Quick Overview
Seniority
Mid Senior
Work mode
Hybrid
Location
CA, United States
Posted
23 hours ago
AWSMFAOAuthSAMLSOC 2SSOTDDAzureC#.NETGoogle CloudPowerShellRESTZero Trust
Job Description
CCS Global Tech is a rapidly growing Information Technology company with a diverse portfolio of technology products and services and a large network of industry partnerships. With over 22 years of being a successful business with a global talent pool and presence, CCS is a certified Microsoft Gold Partner and specializes in delivering expert Microsoft based solutions for technical and business needs. We have been recognized by Inc. 500 Magazine as one of the fastest growing small companies in the Unites States.
we are a Tier 1 vendor for the City and County of San Francisco for Cloud Services, Staffing Services and Training Services. For this multi-year opportunity with a diverse set of needs to address, we are currently focusing on establishing partnerships with individuals as well as companies who can help us enhance our overall service portfolio, cut lead times, and ultimately help us deliver successfully. We currently hold sizable Government accounts in the San Francisco bay area including City and County of San Francisco, San Mateo County, and Santa Clara County.
We take great pride in our global reach and local influence. Your experience alongside our highly skilled and talented internal team who guide you along the way, offers key insights into what helps you stand out in a competitive job market.
If you are a partner company, please submit resumes with contact information of your own W2 Consultants only. Submitted consultants are expected to have excellent communication skills.
Roles/Responsibilities:
- Identity Architecture & Foundation
- Design and document scalable Azure Entra ID tenant topologies, including multi-organization frameworks and external B2B/B2C collaboration structures.
- Establish and enforce enterprise-wide identity standards, architecture guardrails, and naming conventions across all business units and branches.
- Architect and manage secure deployment matrices for workload identities, including Service Principals, Managed Identities, and application registrations.
- Security, Authentication & Zero Trust Implementation
- Configure and deploy a comprehensive Conditional Access policy suite tailored to role-based risks and user sign-in risk levels.
- Implement and scale passwordless authentication mechanisms across the enterprise, including FIDO2 security keys, Passkeys, and Windows Hello for Business.
- Deploy and tune Identity Protection policies to enable automated risk-based authentication and real-time remediation of compromised accounts.
- Establish secure lifecycle management and automated rotation frameworks for cryptographic keys, certificates, and application secrets.
- Identity Governance & Lifecycle Automation
- Build and automate end-to-end Joiner, Mover, and Leaver (JML) user lifecycle workflows utilizing Microsoft Graph API, PowerShell, and Azure Functions.
- Engineer self-service entitlement management catalogs and automate compliance-driven access reviews using Azure Logic Apps.
- Formulate and enforce lifecycle governance policies for guest access, external partners, and B2B user permissions.
- Application & API Integration
- Integrate and onboard SaaS, on-premises, and custom-developed applications (.NET/C#) using standard OAuth 2.0, OpenID Connect, and SAML 2.0 protocols.
- Configure custom token issuance, claims mapping, and MSAL-based authentication across single-page apps, web apps, and web APIs.
- Develop and execute custom authentication extensions to dynamically inject external claims or modify default authentication flows.
- Automation, Scripting & DevOps (CI/CD)
- Integrate identity configurations and policy changes into automated CI/CD pipelines to achieve Identity-as-Code (IaC).
- Write and maintain clean, reusable script libraries using PowerShell, Azure CLI, and Microsoft Graph SDKs to automate repetitive identity workflows.
- Compliance, Risk Management & Operations
- Align and map Entra ID technical controls to regulatory frameworks, including NIST, FedRAMP, SOC 2, and ISO 27001.
- Compile and deliver structured audit evidence packages to demonstrate the compliance and efficacy of identity controls.
- Author technical runbooks for operational teams to streamline the monitoring, troubleshooting, and optimization of complex token and authentication flows.
- Cross-Functional Leadership & Enablement
- Translate complex business and compliance requirements into comprehensive Technical Design Documents (TDD).
- Collaborate with security, application, DevOps, and infrastructure teams to drive enterprise-wide identity modernization initiatives.
- Communicate high-level identity strategies and risk profiles effectively to non-technical stakeholders and executive leadership.
Mandatory Skills:
- Strong experience with Microsoft Entra ID / Azure AD architecture and administration.
- Proficiency in PowerShell scripting, Microsoft Graph API, and REST APIs.
- Knowledge of OAuth 2.0, OpenID Connect, SAML, and SCIM protocols.
- Experience with Conditional Access, MFA, and Identity Governance.
- Familiarity with Azure AD Connect, Hybrid Identity, and Single Sign-On (SSO).
- Understanding of Zero Trust principles and modern authentication methods.
Desirable Skills:
- Microsoft certifications such as SC-300 (Identity and Access Administrator) or AZ-104 (Azure Administrator).
- Experience with Azure Functions, Logic Apps, or Power Automate for workflow automation.
- Background in security compliance frameworks (e.g., ISO 27001, NIST).
- Soft Skills & Leadership:
- Translate business requirements into secure identity solutions
- Communicate complex identity concepts to non-technical stakeholders
- Drive identity modernization initiatives
- Ability to partner with:
- Cloud solution architects
- DBAs
- DevOps
- Infrastructure admins
- Azure AD B2C / External Identities (CIAM)
- Cross-cloud identity (AWS, Google Cloud Platform federation)
- Identity-related incident response
- Strong problem-solving and analytical skills.
- Excellent communication and collaboration abilities.
- Ability to work in a fast-paced, dynamic environment.
- Certifications:
- Microsoft Identity and Access Administrator
- Azure Solutions Architect
- Security-focused certifications
Similar jobs
- LT
Lead, Software Engineer - Cloud Architect - TS/SCI
NewL3Harris Technologies
Patrick Afb, Florida🇺🇸On-site29 minutes agoAWSAnsibleCloudFormation+1Technology - RS
Azure Cloud Architect with Fabric
NewReliable Software Resources
Detroit, MI🇺🇸On-site23 hours agoSQLETLAzure+2Technology - CG
Cloud Engineer- Expert
NewCCS Global Tech
Raleigh, NC🇺🇸Hybrid23 hours agoAWSAzureGoogle CloudTechnology - RT
Platform Architect / Cloud Architect
NewRequest Technology, LLC
Chicago, IL🇺🇸Hybrid23 hours agoAWSFlinkSplunk+12Technology - MS
Senior AWS Cloud Engineer (6805) with Security Clearance
NewMetroStar Systems Inc.
Reston, VA🇺🇸$174k - $220k/yrHybrid23 hours agoDockerMicroservicesAWS+11Technology - EV
Senior Cloud Native Architect
NewEverpure
Remote🇺🇸RemoteYesterdayMicroservicesAnsibleHTTP+2