Full Stack .NET/Privileged Access Platform Engineer

Milton, GA, US • Posted 4 hours ago • Updated 4 hours ago
Full Time
50% Travel Required
On-site
Depends on Experience
Company Branding Image
Fitment

Dice Job Match Score™

🔢 Crunching numbers...

Job Details

Skills

  • Full Stack .NET/Privileged Access Platform Engineer Location: Montreal or Alpharetta
  • 3 days/week onsite Duration: 12 Months Client: WWT/Morgan Stanley Bill: $70 Overview Hands-on senior developer joining the Privileged Access Management team to build a secure privileged-access orchestration and integration platform connecting ITSM/CMDB systems
  • privileged access management tooling
  • Microsoft identity and endpoint services
  • and enterprise audit platforms. This role does not require prior domain expertise in privileged access management tools (e.g.
  • CyberArk) — training/context will be provided. Strong full stack .NET development skills are the priority. Responsibilities • Develop production-grade services using C#/.NET and ASP.NET Core
  • including REST APIs
  • background workers
  • policy/orchestration services
  • event-driven workflows
  • and reconciliation processes. • Build front-end administrative interfaces using Angular
  • supporting privileged-access request
  • approval
  • and monitoring workflows. • Build orchestration and integration workflows across privileged access management platforms (session management
  • endpoint privilege management
  • and automation components)
  • Microsoft Entra PIM
  • Intune
  • Windows LAPS
  • Microsoft Graph
  • Windows 365
  • ITSM/CMDB systems
  • and endpoint-management/automation platforms. • Implement policy-driven authorization workflows that evaluate user identity
  • device identity
  • role eligibility
  • business approval
  • requested operation
  • target scope
  • risk level
  • device posture
  • and permitted duration before privileged actions are executed. • Develop orchestration logic that determines the correct execution mechanism (privileged session brokering
  • endpoint elevation
  • PIM activation
  • endpoint-management actions
  • credential recovery
  • or other approved mechanisms) while preventing overlapping or conflicting control-plane behavior. • Design Azure-hosted solutions using services such as Azure App Service
  • Container Apps or AKS
  • API Management
  • Service Bus/Event Grid
  • Azure SQL
  • Key Vault/Managed HSM
  • Managed Identities
  • Application Insights
  • and private networking. • Implement secure multi-tenant and multi-region application patterns: tenant isolation
  • scoped workload identities
  • per-environment secrets/keys
  • authorization boundaries
  • replay protection
  • idempotency
  • and resilient failover. • Engineer reliable orchestration workflows with comprehensive instrumentation
  • including activation
  • extension
  • expiry
  • revocation
  • credential rotation
  • reconciliation
  • stale-access cleanup
  • dependency-failure handling
  • retries
  • and verification that privileged access was actually removed across downstream systems. • Build scalable asynchronous and bulk-operation capabilities: queues
  • bounded concurrency
  • target manifests
  • canary execution
  • per-target result tracking
  • cancellation
  • and partial-failure handling. • Implement comprehensive security and audit telemetry capturing requester
  • approver
  • operator
  • target
  • requested action
  • policy decision
  • timestamps
  • downstream transaction/session identifiers
  • expiration/revocation
  • and execution outcome. • Apply secure software engineering practices: OAuth 2.0/OIDC
  • workload identity federation
  • certificate-based authentication
  • RBAC
  • least privilege
  • OWASP controls
  • threat modeling
  • secrets management
  • secure SDLC
  • and automated security testing. • Build automated testing covering unit
  • integration
  • contract
  • authorization-boundary
  • cross-tenant
  • concurrency
  • failover
  • and security scenarios
  • supported by CI/CD and Infrastructure-as-Code (using Ansible for automation) with enterprise-standard tooling. Requirements • Strong hands-on experience with C#/.NET
  • ASP.NET Core
  • and Angular in a full stack capacity. • Experience building and operating large-sc…

Summary

Full Stack .NET/Privileged Access Platform Engineer

Location: Montreal or Alpharetta, 3 days/week onsite

Duration: 12 Months

Bill: $70

 

Overview Hands-on senior developer joining the Privileged Access Management team to build a secure privileged-access orchestration and integration platform connecting ITSM/CMDB systems, privileged access management tooling, Microsoft identity and endpoint services, and enterprise audit platforms. This role does not require prior domain expertise in privileged access management tools (e.g., CyberArk) — training/context will be provided. Strong full stack .NET development skills are the priority.

 

Responsibilities

•             Develop production-grade services using C#/.NET and ASP.NET Core, including REST APIs, background workers, policy/orchestration services, event-driven workflows, and reconciliation processes.

•             Build front-end administrative interfaces using Angular, supporting privileged-access request, approval, and monitoring workflows.

•             Build orchestration and integration workflows across privileged access management platforms (session management, endpoint privilege management, and automation components), Microsoft Entra PIM, Intune, Windows LAPS, Microsoft Graph, Windows 365, ITSM/CMDB systems, and endpoint-management/automation platforms.

•             Implement policy-driven authorization workflows that evaluate user identity, device identity, role eligibility, business approval, requested operation, target scope, risk level, device posture, and permitted duration before privileged actions are executed.

•             Develop orchestration logic that determines the correct execution mechanism (privileged session brokering, endpoint elevation, PIM activation, endpoint-management actions, credential recovery, or other approved mechanisms) while preventing overlapping or conflicting control-plane behavior.

•             Design Azure-hosted solutions using services such as Azure App Service, Container Apps or AKS, API Management, Service BEvent Grid, Azure SQL, Key Vault/Managed HSM, Managed Identities, Application Insights, and private networking.

•             Implement secure multi-tenant and multi-region application patterns: tenant isolation, scoped workload identities, per-environment secrets/keys, authorization boundaries, replay protection, idempotency, and resilient failover.

•             Engineer reliable orchestration workflows with comprehensive instrumentation, including activation, extension, expiry, revocation, credential rotation, reconciliation, stale-access cleanup, dependency-failure handling, retries, and verification that privileged access was actually removed across downstream systems.

•             Build scalable asynchronous and bulk-operation capabilities: queues, bounded concurrency, target manifests, canary execution, per-target result tracking, cancellation, retries, and partial-failure handling.

•             Implement comprehensive security and audit telemetry capturing requester, approver, operator, target, requested action, policy decision, timestamps, downstream transaction/session identifiers, expiration/revocation, and execution outcome.

•             Apply secure software engineering practices: OAuth 2.0/OIDC, workload identity federation, Managed Identities, certificate-based authentication, RBAC, least privilege, OWASP controls, threat modeling, secrets management, secure SDLC, and automated security testing.

•             Build automated testing covering unit, integration, contract, authorization-boundary, cross-tenant, concurrency, failover, revocation, reconciliation, and security scenarios, supported by CI/CD and Infrastructure-as-Code (using Ansible for automation) with enterprise-standard tooling.

Requirements

•             Strong hands-on experience with C#/.NET, ASP.NET Core, and Angular in a full stack capacity.

•             Experience building and operating large-sc…

Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: 91109870
  • Position Id: 2933-38163-1790868292
  • Posted 4 hours ago

Company Info

About Microgreen Technologies LLC

A great team is the sum of its people. We are looking for those who want to make a difference with their talents and are looking to grow and learn EVERY.SINGLE.DAY.

Do you consider yourself an innovator? Do you measure each day by what you have accomplished? Read more.

From our business analysts who help identify the next opportunity to partner and addess a healthcare problem to our data visualization and AI/ML engineers who are adept with the latest technologies to our client support specialists who make sure that we are meeting and exceeding expectations, each team member is vital and we want to grow together. Collaboration, respect, and great work-life balance are key in our work culture.

Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

Hybrid in Alpharetta, Georgia

•

Yesterday

Easy Apply

Contract

Depends on Experience

Hybrid in Alpharetta, Georgia

•

Yesterday

Easy Apply

Contract

Depends on Experience

Search all similar jobs