> Markdown version of [/jobs/ext/2425205-cloud-engineer](https://www.wearedevelopers.com/jobs/ext/2425205-cloud-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cloud Engineer - **Company:** TRYFACTA, INC. - **Location:** San Francisco, CA, United States (Remote available) - **Contract:** Temporary contract - **Skills:** Microsoft Access, Microsoft Windows, Application Programming Interfaces (APIs), Amazon Web Services, User Authentication, Microsoft Azure, Microsoft Online Services, C Sharp (Programming Language), Software as a Service, Cloud Computing, Continuous Integration, DevOps, Multi-Factor Authentication, Identity and Access Management, OAuth, Windows PowerShell, Openid Connect, Azure Active Directory, Zero Trust Network Access, Security Assertion Markup Language (SAML), Single Sign-On, Web Applications, Scripting, Google Cloud, Microsoft Power Automate, Azure Powershell, Customer Identity Access Management, Restful APIs, Serverless Computing, Web Api - **Published:** August 31, 2026 - **Apply:** https://www.dice.com/job-detail/8af7076c-2ebd-403a-8064-71365c1ff0f6 ## About the Role * Strong experience with Microsoft Entra ID / Azure AD architecture and administration. * Proficiency in PowerShell scripting, Microsoft Graph API, and REST APIs. * Knowledge of OAuth 2.0, OpenID Connect, SAML, and SCIM protocols. * Experience with Conditional Access, MFA, and Identity Governance. * Familiarity with Azure AD Connect, Hybrid Identity, and Single Sign-On (SSO). * Understanding of Zero Trust principles and modern authentication methods., * Microsoft certifications such as SC-300 (Identity and Access Administrator) or AZ-104 (Azure Administrator). * Experience with Azure Functions, Logic Apps, or Power Automate for workflow automation. * Background in security compliance frameworks (e.g., ISO 27001, NIST). * Soft Skills & Leadership: + Translate business requirements into secure identity solutions + Communicate complex identity concepts to non-technical stakeholders + Drive identity modernization initiatives + Ability to partner with: + Cloud solution architects + DBAs + DevOps + Infrastructure admins * Azure AD B2C / External Identities (CIAM) * Cross-cloud identity (AWS, Google Cloud Platform federation) * Identity-related incident response * Strong problem-solving and analytical skills. * Excellent communication and collaboration abilities. * Ability to work in a fast-paced, dynamic environment. * Certifications: * Microsoft Identity and Access Administrator * Azure Solutions Architect * Security-focused certifications ## Description * Design and document scalable Azure Entra ID tenant topologies, including multi-organization frameworks and external B2B/B2C collaboration structures. * Establish and enforce enterprise-wide identity standards, architecture guardrails, and naming conventions across all business units and branches. * Architect and manage secure deployment matrices for workload identities, including Service Principals, Managed Identities, and application registrations. 2 Security, Authentication & Zero Trust Implementation * Configure and deploy a comprehensive Conditional Access policy suite tailored to role-based risks and user sign-in risk levels. * Implement and scale passwordless authentication mechanisms across the enterprise, including FIDO2 security keys, Passkeys, and Windows Hello for Business. * Deploy and tune Identity Protection policies to enable automated risk-based authentication and real-time remediation of compromised accounts. * Establish secure lifecycle management and automated rotation frameworks for cryptographic keys, certificates, and application secrets. 3 Identity Governance & Lifecycle Automation * Build and automate end-to-end Joiner, Mover, and Leaver (JML) user lifecycle workflows utilizing Microsoft Graph API, PowerShell, and Azure Functions. * Engineer self-service entitlement management catalogs and automate compliance-driven access reviews using Azure Logic Apps. * Formulate and enforce lifecycle governance policies for guest access, external partners, and B2B user permissions. 4 Application & API Integration * Integrate and onboard SaaS, on-premises, and custom-developed applications (.NET/C#) using standard OAuth 2.0, OpenID Connect, and SAML 2.0 protocols. * Configure custom token issuance, claims mapping, and MSAL-based authentication across single-page apps, web apps, and web APIs. * Develop and execute custom authentication extensions to dynamically inject external claims or modify default authentication flows. 5 Automation, Scripting & DevOps (CI/CD) * Integrate identity configurations and policy changes into automated CI/CD pipelines to achieve Identity-as-Code (IaC). * Write and maintain clean, reusable script libraries using PowerShell, Azure CLI, and Microsoft Graph SDKs to automate repetitive identity workflows. 6 Compliance, Risk Management & Operations * Align and map Entra ID technical controls to regulatory frameworks, including NIST, FedRAMP, SOC 2, and ISO 27001. * Compile and deliver structured audit evidence packages to demonstrate the compliance and efficacy of identity controls. * Author technical runbooks for operational teams to streamline the monitoring, troubleshooting, and optimization of complex token and authentication flows. 7 Cross-Functional Leadership & Enablement * Translate complex business and compliance requirements into comprehensive Technical Design Documents (TDD). * Collaborate with security, application, DevOps, and infrastructure teams to drive enterprise-wide identity modernization initiatives. * Communicate high-level identity strategies and risk profiles effectively to non-technical stakeholders and executive leadership. To be considered for this position, you should have: [Skills, Education, or Experience] ## Related Videos - [Develop enterprise-ready applications for Microsoft Teams with Azure resources on modern web technologies](https://www.wearedevelopers.com/videos/187-develop-enterprise-ready-applications-for-microsoft-teams-with-azure-resources-on-modern-web-technologies) - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Web APIs you might not know about](https://www.wearedevelopers.com/videos/281-web-apis-you-might-not-know-about) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [Hacking MSSQL on Cloud. All of them. How I became sysadmin on Azure, AWS, GCP and Alibaba.](https://www.wearedevelopers.com/videos/100339-hacking-mssql-on-cloud-all-of-them-how-i-became-sysadmin-on-azure-aws-gcp-and-alibaba) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [7 Cloud Computing Trends Coming in 2025 for Developers](https://www.wearedevelopers.com/magazine/412-7-cloud-computing-trends-coming-in-2025-for-developers) - [Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence](https://www.wearedevelopers.com/magazine/736-best-us-ai-conferences-for-ctos-in-2026-build-vs-buy-vendor-evaluation-and-peer-intelligence) - [Everything a Developer Needs to Know About MCP with Neo4j](https://www.wearedevelopers.com/magazine/604-everything-a-developer-needs-to-know-about-mcp-with-neo4j) - [Navigating the AI Shift](https://www.wearedevelopers.com/magazine/629-navigating-the-ai-shift) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)