Engineer - Microsoft Entra / Identity & Access Management (IAM)
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+18 more
Job description
The Senior Entra IAM Engineer is responsible for designing, implementing, securing, and supporting enterprise identity and access management solutions using Microsoft Entra ID (formerly Azure Active Directory) and related Microsoft identity technologies. The role serves as a senior technical resource for identity architecture, authentication, authorization, privileged access, application integration, and identity governance across cloud and hybrid environments.
The engineer works closely with cybersecurity, cloud/platform, infrastructure, application, and compliance teams to implement secure, scalable IAM solutions aligned with Zero Trust principles and organizational security requirements., * Design, implement, configure, and support Microsoft Entra ID solutions in complex enterprise environments.
- Engineer identity solutions involving SSO, MFA, passwordless authentication, Conditional Access, RBAC, and federation.
- Design and support hybrid identity environments using Entra Connect / Cloud Sync and on-premises Active Directory.
- Integrate SaaS, cloud, and enterprise applications with Entra ID using SAML 2.0, OAuth 2.0, OpenID Connect (OIDC), and SCIM.
- Implement and manage Entra ID Governance, including access reviews, entitlement management, lifecycle workflows, and identity lifecycle processes.
- Design and administer Privileged Identity Management (PIM) and privileged-access controls.
- Develop and maintain Conditional Access policies based on user, device, application, location, authentication strength, and risk.
- Support Entra ID Protection, identity risk detection, remediation, and security monitoring.
- Engineer identity lifecycle processes covering joiner, mover, and leaver (JML) scenarios.
- Troubleshoot complex authentication, authorization, federation, provisioning, synchronization, and application-access issues.
- Automate IAM administration and operational processes using PowerShell, Microsoft Graph API, REST APIs, and/or infrastructure-as-code approaches.
- Analyze sign-in, audit, provisioning, and security logs to identify and resolve identity-related incidents.
- Partner with security teams to implement Zero Trust and least-privilege access models.
- Develop technical designs, implementation plans, operational procedures, and engineering documentation.
- Participate in architecture and security reviews for applications requiring identity integration.
- Provide technical leadership and mentorship to junior and mid-level IAM engineers.
- Lead or provide senior technical support for IAM migrations, modernization initiatives, and production incidents.
Required Technical Skills
Strong hands-on experience should include:
- Microsoft Entra ID / Azure Active Directory
- Entra Conditional Access
- Multi-Factor Authentication (MFA)
- Passwordless authentication / FIDO2 / Windows Hello for Business
- Entra Privileged Identity Management (PIM)
- Entra ID Governance
- Entra ID Protection
- Enterprise Applications and App Registrations
- SSO and federation
- SAML 2.0, OAuth 2.0 and OpenID Connect
- SCIM provisioning
- Active Directory and hybrid identity
- Entra Connect / Cloud Sync
- Microsoft Graph API
- PowerShell automation
- RBAC and least-privilege access models
- Identity lifecycle management
- Authentication and provisioning troubleshooting
- Identity/security logging and monitoring
Requirements
- Approximately 5-8+ years of IAM or identity engineering experience, with significant hands-on Microsoft Entra experience.
- Experience supporting large-scale enterprise or multi-tenant environments.
- Experience migrating applications from legacy authentication/federation platforms to Entra ID.
- Understanding of Zero Trust architecture and identity-centric security.
- Experience integrating Entra with Microsoft 365, Azure, endpoint/device-management platforms, SIEM/SOC tooling, and third-party SaaS applications.
- Familiarity with broader IAM platforms such as SailPoint, Saviynt, Okta, CyberArk, Ping Identity, or similar technologies is beneficial.
- Experience operating within security and regulatory frameworks such as NIST, ISO 27001, SOC 2, PCI DSS, or similar environments.
Preferred Certifications
Relevant certifications may include Microsoft Certified: Identity and Access Administrator Associate (SC-300), Microsoft security certifications such as SC-100, Azure certifications, CISSP, or equivalent IAM/security credentials.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Where To Find Software Engineering Jobs
Top-Paying Tech Jobs (with Salaries)
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
Where to Find Entry-Level Software Engineering Jobs