Job Title: Senior IAM Engineer
Location: Morrisville, NC or Salem, NH
Duration: 6-12 Months
Visa: No H1b
EST Only
This is a high-level role – looking for a Lead type candidate that also has some architecture/design experience.
- Design and lead the enterprise rollout of Microsoft Entra passkey) support, including device-bound and synced passkey strategies.
- Configure Authentication Methods policies to enable passkeys alongside existing MFA/authentication methods, sequenced with the legacy authentication method deprecation
- Must have enterprise level experience - multi-region environments with 5,000+ identities, or in highly regulated enterprises.
Position Summary
We are seeking an experienced Microsoft Identity Management contractor to design, implement, and harden identity security controls across a global enterprise tenant. This role is hands-on and delivery-focused, covering enterprise passkey deployment, the retirement of SMS and voice authentication in favor of phishing-resistant MFA, Conditional Access policy engineering, application integration governance, and identity risk detection. The ideal candidate has deep, current expertise in the Microsoft Entra ID platform and is comfortable operating in a large, multi-region enterprise with strict compliance and change-management requirements.
The immediate and highest-priority deliverable for this engagement is the enterprise passkey deployment and the accompanying deprecation of SMS and voice authentication methods, both on an accelerated timeline. Candidates should be prepared to lead this work from day one and to demonstrate measurable adoption and legacy-method retirement within the first phase of the engagement.
Key Responsibilities
1. Microsoft Passkeys for Enterprise (Passwordless Authentication)
- Design and lead the enterprise rollout of Microsoft Entra passkey support, including device-bound and synced passkey strategies.
- Configure Authentication Methods policies to enable passkeys alongside existing MFA/authentication methods, sequenced with the legacy authentication method deprecation described in Section 2.
- Define enrollment strategy for end users (self-service registration, Temporary Access Pass provisioning, admin-assisted enrollment for high-privilege accounts).
- Evaluate compatibility across platforms (Windows Hello for Business, mobile authenticator apps, hardware security keys) and browser/device support matrices.
- Partner with helpdesk/security awareness teams on rollout communications, training, and support escalation paths.
- Monitor adoption metrics and authentication method usage reporting post-deployment.
2. Deprecation of SMS and Voice Authentication (Phishing-Resistant MFA)
- Retire SMS and voice call as permitted authentication methods tenant-wide, establishing phishing-resistant MFA as the enterprise standard.
- Baseline current registration and usage of SMS and voice methods by user population, region, role, and device type.
- Define and enforce Conditional Access Authentication Strengths to require phishing-resistant methods, with staged scoping that begins with privileged and high-risk accounts and expands to the full user base.
- Build and govern the exception framework for populations where passkeys are not immediately viable.
- Partner with the Global Service Desk to harden identity verification and account recovery procedures.
3. Entra Conditional Access Policy Design & Management
- Architect, build, and maintain Conditional Access policies governing sign-in risk, device compliance, location, application sensitivity, and user/group scoping.
- Manage policy lifecycle using report-only mode, staged rollout, and What If tool validation prior to enforcement.
- Design break-glass/emergency access account exclusions and safeguards to prevent tenant lockout.
- Integrate Conditional Access with device compliance (Intune), session controls (Conditional Access App Control), sign-in risk (Entra ID Protection), and Global Secure Access, where applicable.
- Continuously review and optimize policies to reduce gaps, redundant rules, and conflicting conditions across a large, distributed policy set.
- Document policy intent, scope, and exceptions for audit and compliance purposes.
4. Enterprise Application Permissions & Integrations
- Review, govern, and remediate OAuth/OpenID Connect and SAML application permissions across the enterprise application portfolio.
- Assess delegated vs. application permissions requested by first- and third-party apps; apply least-privilege principles and admin consent workflows.
- Configure and maintain admin consent policies, permission classifications, and periodic access reviews for enterprise applications.
- Support integration of enterprise SaaS applications via SSO (SAML/OIDC), provisioning (SCIM), and federation, coordinating with application owners and vendors.
- Identify and remediate risky or over-privileged application grants (e.g., via Entra ID reporting or Defender for Cloud Apps).
- Maintain an accurate inventory/catalog of enterprise applications, owners, and permission scopes.
Required Qualifications
- 5+ years of hands-on experience administering Microsoft Entra ID (Azure AD) in an enterprise environment.
- Demonstrated experience leading an organization-wide passkey/FIDO2 rollout to full production at enterprise scale, including Windows Hello for Business, with direct ownership of enrollment campaigns and accountability for adoption outcomes.
- Demonstrated experience retiring legacy authentication methods (SMS, voice, password-only) in a production tenant.
- Strong working knowledge of Conditional Access policy design, testing, and staged enforcement in complex, multi-region tenants.
- Practical experience with enterprise application integration (SSO, SAML/OIDC, SCIM provisioning) and OAuth permission governance.
- Experience managing App Registration lifecycle and enterprise application security standards.
- Proficiency with Entra ID Protection, including risk policy configuration and investigation workflows.
- Proficiency with PowerShell and the Microsoft Graph API for identity automation, bulk migration operations, and adoption/compliance reporting at scale.
- Familiarity with related Microsoft security tooling (Microsoft Defender for Cloud Apps, Microsoft Purview, Intune) as they intersect with identity controls.
- Strong understanding of enterprise change management, documentation, and compliance/audit expectations.
- Excellent communication skills for cross-functional coordination (security, helpdesk, application owners, compliance).
Preferred Qualifications
- Microsoft certifications such as SC-300 (Identity and Access Administrator) or equivalent.
- Prior experience in large, multi-region environments with 5,000+ identities, or in highly regulated enterprises.
- Familiarity with hybrid identity (Entra Connect/Cloud Sync) and legacy AD-to-cloud migration considerations.
Thanks & Regards.
Aviral Sapra
Voto Consulting LLC
Direct #:
North Brunswick, NJ, 08902