Category | Skill | Description from the JD | Customer Priority |
Identity & Access Management | Microsoft Entra ID | Administer and harden Microsoft Entra ID: app registrations and Enterprise Application permissions, consent governance, service principals and managed identities, credential and secret hygiene, and least-privilege scoping. | Mandatory |
Modern Authentication | Secure and govern modern authentication flows across the estate: OIDC, OAuth 2.0 with PKCE, JWT validation and handling, and mTLS. | Good to Have |
Conditional Access | Design, implement, and continuously tune Conditional Access policies. | Good to Have |
Privileged Access Security | MFA enforcement, Privileged Identity Management (PIM) / just-in-time elevation, role minimization, and break-glass procedures. | Mandatory |
App Registrations & Enterprise Applications | App registrations and Enterprise Application permissions, consent governance, service principals and managed identities, credential and secret hygiene, and least-privilege scoping. | Good to Have |
Cloud Security | Security Findings Remediation | Own the full lifecycle of security findings and recommendations through triage, remediation, verification, and closure. | Mandatory |
Recurrence Prevention | Root-cause recurring issues and implement systemic fixes using policy-as-code, automated guardrails, and secure baselines. | Mandatory |
Microsoft Defender for Cloud | Drive secure-score improvement, remediate recommendations, and manage cloud security posture (CSPM). | Mandatory |
Azure Policy | Build and enforce guardrails using Azure Policy; maintain secure-by-default baselines and detect or remediate configuration drift. | Good to Have |
Security Governance | Contribute to standards, control definitions, exception handling, and audit evidence. | Mandatory |
Cloud & SaaS Admin Portal Security | Secure all cloud and SaaS administrative portals, including Azure, Microsoft 365 admin, identity providers, and additional cloud platforms in use. | Mandatory |
Terraform for IaC | Terraform & Secure IaC Baselines | Build and enforce guardrails using Terraform; maintain secure-by-default infrastructure-as-code baselines and detect or remediate configuration drift. | Optional |
AI Security | AI Workloads, Services & Agents | Apply security controls to AI workloads, services, and AI agents. | Mandatory |
AI Identities, Permissions & Risk | Agent and workload identities, tool and permission scoping, data-exposure and prompt-injection risk, and emerging AI security best practices. | Mandatory |