Cloud Engineer


Tryfacta
Dice Job Match Score™
🔢 Crunching numbers...
Job Details
Skills
- Microsoft Entra ID
- Azure AD
- Identity and Access Management (IAM)
- PowerShell
- Microsoft Graph API
- REST APIs
- OAuth 2.0
- OpenID Connect
- SAML
- SCIM
- Conditional Access
- MFA
- Identity Governance
- Azure AD Connect
- Hybrid Identity
- Single Sign-On (SSO)
- Zero Trust
- Azure Functions
- Logic Apps
- Power Automate
- Azure B2C
- External Identities
- Identity Modernization
- Azure CLI
- Microsoft Graph SDK
- CI/CD
- Identity-as-Code
- NIST
- ISO 27001
- FedRAMP
- SOC 2
Summary
Tryfacta is a leading, nationally renowned Workforce Management Solution provider for private &public sector firms across the US. We specialize in Healthcare, IT, Business Support, and Professional & Craft/Light Industrial ecosystems.
Founded in March 1996, we have a presence in all 50 States. Tryfacta has Ranked number 1 as one of the fastest-growing companies by Inc. Magazine (Inc. 5000)!
Tryfacta is certified by the Joint Commission for Healthcare Staffing Services & has numerous ISO Certifications that capture our commitment to continuous improvement.
Position Title: Cloud Engineer
Location: San Francisco, CA 94102
Duration:
| Start Date of Assignment: | 10/1/2026 | ||
| Term (including any Option Terms): | Maximum Hours Per Term | |||
| Initial Term: | 10/01/2026 – 09/30/2027 | 1,976 | ||
| 1st Option Term: | 10/01/2027 – 09/30/2028 | 1,976 | ||
| 2nd Option Term: | 10/01/2028 – 09/30/2029 | 1,968 | ||
Work Schedule: This position is a remote position and will be onsite only when needed. The remote status of this position is subject to change if deemed necessary by the client.
- Tasks and Responsibilities to be Performed
| Task No. | Description of Tasks and Responsibilities for each Classification |
|---|---|
| 1 | Identity Architecture & Foundation • Design and document scalable Azure Entra ID tenant topologies, including multi-organization frameworks and external B2B/B2C collaboration structures. • Establish and enforce enterprise-wide identity standards, architecture guardrails, and naming conventions across all business units and branches. • Architect and manage secure deployment matrices for workload identities, including Service Principals, Managed Identities, and application registrations. |
| 2 | Security, Authentication & Zero Trust Implementation • Configure and deploy a comprehensive Conditional Access policy suite tailored to role-based risks and user sign-in risk levels. • Implement and scale passwordless authentication mechanisms across the enterprise, including FIDO2 security keys, Passkeys, and Windows Hello for Business. • Deploy and tune Identity Protection policies to enable automated risk-based authentication and real-time remediation of compromised accounts. • Establish secure lifecycle management and automated rotation frameworks for cryptographic keys, certificates, and application secrets. |
| 3 | Identity Governance & Lifecycle Automation • Build and automate end-to-end Joiner, Mover, and Leaver (JML) user lifecycle workflows utilizing Microsoft Graph API, PowerShell, and Azure Functions. • Engineer self-service entitlement management catalogs and automate compliance-driven access reviews using Azure Logic Apps. • Formulate and enforce lifecycle governance policies for guest access, external partners, and B2B user permissions. |
| 4 | Application & API Integration • Integrate and onboard SaaS, on-premises, and custom-developed applications (.NET/C#) using standard OAuth 2.0, OpenID Connect, and SAML 2.0 protocols. • Configure custom token issuance, claims mapping, and MSAL-based authentication across single-page apps, web apps, and web APIs. • Develop and execute custom authentication extensions to dynamically inject external claims or modify default authentication flows. |
| 5 | Automation, Scripting & DevOps (CI/CD) • Integrate identity configurations and policy changes into automated CI/CD pipelines to achieve Identity-as-Code (IaC). • Write and maintain clean, reusable script libraries using PowerShell, Azure CLI, and Microsoft Graph SDKs to automate repetitive identity workflows. |
| 6 | Compliance, Risk Management & Operations • Align and map Entra ID technical controls to regulatory frameworks, including NIST, FedRAMP, SOC 2, and ISO 27001. • Compile and deliver structured audit evidence packages to demonstrate the compliance and efficacy of identity controls. • Author technical runbooks for operational teams to streamline the monitoring, troubleshooting, and optimization of complex token and authentication flows. |
| 7 | Cross-Functional Leadership & Enablement * Translate complex business and compliance requirements into comprehensive Technical Design Documents (TDD). * Collaborate with security, application, DevOps, and infrastructure teams to drive enterprise-wide identity modernization initiatives. * Communicate high-level identity strategies and risk profiles effectively to non-technical stakeholders and executive leadership. |
To be considered for this position, you should have: [Skills, Education, or Experience]
- Strong experience with Microsoft Entra ID / Azure AD architecture and administration.
- Proficiency in PowerShell scripting, Microsoft Graph API, and REST APIs.
- Knowledge of OAuth 2.0, OpenID Connect, SAML, and SCIM protocols.
- Experience with Conditional Access, MFA, and Identity Governance.
- Familiarity with Azure AD Connect, Hybrid Identity, and Single Sign-On (SSO).
- Understanding of Zero Trust principles and modern authentication methods.
- Microsoft certifications such as SC-300 (Identity and Access Administrator) or AZ-104 (Azure Administrator).
- Experience with Azure Functions, Logic Apps, or Power Automate for workflow automation.
- Background in security compliance frameworks (e.g., ISO 27001, NIST).
- Soft Skills & Leadership:
- Translate business requirements into secure identity solutions
- Communicate complex identity concepts to non-technical stakeholders
- Drive identity modernization initiatives
- Ability to partner with:
- Cloud solution architects
- DBAs
- DevOps
- Infrastructure admins
- Azure AD B2C / External Identities (CIAM)
- Cross-cloud identity (AWS, Google Cloud Platform federation)
- Identity-related incident response
- Strong problem-solving and analytical skills.
- Excellent communication and collaboration abilities.
- Ability to work in a fast-paced, dynamic environment.
- Certifications:
- Microsoft Identity and Access Administrator
- Azure Solutions Architect
- Security-focused certifications
Tryfacta is an Equal Opportunity/Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, protected veteran or disabled status, or genetic information.
- Dice Id: 10107000
- Position Id: 26-04650
- Posted 1 hour ago
Company Info
At Tryfacta, our mission is to create opportunities for our clients, candidates, and our team members. As a Minority Owned Business Enterprise (MBE) with over 40 Diversity Certifications spanning 28 States, we are dedicated to supporting Staffing Programs and providing Tech and Business Advisory services to both the Private and Public sectors.
Our journey began in the late 1990s as a key player in the staffing industry, and we quickly expanded our expertise to include IT Consulting, with a specific focus on SAP Implementations. With over 26 years of experience, we have developed a robust business solutions model to tackle complex business challenges, consistently delivering services that surpass our clients' expectations.
At Tryfacta, our core values serve as a guiding compass, shaping our behavior and forming the foundation of our culture. These values drive our growth, foster our commitment to excellence, and enable us to serve our clients and stakeholders with character, entrepreneurship, respect, and a genuine desire to make a difference.
-p-1080.jpg%3Fformat%3Dwebp&w=1080&q=75)

Similar Jobs
It looks like there aren't any Similar Jobs for this job yet.
Search all similar jobs