Job Summary
We are seeking a highly skilled Entra ID Team Lead / Identity & Security Architect with deep expertise in authentication, authorization, identity and access management, security governance, AI, and cloud security.
The successful candidate will lead a Workforce Security / Workforce Authentication and Authorization team responsible for designing and securely implementing identity solutions across hybrid and cloud environments.
The role requires strong expertise in Microsoft Entra ID, Azure, AWS Security, authentication protocols, Zero Trust, privileged access, identity governance, application security, and modern cloud architectures, along with the ability to provide technical leadership and consultation to stakeholders and IT management.
Key Responsibilities
Workforce Identity & Security Leadership
- Lead an identity-centric Workforce Security team.
- Drive the development of authentication and access-management solutions.
- Define and implement secure identity and access patterns.
- Apply security principles including:
- Zero Trust
- Least Privilege
- Defense in Depth
- Review identity and access management security solutions proposed by stakeholders.
- Provide technical consultation to partners, engineering teams, and IT management.
- Lead secure implementation of workforce authentication and authorization solutions across hybrid and cloud environments.
Microsoft Entra ID & Identity Management
- Provide deep technical leadership across Microsoft Entra ID solutions.
- Design and implement identity and access management solutions using:
- Entra ID
- Azure
- Enterprise Privileged Management (EPM)
- Entitlement Management
- Work with identity governance and access-management scenarios.
- Support privileged identity management and Just-in-Time (JIT) access.
- Design role-based access control and identity governance solutions.
- Support passwordless authentication and modern authentication solutions.
Authentication & Authorization
Strong hands-on knowledge of:
- OAuth
- OIDC
- SAML
- SSO
- MFA
- Conditional Access
- Kerberos
- LDAP
- Identity Federation
- Authorization Patterns
- Token Handling
- Authentication Flows
- Design secure authentication and authorization patterns for enterprise applications.
- Support identity federation and cloud-native authentication architectures.
- Design secure access patterns across applications, users, devices, and cloud services.
AI & Identity
- Understand AI concepts, patterns, and their impact on the Identity and Access Management domain.
- Participate in AI adoption initiatives with an identity and security focus.
- Develop knowledge of Entra ID agentic identity concepts.
- Understand identity and authentication patterns associated with AI-enabled and agentic solutions.
- Evaluate the security implications of AI adoption within identity and access management.
- Provide identity-focused guidance for AI and automation initiatives.
Application Identity & Security
- Provide identity and security solutions for:
- Java-based microservices
- React-based frontends
- Android applications
- iOS applications
- Design application authentication and authorization solutions on Azure.
- Support application registration and application integration scenarios.
- Implement secure token and session-handling mechanisms.
- Work with:
- JWT
- Session Management
- Code Signing
- Certificate Authentication
- TLS/SSL
- API Security
- Application Registration
- Application Integration
Cloud Security
- Provide security architecture and identity solutions across Azure and AWS environments.
- Strong understanding of cloud security concepts including:
- Policies
- RBAC
- Identities
- Privileged Access Management
- Activities
- Support secure cloud-native architectures.
- Apply identity and security controls across hybrid and cloud infrastructures.
- Work with Cloud Infrastructure Entitlement Management (CIEM) solutions.
- Identify and support remediation of:
- Toxic combinations
- High-risk entitlements
- Excessive privileges
- Access risks
Security Products & Technologies
Hands-on or strong knowledge of:
- Microsoft Entra ID
- EPM
- Microsoft Sentinel
- Azure
- AWS Security
- Okta
- PingFederate
- Entitlement Management Solutions
- CIEM
- Privileged Identity Management
- Secrets Management
Workforce Cybersecurity
Act as a workforce cybersecurity expert across solutions involving:
- End User Computing
- Proxy Solutions
- MFA
- SSO
- Conditional Access
- Passwordless Authentication
- YubiKey
- Biometric Authentication
- Identity Governance
- Secrets Management
- Automation
- RBAC
- Privileged Identity Management
- Just-in-Time Access
Security Architecture & Threat Modeling
- Apply threat modeling concepts and methodologies to identity and security solutions.
- Understand application security principles and OWASP standards.
- Apply security best practices to enterprise applications.
- Consider browser compatibility, storage, cookies, and session security.
- Evaluate application and identity security risks during architecture and design.
API, Network & Infrastructure Security
Maintain awareness and understanding of:
- API Management
- Firewalls
- DLP
- VPNs
- DNS
- Azure Defender
- MCAS
- Microsoft Sentinel
- WAFs
- Application Gateways
- NSGs
- Application Proxy
- RADIUS Clusters
- CDN
Apply appropriate security controls across application, network, and identity layers.
Security Operations & Troubleshooting
- Support operations teams in troubleshooting complex identity scenarios.
- Analyze and investigate identity and security issues using:
- Microsoft Sentinel
- KQL
- Audit Logs
- Perform identity-related incident analysis and troubleshooting.
- Investigate authentication, authorization, access, and identity governance issues.
- Support operational teams with complex identity scenarios across hybrid and cloud environments.
Container & Kubernetes Security
- Understand Docker security concepts.
- Understand container orchestration security.
- Support security considerations for Kubernetes environments.
- Apply identity and access controls within containerized and cloud-native environments.
Required Technical Skills
Identity & Access Management
- Microsoft Entra ID
- Authentication
- Authorization
- Access Management
- Identity Governance
- Privileged Identity Management
- Entitlement Management
- RBAC
- Just-in-Time Access
- Zero Trust
- Least Privilege
- Defense in Depth
Authentication Protocols
- OAuth
- OIDC
- SAML
- SSO
- MFA
- Conditional Access
- Kerberos
- LDAP
- Identity Federation
Cloud Security
- Azure
- AWS Security
- Azure Security
- Cloud Security Architecture
- Cloud-native services
- CIEM
- Privileged Access Management
- Secrets Management
Application Security
- JWT
- Session Handling
- Code Signing
- Certificate Authentication
- TLS/SSL
- API Security
- Application Registration
- Application Integration
- OWASP
- Threat Modeling
Security Operations
- Microsoft Sentinel
- KQL
- Audit Logs
- Security Monitoring
- Identity Troubleshooting
Preferred / Additional Skills
- Okta
- PingFederate
- EPM
- Azure Defender
- MCAS
- API Management
- WAF
- Application Gateway
- NSGs
- Application Proxy
- RADIUS
- Docker Security
- Kubernetes Security
- AI / Agentic Identity
- YubiKey
- Biometric Authentication