. Partner with the SOC, help desk, application owners, developers, compliance, and leadership teams, and produce documentation on authentication adoption, Conditional Access, and identity risk., Job Title: Infrastructure Security Engineer Location-Type: Remote with required travel (minimum monthly, travel expenses covered by the client), OR Local Hybrid, Charlotte, NC (onsite as needed) Start Date: ASAP Duration: Contract, 6 months, with poten... ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [Develop enterprise-ready applications for Microsoft Teams with Azure resources on modern web technologies](https://www.wearedevelopers.com/videos/187-develop-enterprise-ready-applications-for-microsoft-teams-with-azure-resources-on-modern-web-technologies) - [Delegating the chores of authenticating users to Keycloak](https://www.wearedevelopers.com/videos/1558-delegating-the-chores-of-authenticating-users-to-keycloak) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence](https://www.wearedevelopers.com/magazine/736-best-us-ai-conferences-for-ctos-in-2026-build-vs-buy-vendor-evaluation-and-peer-intelligence) - [Navigating the AI Shift](https://www.wearedevelopers.com/magazine/629-navigating-the-ai-shift) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Got AI ideas but no money? Here are 10 free ways to level up your AI skills with Google Cloud](https://www.wearedevelopers.com/magazine/600-got-ai-ideas-but-no-money-here-are-10-free-ways-to-level-up-your-ai-skills-with-google-cloud)