Key Responsibilities
Define enterprise Microsoft Entra IAM security architecture, standards, reference architectures, design patterns, and engineering guardrails
Architect secure identity solutions across cloud, hybrid, multi-cloud, SaaS, and on-premises environments
Develop and implement identity-centric Zero Trust architecture emphasizing continuous verification, least privilege, strong authentication, and risk-based access
Design enterprise Conditional Access strategies covering users, administrators, workloads, applications, devices, authentication strength, and risk
Architect phishing-resistant and passwordless authentication solutions using FIDO2/passkeys, Windows Hello for Business, certificate-based authentication, and other supported authentication methods
Design and govern Privileged Identity Management (PIM) and privileged-access models to minimize standing administrative privileges and enforce just-in-time access
Establish security architecture for workload identities, managed identities, service principals, application registrations, API permissions, and secrets and certificate management
Architect secure application authentication and authorization using OAuth 2.0, OpenID Connect, SAML 2.0, SCIM, Microsoft Graph, and modern authentication patterns
Design Entra ID Governance capabilities, including entitlement management, access reviews, lifecycle workflows, separation of duties, and automated identity lifecycle controls
Define security architecture for joiner, mover, and leaver (JML) processes and ensure timely provisioning, modification, and removal of access
Design and review hybrid identity security, including Active Directory integration, Entra Connect/Cloud Sync, authentication flows, and protection of privileged identity paths
Lead IAM threat modeling and security architecture reviews for new applications, platforms, cloud services, and major technology initiatives
Identify identity-related attack paths, excessive privileges, legacy authentication dependencies, insecure application permissions, and other IAM security risks
Design controls for detecting and responding to identity compromise, credential theft, token abuse, risky sign-ins, privilege escalation, and unauthorized access
Define identity logging, monitoring, and alerting requirements and integrate Entra telemetry with SIEM/SOC and security operations processes
Provide architecture and engineering leadership for complex IAM implementations, migrations, integrations, and security remediation initiatives
Required Qualifications
9+ years of experience
Bachelors Degree
Skills
Microsoft Entra ID
Conditional Access
Passwordless Authentication
Privileged Identity Management
Workload Identities
Authentication Protocols
Entra ID Governance
Hybrid Identity
Identity Threat Detection and Response
SIEM Integration
Identity and Access Management Architecture
Zero Trust Architecture
Security Architecture Reviews
Threat Modeling
Identity Governance
Privileged Access Management
Technical Leadership
Cross-functional Collaboration
Security Operations Integration
Identity Risk Management
Schedule
Start date: 2026-10-19
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
- Dice Id: compun
- Position Id: KUMDC5943454
- Posted 7 hours ago