> Markdown version of [/jobs/ext/2697317-iam-engineer](https://www.wearedevelopers.com/jobs/ext/2697317-iam-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # IAM Engineer - **Company:** Owings Mills Limited Partnership - **Location:** New York, NY, United States (Remote available) - **Experience:** Expert - **Salary:** $145,600.0 - $156,000.0 - **Contract:** Temporary to permanent - **Skills:** .NET Framework, Active Directory, Application Programming Interfaces (APIs), Cloud Computing, Marketing Information Systems, OAuth, OpenID, Windows PowerShell, Azure Active Directory, Security Assertion Markup Language (SAML), Single Sign-On, Enterprise Application Integration, Microsoft InTune, Cloud Migration - **Published:** September 3, 2026 - **Apply:** https://mondo.gosnaphop.com/jobs/l/login/c8336608-98ca-11ec-8029-42010a8a0008/68b7f40c-a789-11f1-8336-024201c20d84/false?applyId=565db6e2-a6cb-11f1-b939-02420a6c7775&apply=true&returnUrl=%2Fjobs%2Fl%2Frecruiting%2Fjobapplication%2F565db6e2-a6cb-11f1-b939-02420a6c7775%2F68b7f40c-a789-11f1-8336-024201c20d84%2Ffalse%3Fstep%3D1 ## About the Role 5 years of hands-on Microsoft Entra ID/Azure AD experience in an enterprise environment. Demonstrated end-to-end passkey/FIDO2 implementation experience taken into full production, not limited to a pilot or POC. Deep Conditional Access experience, including designing, testing, staging, implementing, troubleshooting, and optimizing policies. Enterprise application integration experience with SSO, SAML, OIDC/OAuth, and SCIM, with strong App Registration and least-privilege permissions governance. Hands-on Entra ID Protection experience covering sign-in risk, user risk, compromised identities, and remediation workflows. Strong PowerShell and Microsoft Graph API skills for identity automation, large-scale changes, and reporting. Strong communication skills with the ability to collaborate across security, engineering, compliance, and business stakeholders in a formal change-management environment. Preferred Qualifications: Microsoft SC-300: Identity and Access Administrator certification. Experience supporting 5,000 identities in a global or multi-region Microsoft tenant. Experience with Entra Connect/Cloud Sync and legacy Active Directory-to-cloud migrations. Familiarity with Microsoft Intune for device-based identity controls. Exposure to Microsoft Defender for Cloud Apps, Microsoft Purview, or Global Secure Access. Experience designing formal identity governance frameworks, audit documentation, and compliance reporting. Prior work in a highly regulated enterprise environment. *, 5 years of hands-on Microsoft Entra ID/Azure AD experience in an enterprise environment. Demonstrated end-to-end passkey/FIDO2 implementation experience taken into full production, not limited to a pilot or POC. Deep Conditional Access experience, including designing, testing, staging, implementing, troubleshooting, and optimizing policies. Enterprise application integration experience with SSO, SAML, OIDC/OAuth, and SCIM, with strong App Registration and least-privilege permissions governance. Hands-on Entra ID Protection experience covering sign-in risk, user risk, compromised identities, and remediation workflows. Strong PowerShell and Microsoft Graph API skills for identity automation, large-scale changes, and reporting. Strong communication skills with the ability to collaborate across security, engineering, compliance, and business stakeholders in a formal change-management environment. Preferred Qualifications: Microsoft SC-300: Identity and Access Administrator certification. Experience supporting 5,000 identities in a global or multi-region Microsoft tenant. Experience with Entra Connect/Cloud Sync and legacy Active Directory-to-cloud migrations. Familiarity with Microsoft Intune for device-based identity controls. Exposure to Microsoft Defender for Cloud Apps, Microsoft Purview, or Global Secure Access. Experience designing formal identity governance frameworks, audit documentation, and compliance reporting. Prior work in a highly regulated enterprise environment. ## Description The client is seeking an experienced IAM Engineer to lead enterprise-wide passkey and phishing-resistant MFA initiatives, harden Conditional Access policies, and govern application identity across a large global Microsoft Entra environment., Lead the enterprise rollout of Microsoft Entra passkeys and FIDO2, migrating users away from SMS, voice, and other legacy authentication methods. Build and execute the passkey enrollment strategy, covering Windows Hello for Business, Microsoft Authenticator, hardware security keys, and Temporary Access Pass (TAP). Design, test, stage, implement, and maintain Conditional Access policies, beginning with privileged and high-risk accounts before expanding org-wide. Review and secure enterprise applications and App Registrations within Entra, including OAuth/OIDC, SAML, SCIM, SSO, permissions, and lifecycle management. Monitor sign-in and user risk through Entra ID Protection, investigate potentially compromised identities, and drive remediation. Automate bulk changes, reporting, and migration activities using PowerShell and Microsoft Graph API. Partner with the SOC, help desk, application owners, developers, compliance, and leadership teams, and produce documentation on authentication adoption, Conditional Access, and identity risk. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Develop enterprise-ready applications for Microsoft Teams with Azure resources on modern web technologies](https://www.wearedevelopers.com/videos/187-develop-enterprise-ready-applications-for-microsoft-teams-with-azure-resources-on-modern-web-technologies) - [This Is Not Your Father's .NET](https://www.wearedevelopers.com/videos/967-this-is-not-your-father-s-net) - [Delegating the chores of authenticating users to Keycloak](https://www.wearedevelopers.com/videos/1558-delegating-the-chores-of-authenticating-users-to-keycloak) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) - [Hacking MSSQL on Cloud. All of them. How I became sysadmin on Azure, AWS, GCP and Alibaba.](https://www.wearedevelopers.com/videos/100339-hacking-mssql-on-cloud-all-of-them-how-i-became-sysadmin-on-azure-aws-gcp-and-alibaba) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Where To Find Software Engineering Jobs](https://www.wearedevelopers.com/magazine/396-where-to-find-software-engineering-jobs) - [What Makes WeAreDevelopers World Congress Different From Every Other Tech Event?](https://www.wearedevelopers.com/magazine/701-what-makes-wearedevelopers-world-congress-different-from-every-other-tech-event)