Sr Entra ID Integration Engineer

Washington, DC, US • Posted 1 hour ago • Updated 1 hour ago
Full Time
On-site
USD 130,000.00 per year
Fitment

Dice Job Match Score™

🔢 Crunching numbers...

Job Details

Skills

  • Telecommuting
  • Insurance
  • Network
  • DevSecOps
  • Migration
  • IT Management
  • Mentorship
  • Microsoft Windows
  • Brand
  • Real-time
  • Optimization
  • Leadership
  • PASS
  • System Integration
  • OIDC
  • Lifecycle Management
  • OAuth
  • API
  • Security Operations
  • Threat Analysis
  • SIEM
  • Analytics
  • Incident Management
  • Test Plans
  • Change Management
  • Authentication
  • Standard Operating Procedure
  • Knowledge Base
  • FISMA
  • FIPS
  • NIST SP 800 Series
  • OMB
  • System Security
  • SSP
  • Reporting
  • STIG
  • Vulnerability Management
  • Documentation
  • Auditing
  • Continuous Monitoring
  • Computer Science
  • Information Technology
  • Information Systems
  • Cloud Security
  • Active Directory
  • Cloud Computing
  • Cyber Security
  • Security Clearance
  • FedRAMP
  • Authorization
  • Security Controls
  • Microsoft Azure
  • Microsoft
  • Management
  • Enterprise Software
  • SSO
  • Access Control
  • Multi-factor Authentication
  • Regulatory Compliance
  • Evaluation
  • Identity Management
  • PIM
  • Provisioning
  • Workflow
  • Campaign Management
  • SAML
  • Military
  • Promotions
  • Agile
  • Professional Services
  • Operations Management
  • Partnership
  • Service Delivery
  • Continuous Improvement
  • Law

Summary

Koniag Data Solutions, a Koniag Government Services company, is seeking an experienced Entra ID Integration Engineer (Senior) to support enterprise identity and access management operations and IT administrative and operational support services for a federal government client. This position requires an active security clearance or the ability to obtain and maintain a government background investigation and all requisite IT access authorizations prior to performing work. Specific clearance requirements will be confirmed at time of offer. Primary work will be performed at the client site in Washington, DC and approved remote/telework locations.

We offer competitive compensation and an extraordinary benefits package including health, dental and vision insurance, 401K with company matching, flexible spending accounts, paid holidays, three weeks paid time off, and more.

This role serves as a critical senior technical function responsible for the architecture, engineering, implementation, administration, and continuous improvement of enterprise Microsoft Entra ID (formerly Azure Active Directory) identity and access management capabilities across a complex, geographically distributed federal IT environment spanning on-premises infrastructure, cloud platforms, hybrid environments, and enterprise applications.

The ideal candidate is a highly experienced and technically authoritative identity and access management engineer with deep, hands-on expertise across the full Microsoft Entra ID platform portfolio-including Entra ID tenant administration, Conditional Access, Privileged Identity Management (PIM), Identity Protection, External Identities, Entra ID Governance, and hybrid identity integration with on-premises Active Directory-combined with a comprehensive understanding of enterprise identity architecture, Zero Trust identity principles, and Federal cybersecurity compliance requirements. This individual must possess the technical depth, architectural vision, and operational discipline required to lead the design, implementation, and sustained operation of enterprise-grade Entra ID identity capabilities that protect Government identities, enforce least-privilege access, and support Zero Trust objectives in a highly regulated federal IT environment.

The Entra ID Integration Engineer (Senior) will serve as the program's primary subject matter expert and technical authority for all Microsoft Entra ID platform capabilities, leading the architecture, engineering, implementation, administration, and continuous improvement of enterprise identity and access management infrastructure. This individual works closely with security engineers, network engineers, cloud operations teams, Zero Trust engineers, DevSecOps engineers, application developers, and Government stakeholders to ensure Entra ID capabilities are architected, deployed, and operated in a manner that delivers maximum identity security, operational resilience, and compliance with Federal cybersecurity frameworks and Zero Trust Architecture objectives across the full enterprise environment.

Principal responsibilities will include but are not limited to:

Architecture & Engineering Leadership
  • Serve as the program's technical authority and subject matter expert for all Microsoft Entra ID platform capabilities, providing authoritative architectural guidance, engineering leadership, and expert technical recommendations to program leadership, functional teams, and Government stakeholders on identity architecture, access management strategy, and Zero Trust identity implementation.
  • Lead the design and architecture of enterprise Microsoft Entra ID identity solutions, including tenant architecture design, hybrid identity infrastructure, Conditional Access policy frameworks, Privileged Identity Management configurations, Identity Protection policies, and Entra ID Governance implementations aligned with Federal Zero Trust requirements and program security objectives.
  • Develop and maintain enterprise Entra ID architecture documentation, including identity architecture diagrams, authentication flow diagrams, Conditional Access policy frameworks, hybrid identity topology diagrams, and platform configuration baselines, ensuring documentation is current, accurate, and aligned with operational reality.
  • Lead identity architecture reviews for new systems, applications, cloud migrations, and infrastructure changes, assessing Entra ID platform impact, identifying identity security risks, and recommending configuration and policy improvements to maintain Zero Trust identity posture.
  • Design and implement Zero Trust identity architectures leveraging Microsoft Entra ID capabilities, including continuous access evaluation, risk-based Conditional Access, phishing-resistant MFA enforcement, identity risk detection, and least-privilege access governance.
  • Evaluate emerging Microsoft Entra ID platform capabilities, identity security industry developments, and Federal identity policy requirements, providing well-researched recommendations to program leadership and Government stakeholders on opportunities to enhance identity security and advance Zero Trust maturity.
  • Provide senior technical leadership and mentorship to junior and mid-level engineers, sharing identity and access management expertise, guiding technical development, and ensuring consistent application of identity engineering best practices across the team.

Entra ID Tenant Administration & Engineering
  • Lead the engineering, implementation, and administration of the enterprise Microsoft Entra ID tenant, ensuring the tenant is properly configured, secured, and continuously maintained in alignment with Federal security requirements, Microsoft security best practices, and applicable DISA STIGs and CIS Benchmarks.
  • Design and maintain the enterprise Entra ID tenant configuration, including directory settings, authentication methods, password policies, self-service password reset (SSPR) configurations, and security defaults enforcement in alignment with Zero Trust identity principles.
  • Implement and maintain enterprise Entra ID authentication method policies, ensuring phishing-resistant MFA-including FIDO2 security keys, Windows Hello for Business, and certificate-based authentication-is deployed, enforced, and operationally managed across all user populations.
  • Configure and maintain Entra ID domain configurations, custom domain registrations, and tenant branding settings, ensuring the tenant accurately represents the Government organization and supports seamless user authentication experiences.
  • Administer Entra ID directory objects, including user accounts, groups, administrative units, and service principals, ensuring accurate provisioning, lifecycle management, and deprovisioning in accordance with defined identity governance procedures.
  • Implement and maintain Entra ID group management policies, including dynamic group membership rules, group naming conventions, group lifecycle policies, and group-based access assignment configurations.
  • Monitor Entra ID tenant health, service availability, and operational metrics, proactively identifying and resolving tenant configuration issues, service disruptions, and security anomalies.

Conditional Access Engineering
  • Lead the design, implementation, and continuous optimization of the enterprise Conditional Access policy framework, ensuring all access to Government resources is continuously evaluated against defined trust signals and that access decisions enforce Zero Trust least-privilege principles.
  • Design and implement a comprehensive, well-structured Conditional Access policy architecture, including named locations, compliance requirements, sign-in risk policies, user risk policies, session controls, and application-specific access policies that collectively enforce granular, risk-based access control across the enterprise.
  • Implement and maintain phishing-resistant MFA enforcement policies, ensuring strong, unphishable authentication factors are required for all privileged access, high-value application access, and access from non-compliant or unmanaged devices.
  • Design and implement device compliance-based Conditional Access policies, integrating Microsoft Intune device compliance signals into access control decisions to enforce Zero Trust device trust requirements.
  • Implement and maintain sign-in risk and user risk-based Conditional Access policies, leveraging Entra ID Identity Protection risk signals to dynamically adjust authentication requirements and access restrictions based on detected identity risk.
  • Implement and maintain Continuous Access Evaluation (CAE) configurations, ensuring access tokens are continuously validated and revoked in near-real time when critical security events or policy changes are detected.
  • Manage Conditional Access policy lifecycle, including regular policy review and optimization cycles, policy documentation maintenance, exclusion management, and impact assessment for proposed policy changes.
  • Develop and maintain Conditional Access policy documentation, including policy specifications, decision matrices, exclusion registers, and impact assessment records, ensuring the policy framework is well-documented and auditable.

Privileged Identity Management (PIM) Engineering
  • Lead the engineering, implementation, and administration of Microsoft Entra ID Privileged Identity Management (PIM) capabilities, ensuring all privileged access to Azure resources, Entra ID roles, and enterprise applications is governed through just-in-time access provisioning, approval workflows, and continuous monitoring.
  • Design and implement PIM role assignment policies for all Entra ID directory roles and Azure resource roles, defining eligibility criteria, activation requirements, maximum activation durations, approval workflows, and justification requirements for each privileged role.
  • Configure and maintain PIM access review campaigns for all privileged role assignments, ensuring periodic certification of privileged access is conducted, documented, and enforced in alignment with least-privilege access governance requirements.
  • Implement and maintain PIM alert configurations, ensuring anomalous privileged access activities-including role activations outside business hours, repeated activation failures, and assignments outside PIM governance-are detected and escalated promptly.
  • Develop and maintain PIM operational documentation, including privileged role catalogs, activation procedure guides, and access review schedules, ensuring PIM governance processes are well-documented and consistently followed.

Identity Protection Engineering
  • Lead the engineering, implementation, and administration of Microsoft Entra ID Identity Protection capabilities, ensuring continuous detection, investigation, and remediation of identity-based threats across the enterprise user population.
  • Configure and maintain Identity Protection user risk and sign-in risk detection policies, ensuring high-risk identity events trigger appropriate automated remediation actions-including MFA challenges, password resets, and session termination-or are escalated for manual investigation.
  • Develop and maintain Identity Protection risk investigation workflows, ensuring security operations personnel have clear procedures for investigating and remediating detected identity risk events in a timely and consistent manner.
  • Integrate Identity Protection risk signals with the enterprise SIEM platform and security operations workflows, ensuring identity risk detections are incorporated into the program's broader threat detection, investigation, and incident response processes.
  • Monitor Identity Protection detection effectiveness, analyzing risk detection rates, false positive patterns, and remediation outcomes to identify tuning opportunities and improve detection fidelity.

Entra ID Governance Engineering
  • Lead the engineering, implementation, and administration of Microsoft Entra ID Governance capabilities, including entitlement management, access reviews, lifecycle workflows, and terms of use policies, ensuring identity governance processes are automated, auditable, and aligned with least-privilege access principles.
  • Design and implement Entra ID Governance entitlement management configurations, including access package definitions, access package policies, approval workflows, and assignment lifecycle management, ensuring users can request access through governed, auditable processes.
  • Configure and maintain Entra ID Governance access review campaigns for group memberships, application assignments, and privileged role assignments, ensuring periodic access certification is consistently conducted and documented across all critical access populations.
  • Implement and maintain Entra ID Governance lifecycle workflow configurations, including joiner, mover, and leaver workflow automation, ensuring user account provisioning, access updates, and deprovisioning are triggered automatically based on HR system signals and defined workflow logic.
  • Develop and maintain identity governance reporting capabilities, providing program leadership and Government stakeholders with accurate visibility into access certification status, entitlement management activity, and identity lifecycle workflow outcomes.

Hybrid Identity Engineering
  • Lead the engineering, implementation, and administration of hybrid identity infrastructure, ensuring seamless and secure identity synchronization, authentication, and access management between on-premises Active Directory environments and the Microsoft Entra ID cloud tenant.
  • Design and maintain Microsoft Entra Connect or Entra Cloud Sync configurations, including object scoping rules, attribute synchronization mappings, password hash synchronization or pass-through authentication configurations, and synchronization health monitoring.
  • Implement and maintain Entra ID seamless single sign-on (SSO) configurations for hybrid environments, ensuring domain-joined on-premises devices can authenticate transparently to cloud resources without additional credential prompts.
  • Support the administration and maintenance of Active Directory Federation Services (AD FS) configurations where applicable, including claims rule management, relying party trust configurations, and federation health monitoring.
  • Monitor hybrid identity synchronization health, identifying and resolving synchronization errors, attribute conflicts, and object filtering issues that may impact user authentication or access management.

Application Integration & Single Sign-On Engineering
  • Lead the engineering, implementation, and administration of enterprise application integrations with Microsoft Entra ID, designing and implementing SSO and automated provisioning configurations for all in-scope enterprise applications across the Government application portfolio.
  • Design and implement SAML, OIDC, and OAuth 2.0-based SSO integrations between enterprise applications and Entra ID, ensuring users can authenticate seamlessly and securely to all integrated applications using their Entra ID credentials and MFA.
  • Implement and maintain SCIM-based automated provisioning and deprovisioning integrations between Entra ID and enterprise applications, ensuring user account lifecycle management is automated, consistent, and auditable across all provisioned applications.
  • Configure and maintain Entra ID application registration configurations, including app registrations, enterprise applications, OAuth permission grants, and API permission assignments, ensuring all application identities are properly governed and least-privilege API access is enforced.
  • Support the development and maintenance of an enterprise application SSO and provisioning catalog, documenting all integrated applications, their integration methods, provisioning configurations, and assigned Conditional Access policies.

Security Operations & Threat Intelligence Integration
  • Lead the integration of Entra ID sign-in logs, audit logs, Identity Protection risk detections, and PIM activity data with the enterprise SIEM platform, ensuring identity telemetry is reliably forwarded, accurately parsed, and available for detection, investigation, and compliance reporting.
  • Develop and maintain Entra ID-specific SIEM detection content, including correlation rules, behavioral analytics, and alerting configurations that leverage Entra ID telemetry to detect identity-based threats, account compromise, privilege escalation, and anomalous access patterns.
  • Support incident response activities involving identity-based security events, providing expert Entra ID platform knowledge and remediation capabilities to investigation and containment efforts, including account disablement, token revocation, and session termination.
  • Conduct Entra ID threat hunting activities, proactively searching for indicators of identity compromise, anomalous authentication patterns, and unauthorized access within Entra ID sign-in and audit log data.

Change Management & Operations
  • Lead the preparation and submission of Entra ID change requests for Change Advisory Board (CAB) review, developing comprehensive implementation plans, technical impact assessments, rollback procedures, and test plans for all significant platform changes.
  • Coordinate with the change management process to ensure all Entra ID platform changes are properly reviewed, approved, scheduled, and implemented without degradation to identity services, authentication availability, or security posture.
  • Conduct post-implementation reviews for significant Entra ID platform changes, documenting outcomes, unexpected impacts, and lessons learned to continuously improve change execution practices.
  • Develop and maintain comprehensive Entra ID operational runbooks, standard operating procedures, and knowledge base articles, ensuring documentation supports reliable and consistent platform operations.

Compliance, ATO & Continuous Monitoring
  • Ensure all Entra ID platform configurations are maintained in compliance with applicable Federal cybersecurity frameworks and requirements, including NIST SP 800-53, FISMA, FedRAMP, HSPD-12/FIPS 201, NIST SP 800-207 Zero Trust Architecture, OMB M-22-09, applicable DISA STIGs, and client-specific cybersecurity policies.
  • Support ATO activities for Entra ID-dependent systems and applications, including identity security control implementation documentation, system security plan (SSP) contribution, continuous monitoring reporting, and audit evidence collection.
  • Conduct regular Entra ID configuration compliance assessments, identifying and remediating configuration deviations from applicable security baselines, DISA STIGs, and CIS Benchmarks for Microsoft Entra ID.
  • Support vulnerability management activities for Entra ID platform components, tracking and remediating platform vulnerabilities and security configuration weaknesses identified through vendor advisories, security assessments, and continuous monitoring activities.
  • Develop and maintain Entra ID compliance documentation, including configuration baseline specifications, security control implementation evidence, Conditional Access policy documentation, and audit artifacts supporting the program's ATO and continuous monitoring obligations.

Education and Experience:

Required:
  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, Information Systems, or a related field from an accredited college or university. Equivalent combination of education and directly relevant experience may be considered.
  • Minimum of 7 years of hands-on experience in identity and access management engineering, cloud security, or a closely related discipline, with at least 4 years of demonstrated hands-on experience engineering and administering Microsoft Entra ID (Azure Active Directory) in an enterprise environment.
  • Demonstrated hands-on experience designing and implementing enterprise Conditional Access policy frameworks, including risk-based access policies, device compliance integration, and phishing-resistant MFA enforcement.
  • Demonstrated experience with Microsoft Entra ID Privileged Identity Management (PIM) configuration, including just-in-time access provisioning, approval workflows, and access review campaign management.
  • Experience with hybrid identity infrastructure, including Microsoft Entra Connect or Entra Cloud Sync configuration, synchronization management, and troubleshooting.
  • Experience supporting identity and access management activities in a federal government IT contracting environment, including familiarity with applicable Federal cybersecurity compliance frameworks.
  • Active security clearance or the ability to obtain and maintain a government background investigation and all requisite IT access authorizations. Specific clearance requirements will be confirmed at time of offer.

Preferred:
  • Prior experience serving as a senior Entra ID or Azure AD engineer or architect on a federal IT program of comparable scale and complexity.
  • Hands-on experience with Microsoft Entra ID Governance entitlement management, lifecycle workflows, and access review campaign administration.
  • Experience supporting FedRAMP authorization activities and implementing Entra ID-based identity security controls within Microsoft Azure Government environments.

Required Skills and Competencies:
  • Deep technical expertise across the Microsoft Entra ID platform portfolio, with demonstrated hands-on proficiency in tenant administration, Conditional Access policy engineering, PIM configuration, Identity Protection management, hybrid identity synchronization, and enterprise application SSO integration.
  • Strong Zero Trust identity architecture skills with demonstrated ability to design, implement, and maintain enterprise-grade identity security architectures incorporating continuous access evaluation, risk-based access controls, phishing-resistant MFA, and least-privilege identity governance.
  • Advanced proficiency with Conditional Access policy design and implementation, including risk-based policies, device compliance integration, named locations, session controls, and Continuous Access Evaluation.
  • Demonstrated experience with Privileged Identity Management (PIM) engineering, including role assignment policy design, just-in-time access provisioning, approval workflow configuration, and access review campaign management.
  • Strong knowledge of enterprise identity protocols and standards, including SAML 2.0,

Our Equal Employment Opportunity Policy:

The company is an equal opportunity employer. The company shall not discriminate against any employee or applicant because of race, color, religion, creed, ethnicity, sex, sexual orientation, gender or gender identity (except where gender is a bona fide occupational qualification), national origin or ancestry, age, disability, citizenship, military/veteran status, marital status, genetic information or any other characteristic protected by applicable federal, state, or local law. We are committed to equal employment opportunity in all decisions related to employment, promotion, wages, benefits, and all other privileges, terms, and conditions of employment.

The company is dedicated to seeking all qualified applicants. If you require an accommodation to navigate or to apply to a position on our website, please contact Heaven Wood via e-mail at or by calling to request accommodations.

Koniag Government Services (KGS) is an Alaska Native Owned corporation supporting the values and traditions of our native communities through an agile employee and corporate culture that delivers Enterprise Solutions, Professional Services and Operational Management to Federal Government Agencies. As a wholly owned subsidiary of Koniag, we apply our proven commercial solutions to a deep knowledge of Defense and Civilian missions to provide forward leaning technical, professional, and operational solutions. KGS enables successful mission outcomes for our customers through solution-oriented business partnerships and a commitment to exceptional service delivery. We ensure long-term success with a continuous improvement approach while balancing the collective interests of our customers, employees, and native communities. For more information, please visit ;br>
Equal Opportunity Employer/Veterans/Disabled. Shareholder Preference in accordance with Public Law 88-352
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: 80183286
  • Position Id: 1895143dff058446069734c7bc736ee2
  • Posted 1 hour ago
Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

Washington, District of Columbia

Today

Easy Apply

Contract

USD 65.00 - 71.00 per hour

Rockville, Maryland

Today

Full-time

USD 87,100.00 - 157,450.00 per year

Rockville, Maryland

Today

Full-time

USD 131,300.00 - 237,350.00 per year

Reston, Virginia

Today

Full-time

USD 86,100.00 - 169,800.00 per year

Search all similar jobs