Hello,
I have below exclusive position with my client. Please let me know your interest so that we can move ahead for further steps.
Job Title: Microsoft Entra Leader
Location: 100% Remote
Job Type: 06+ Months Contract
Responsibilities:
· Need a senior, hands-on Identity Implementation Lead who can take a complex identity program from detailed design through build, test, documentation, and handoff.
· Must be an engineer-practitioner, not strategy-only or portal-only.
· Core profile: 10–15 years IAM experience, with 5–7+ years deep Microsoft identity work and recent complex Entra implementations.
· Must be strong in:
o Entra tenant build, governance, Conditional Access, PIM, Identity Protection
o Hybrid identity and Entra Connect routing
o Cross-tenant access and synchronization
o Configuration-as-code with Git, Graph, CI/CD, drift detection, and testing
o Application identity, federation, and migration planning
o Delivery leadership, documentation, and customer enablement
· Non-negotiable technical skills:
o Greenfield Entra tenant design and production build
o Conditional Access design, rollout safety, and policy interaction testing
o Privileged access: FIDO2/passkeys, TAP, break-glass, PIM, admin identities
o Hybrid identity routing across tenants from a shared AD estate
o Graph-based automation and secure DevSecOps
o Enterprise app / federation patterns: SAML, OIDC, OAuth, WS-Fed, ADFS
o Logging, monitoring, audit, SIEM integration, and operational handoff
· Ideal work history:
o Built a production Entra tenant from scratch
o Led a multi-tenant identity program
o Implemented native cross-tenant sync
o Engineered Entra Connect routing and sync rules
o Delivered Graph-based config deployment through CI/CD
o Led a safe Conditional Access rollout
o Left behind tested automation, runbooks, and trained operators
· Must be able to:
o Explain architecture clearly
o Build directly in Entra, Graph, PowerShell, Git, CI/CD
o Sequence technical work and manage risk
o Pair with customer engineers and transfer ownership
· Strong differentiators:
o Large distributed or retail/franchise identity environments
o Microsoft365DSC / Terraform in addition to Graph
o Defender for Identity, LAPS, SIEM, Intune, Tanium
o GitHub Actions / Azure DevOps depth
o Relevant Microsoft certifications
· Interview should validate:
o Hands-on delivery history
o Safe Conditional Access rollout approach
o Hybrid identity routing knowledge
o Cross-tenant sync design
o Config-as-code / CI-CD design
o Application migration and coexistence experience
o Operational handoff and documentation quality
· Red flags:
o Mostly architecture/presales, not hands-on build work
o Portal-only CA knowledge
o Script-only automation without testing/drift control
o Weak understanding of Entra Connect routing and matching behavior.
o Treating guest access and cross-tenant sync as the same thing
o Overreliance on unsupported/beta features
o Weak documentation, testing, or handoff discipline
· Staffing expectation:
o One primary lead should own the core solution
o Adjacent specialist support is still needed for endpoints, security ops, DNS/certs, workload impacts, and technical writing