Quick Overview
Job Description
Role : Senior Engineer - Microsoft Entra / Identity & Access Management (IAM)
Location : Dallas, TX ( Hybrid onsite working)
Locals preferred
Role Summary
The Senior Entra IAM Engineer is responsible for designing, implementing, securing, and supporting enterprise identity and access management solutions using Microsoft Entra ID (formerly Azure Active Directory) and related Microsoft identity technologies. The role serves as a senior technical resource for identity architecture, authentication, authorization, privileged access, application integration, and identity governance across cloud and hybrid environments.
The engineer works closely with cybersecurity, cloud/platform, infrastructure, application, and compliance teams to implement secure, scalable IAM solutions aligned with Zero Trust principles and organizational security requirements.
Key Responsibilities
- Design, implement, configure, and support Microsoft Entra ID solutions in complex enterprise environments.
- Engineer identity solutions involving SSO, MFA, passwordless authentication, Conditional Access, RBAC, and federation.
- Design and support hybrid identity environments using Entra Connect / Cloud Sync and on-premises Active Directory.
- Integrate SaaS, cloud, and enterprise applications with Entra ID using SAML 2.0, OAuth 2.0, OpenID Connect (OIDC), and SCIM.
- Implement and manage Entra ID Governance, including access reviews, entitlement management, lifecycle workflows, and identity lifecycle processes.
- Design and administer Privileged Identity Management (PIM) and privileged-access controls.
- Develop and maintain Conditional Access policies based on user, device, application, location, authentication strength, and risk.
- Support Entra ID Protection, identity risk detection, remediation, and security monitoring.
- Engineer identity lifecycle processes covering joiner, mover, and leaver (JML) scenarios.
- Troubleshoot complex authentication, authorization, federation, provisioning, synchronization, and application-access issues.
- Automate IAM administration and operational processes using PowerShell, Microsoft Graph API, REST APIs, and/or infrastructure-as-code approaches.
- Analyze sign-in, audit, provisioning, and security logs to identify and resolve identity-related incidents.
- Partner with security teams to implement Zero Trust and least-privilege access models.
- Develop technical designs, implementation plans, operational procedures, and engineering documentation.
- Participate in architecture and security reviews for applications requiring identity integration.
- Provide technical leadership and mentorship to junior and mid-level IAM engineers.
- Lead or provide senior technical support for IAM migrations, modernization initiatives, and production incidents.
Required Technical Skills
Strong hands-on experience should include:
- Microsoft Entra ID / Azure Active Directory
- Entra Conditional Access
- Multi-Factor Authentication (MFA)
- Passwordless authentication / FIDO2 / Windows Hello for Business
- Entra Privileged Identity Management (PIM)
- Entra ID Governance
- Entra ID Protection
- Enterprise Applications and App Registrations
- SSO and federation
- SAML 2.0, OAuth 2.0 and OpenID Connect
- SCIM provisioning
- Active Directory and hybrid identity
- Entra Connect / Cloud Sync
- Microsoft Graph API
- PowerShell automation
- RBAC and least-privilege access models
- Identity lifecycle management
- Authentication and provisioning troubleshooting
- Identity/security logging and monitoring
Preferred Experience
- Approximately 5–8+ years of IAM or identity engineering experience, with significant hands-on Microsoft Entra experience.
- Experience supporting large-scale enterprise or multi-tenant environments.
- Experience migrating applications from legacy authentication/federation platforms to Entra ID.
- Understanding of Zero Trust architecture and identity-centric security.
- Experience integrating Entra with Microsoft 365, Azure, endpoint/device-management platforms, SIEM/SOC tooling, and third-party SaaS applications.
- Familiarity with broader IAM platforms such as SailPoint, Saviynt, Okta, CyberArk, Ping Identity, or similar technologies is beneficial.
- Experience operating within security and regulatory frameworks such as NIST, ISO 27001, SOC 2, PCI DSS, or similar environments.
Preferred Certifications
Relevant certifications may include Microsoft Certified: Identity and Access Administrator Associate (SC-300), Microsoft security certifications such as SC-100, Azure certifications, CISSP, or equivalent IAM/security credentials.
Similar jobs
- DE
Forward Deployed Engineer AI
NewDTEL Engineering & Consultants Inc
Columbus, OH🇺🇸Hybrid20 hours agoEngineering - ME
AWS Engineer, East Whiteland Township, PA
NewMetaRPO
Pennsburg, PA🇺🇸Hybrid20 hours agoEngineering - GA
Engineer III with Security Clearance
NewGeneral Atomics
Palmdale, CA🇺🇸Hybrid20 hours agoEngineering - TT
C&A (Controls & Automation) Engineer
NewTHE TILTED CIRCLE LLC
Cleveland, OH🇺🇸On-site20 hours agoSCADAEngineering - IS
Engineer II, Ground System Operator with Security Clearance
NewIridium Satellite Communications
Grand Forks, ND🇺🇸$75k - $95k/yrHybrid20 hours agoEngineering - CO
R -6B1BI3-Design and Analysis Engineer 3 - 664-Electronic Sys De with Security Clearance
NewConfidential
Berkeley, MO🇺🇸On-site20 hours agoEngineering