IAM Engineer
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+2 more
Job description
The client is seeking an experienced IAM Engineer to lead enterprise-wide passkey and phishing-resistant MFA initiatives, harden Conditional Access policies, and govern application identity across a large global Microsoft Entra environment., Lead the enterprise rollout of Microsoft Entra passkeys and FIDO2, migrating users away from SMS, voice, and other legacy authentication methods. Build and execute the passkey enrollment strategy, covering Windows Hello for Business, Microsoft Authenticator, hardware security keys, and Temporary Access Pass (TAP). Design, test, stage, implement, and maintain Conditional Access policies, beginning with privileged and high-risk accounts before expanding org-wide. Review and secure enterprise applications and App Registrations within Entra, including OAuth/OIDC, SAML, SCIM, SSO, permissions, and lifecycle management. Monitor sign-in and user risk through Entra ID Protection, investigate potentially compromised identities, and drive remediation. Automate bulk changes, reporting, and migration activities using PowerShell and Microsoft Graph API. Partner with the SOC, help desk, application owners, developers, compliance, and leadership teams, and produce documentation on authentication adoption, Conditional Access, and identity risk.
Requirements
5 years of hands-on Microsoft Entra ID/Azure AD experience in an enterprise environment. Demonstrated end-to-end passkey/FIDO2 implementation experience taken into full production, not limited to a pilot or POC. Deep Conditional Access experience, including designing, testing, staging, implementing, troubleshooting, and optimizing policies. Enterprise application integration experience with SSO, SAML, OIDC/OAuth, and SCIM, with strong App Registration and least-privilege permissions governance. Hands-on Entra ID Protection experience covering sign-in risk, user risk, compromised identities, and remediation workflows. Strong PowerShell and Microsoft Graph API skills for identity automation, large-scale changes, and reporting. Strong communication skills with the ability to collaborate across security, engineering, compliance, and business stakeholders in a formal change-management environment.
Preferred Qualifications: Microsoft SC-300: Identity and Access Administrator certification. Experience supporting 5,000 identities in a global or multi-region Microsoft tenant. Experience with Entra Connect/Cloud Sync and legacy Active Directory-to-cloud migrations. Familiarity with Microsoft Intune for device-based identity controls. Exposure to Microsoft Defender for Cloud Apps, Microsoft Purview, or Global Secure Access. Experience designing formal identity governance frameworks, audit documentation, and compliance reporting. Prior work in a highly regulated enterprise environment. *, 5 years of hands-on Microsoft Entra ID/Azure AD experience in an enterprise environment. Demonstrated end-to-end passkey/FIDO2 implementation experience taken into full production, not limited to a pilot or POC. Deep Conditional Access experience, including designing, testing, staging, implementing, troubleshooting, and optimizing policies. Enterprise application integration experience with SSO, SAML, OIDC/OAuth, and SCIM, with strong App Registration and least-privilege permissions governance. Hands-on Entra ID Protection experience covering sign-in risk, user risk, compromised identities, and remediation workflows. Strong PowerShell and Microsoft Graph API skills for identity automation, large-scale changes, and reporting. Strong communication skills with the ability to collaborate across security, engineering, compliance, and business stakeholders in a formal change-management environment.
Preferred Qualifications: Microsoft SC-300: Identity and Access Administrator certification. Experience supporting 5,000 identities in a global or multi-region Microsoft tenant. Experience with Entra Connect/Cloud Sync and legacy Active Directory-to-cloud migrations. Familiarity with Microsoft Intune for device-based identity controls. Exposure to Microsoft Defender for Cloud Apps, Microsoft Purview, or Global Secure Access. Experience designing formal identity governance frameworks, audit documentation, and compliance reporting. Prior work in a highly regulated enterprise environment.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again
Fully Remote Software Engineer Jobs
Where To Find Software Engineering Jobs