Haystack
← Back to Jobs
Technology
AS

IAM Engineer/ Architect- Houston, TX- HYBRID

Avtech SolutionsHouston, TX🇺🇸United StatesPosted 19 Aug 2026

Quick Overview

Work Type
Hybrid
Level
Mid Senior

Job Description

IAM engineer/architect. Houston, Texas- HYBRID

Identity as a Perimeter and Modernization Program

Microsoft Entra ID, Windows Hello for Business, Passkeys, and Conditional Access

1. Project Overview

CenterPoint Energy seeks to modernize enterprise identity security through the deployment and enforcement of phishing-resistant authentication across the Microsoft Entra ID environment. The initiative will establish Windows Hello for Business (WHfB) as the primary enterprise authentication method and implement passwordless authentication through Passkeys, Microsoft Authenticator Passwordless, and FIDO2 security keys where appropriate.

The project will further strengthen Zero Trust identity controls through Conditional Access optimization, Continuous Access Evaluation (CAE), device trust validation, Identity Protection integration, and administrative security hardening.

2. Project Objectives

The objectives of this engagement are to:

  • Eliminate reliance on passwords for daily authentication.
  • Reduce phishing, MFA fatigue, token theft, and credential compromise risks.
  • Establish phishing-resistant authentication as the enterprise standard.
  • Improve identity security posture consistent with NIST CSF 2.0 and Zero Trust principles.
  • Enhance Conditional Access governance and policy enforcement.
  • Strengthen administrator authentication requirements.
  • Improve contractor and B2B identity controls.
  • Leverage device health and compliance signals as authentication controls.
  • Enable Continuous Access Evaluation (CAE) for near real-time access revocation.
  • Establish operational processes for passwordless onboarding, recovery, and lifecycle management.

3. Scope

Phase 1 Rapid assessment and planning

Review current state:

  • Microsoft Entra ID tenant configuration
  • Authentication methods policy
  • Passwordless readiness
  • Existing Conditional Access policies
  • MFA deployment status
  • Identity Protection configuration
  • Device compliance posture
  • Enrollment processes
  • Administrative account architecture
  • B2B config settings

Deliverables

  • Current-state assessment
  • Gap analysis
  • Passwordless config
  • Deployment plan

Phase 2 Windows Hello for Business Enforcement (Under progress now, we need some light touch here)

Windows Hello for Business Deployment

Configure and enforce WHfB for all CNP devices using GPO and InTune:

  • Employees
  • Corporate laptops
  • Microsoft-managed endpoints
  • Hybrid and cloud-joined devices

Configuration Activities

  • GPO
  • TPM-backed credential enforcement
  • Biometric authentication enablement
  • PIN policy standardization
  • Intune policy deployment
  • Enrollment automation
  • Compliance reporting

Deliverables

  • Deployment configuration
  • Enrollment procedures
  • Support documentation

Phase 3 Enterprise Passwordless Authentication

Microsoft Authenticator Passwordless

Deploy:

  • Passwordless phone sign-in
  • Phish-resistant MFA controls
  • Authentication method policies

Passkey Deployment

Enable and enforce passkeys for:

Employees

  • Microsoft Authenticator Passkeys
  • Device-bound passkeys
  • Cross-platform passkeys (approved scenarios)

Privileged Administrators (A accounts)

  • Passkeys required
  • Hardware-backed authenticators preferred
  • Dedicated administrative accounts
  • Phishing-resistant authentication enforcement

Contractors

  • Passkeys where mobile devices are supported
  • FIDO2 security keys for shared workstation environments
  • Strong authentication onboarding process

B2B Users

  • Trust external MFA and require phishing-resistant authentication
  • Passkey registration

Temporary Access Pass (TAP)

Implement TAP process for:

  • New hires
  • Authentication recovery
  • Device replacement
  • Lost passkeys
  • Lost security keys

Phase 4 FIDO2 Security Key Program

Security Key Deployment

Implement FIDO2 security keys for specific users such as:

  • Privileged administrators
  • Break-glass accounts
  • Contractors

Deliverables

  • Develop the process for lifecycle management
  • Lost/stolen key process, ordering and replacement
  • FIDO2 inventory process

4. Conditional Access Modernization

Conditional Access Policy Review

Implement CA Policy Standards

Require:

  • Passkeys
  • WHfB
  • FIDO2

Block:

  • Legacy authentication and High-risk authentication methods
  • Weak MFA methods including SMS and Phone Calls

User-Based Policies

Improve CA Policy controls for:

  • Employees
  • Contractors
  • B2B users
  • Privileged administrators
  • Service accounts

Application Policies

Protect:

  • Microsoft 365 - for example - review mailbox sharing permissions to prevent excessive sharing (including company-wide access). Process to prevent this reoccurring.
  • Azure Portal
  • Service accounts to be protected and allow sign-in access from approved/trusted IP addresses only.
  • Privileged applications
  • SaaS platforms

Session Controls

Configure:

  • Sign-in frequency
  • Risk-based access
  • Continuous access evaluation

Deliverables

  • CA policy cleanup for clarity and consistency
  • Optimize and enhance CA policies

5. Device Trust and Health Controls

Intune and Device Compliance Enhancement

Implement Conditional Access enforcement based on:

Device Health

Require:

  • Entra registered/joined devices
  • Managed devices
  • Compliant devices

Compliance Signals

Validate:

  • BitLocker enabled
  • TPM available
  • Defender active
  • CrowdStrike EDR active (primary)
  • Domain joined and OS supported
  • Secure Boot enabled
  • Palo Alto VPN enabled

Deliverables

  • Device compliance configuration and rollout
  • Compliance policies
  • Reporting dashboard

6. Continuous Access Evaluation (CAE)

CAE Enablement

Implement and validate:

  • Continuous Access Evaluation
  • Real-time session revocation
  • Token invalidation upon risk events
  • Location change enforcement
  • Privilege change enforcement

Deliverables

  • CAE configuration
  • Validation and operational procedures

7. Reporting

Develop:

  • Authentication adoption metrics
  • Passwordless enrollment metrics
  • CA compliance reporting
  • Device health reporting
  • Executive dashboards

Example KPIs

  • % WHfB Enrollment
  • % Passkey Adoption
  • % Passwordless Authentication Usage
  • % CA Coverage
  • % Compliant Devices
  • Privileged Account Passwordless Adoption
  • High-Risk Sign-In Reduction

8. Change Management, Knowledge Transfer & Operational Hand-off

Provide:

  • IAM Administrative training
  • Service Desk training
  • IAM operational procedures
  • User communications

Skills

MFA
Azure
Zero Trust

Similar jobs