Haystack
← Back to Jobs
Remote
Technology
TR

Cloud Engineer

TryfactaUnited States🇺🇸United StatesPosted 31 Aug 2026

Quick Overview

Seniority
Mid Senior
Work mode
Remote
Location
United States
Posted
Yesterday
AWSMFAOAuthSAMLSOC 2SSOTDDAzureC#.NETGoogle CloudPowerShellRESTZero Trust

Job Description

About US:
Tryfacta is a leading, nationally renowned Workforce Management Solution provider for private &public sector firms across the US. We specialize in Healthcare, IT, Business Support, and Professional & Craft/Light Industrial ecosystems.

Founded in March 1996, we have a presence in all 50 States. Tryfacta has Ranked number 1 as one of the fastest-growing companies by Inc. Magazine (Inc. 5000)!

Tryfacta is certified by the Joint Commission for Healthcare Staffing Services & has numerous ISO Certifications that capture our commitment to continuous improvement.

Job Summary:
Tryfacta is seeking a Cloud Engineer for our client in San Francisco, CA 94102. This is a temporary contract assignment. If you meet the qualifications listed below and are interested, please Apply Now!

Position Title: Cloud Engineer
Location: San Francisco, CA 94102
Duration:
  1. Duration of Assignment:


Start Date of Assignment:10/1/2026
Term (including any Option Terms):Maximum Hours Per Term
Initial Term:10/01/2026 – 09/30/20271,976
1st Option Term: 10/01/2027 – 09/30/20281,976
2nd Option Term: 10/01/2028 – 09/30/20291,968

Work Schedule: This position is a remote position and will be onsite only when needed. The remote status of this position is subject to change if deemed necessary by the client.
Responsibilities for this position include, but are not limited to:
  1. Tasks and Responsibilities to be Performed
Task No.Description of Tasks and Responsibilities for each Classification
1Identity Architecture & Foundation
• Design and document scalable Azure Entra ID tenant topologies, including multi-organization frameworks and external B2B/B2C collaboration structures.
• Establish and enforce enterprise-wide identity standards, architecture guardrails, and naming conventions across all business units and branches.
• Architect and manage secure deployment matrices for workload identities, including Service Principals, Managed Identities, and application registrations.
2Security, Authentication & Zero Trust Implementation
• Configure and deploy a comprehensive Conditional Access policy suite tailored to role-based risks and user sign-in risk levels.
• Implement and scale passwordless authentication mechanisms across the enterprise, including FIDO2 security keys, Passkeys, and Windows Hello for Business.
• Deploy and tune Identity Protection policies to enable automated risk-based authentication and real-time remediation of compromised accounts.
• Establish secure lifecycle management and automated rotation frameworks for cryptographic keys, certificates, and application secrets.
3Identity Governance & Lifecycle Automation
• Build and automate end-to-end Joiner, Mover, and Leaver (JML) user lifecycle workflows utilizing Microsoft Graph API, PowerShell, and Azure Functions.
• Engineer self-service entitlement management catalogs and automate compliance-driven access reviews using Azure Logic Apps.
• Formulate and enforce lifecycle governance policies for guest access, external partners, and B2B user permissions.
4Application & API Integration
• Integrate and onboard SaaS, on-premises, and custom-developed applications (.NET/C#) using standard OAuth 2.0, OpenID Connect, and SAML 2.0 protocols.
• Configure custom token issuance, claims mapping, and MSAL-based authentication across single-page apps, web apps, and web APIs.
• Develop and execute custom authentication extensions to dynamically inject external claims or modify default authentication flows.
5Automation, Scripting & DevOps (CI/CD)
• Integrate identity configurations and policy changes into automated CI/CD pipelines to achieve Identity-as-Code (IaC).
• Write and maintain clean, reusable script libraries using PowerShell, Azure CLI, and Microsoft Graph SDKs to automate repetitive identity workflows.
6Compliance, Risk Management & Operations
• Align and map Entra ID technical controls to regulatory frameworks, including NIST, FedRAMP, SOC 2, and ISO 27001.
• Compile and deliver structured audit evidence packages to demonstrate the compliance and efficacy of identity controls.
• Author technical runbooks for operational teams to streamline the monitoring, troubleshooting, and optimization of complex token and authentication flows.
7Cross-Functional Leadership & Enablement
* Translate complex business and compliance requirements into comprehensive Technical Design Documents (TDD).
* Collaborate with security, application, DevOps, and infrastructure teams to drive enterprise-wide identity modernization initiatives.
* Communicate high-level identity strategies and risk profiles effectively to non-technical stakeholders and executive leadership.

To be considered for this position, you should have: [Skills, Education, or Experience]
Minimum Job-Specific Skills/Qualifications Required for each Classification (in order of relative importance):
  • Strong experience with Microsoft Entra ID / Azure AD architecture and administration.
  • Proficiency in PowerShell scripting, Microsoft Graph API, and REST APIs.
  • Knowledge of OAuth 2.0, OpenID Connect, SAML, and SCIM protocols.
  • Experience with Conditional Access, MFA, and Identity Governance.
  • Familiarity with Azure AD Connect, Hybrid Identity, and Single Sign-On (SSO).
  • Understanding of Zero Trust principles and modern authentication methods.
Additional Skills/Qualifications Desired for each Classification:
  • Microsoft certifications such as SC-300 (Identity and Access Administrator) or AZ-104 (Azure Administrator).
  • Experience with Azure Functions, Logic Apps, or Power Automate for workflow automation.
  • Background in security compliance frameworks (e.g., ISO 27001, NIST).
  • Soft Skills & Leadership:
    • Translate business requirements into secure identity solutions
    • Communicate complex identity concepts to non-technical stakeholders
    • Drive identity modernization initiatives
    • Ability to partner with:
    • Cloud solution architects
    • DBAs
    • DevOps
    • Infrastructure admins
  • Azure AD B2C / External Identities (CIAM)
  • Cross-cloud identity (AWS, Google Cloud Platform federation)
  • Identity-related incident response
  • Strong problem-solving and analytical skills.
  • Excellent communication and collaboration abilities.
  • Ability to work in a fast-paced, dynamic environment.
  • Certifications:
  • Microsoft Identity and Access Administrator
  • Azure Solutions Architect
  • Security-focused certifications

Tryfacta is an Equal Opportunity/Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, protected veteran or disabled status, or genetic information.

Similar jobs