IAM Engineer
Mondo · Salem, NH · 1 wk ago
RemoteRemoteInformation Technology$70–$75/hrContract
Remote – East Coast only. Start date is ASAP (within 2 weeks of offer) for this 6-month contract position with option to extend.
About the role
The client is seeking an experienced IAM Engineer to lead enterprise-wide passkey and phishing-resistant MFA initiatives, harden Conditional Access policies, and govern application identity across a large global Microsoft Entra environment.
Responsibilities
- Lead the enterprise rollout of Microsoft Entra passkeys and FIDO2, migrating users away from SMS, voice, and other legacy authentication methods.
- Build and execute the passkey enrollment strategy, covering Windows Hello for Business, Microsoft Authenticator, hardware security keys, and Temporary Access Pass (TAP).
- Design, test, stage, implement, and maintain Conditional Access policies, beginning with privileged and high-risk accounts before expanding org-wide.
- Review and secure enterprise applications and App Registrations within Entra, including OAuth/OIDC, SAML, SCIM, SSO, permissions, and lifecycle management.
- Monitor sign-in and user risk through Entra ID Protection, investigate potentially compromised identities, and drive remediation.
- Automate bulk changes, reporting, and migration activities using PowerShell and Microsoft Graph API.
- Partner with the SOC, help desk, application owners, developers, compliance, and leadership teams, and produce documentation on authentication adoption, Conditional Access, and identity risk.
Requirements
- 5 years of hands-on Microsoft Entra ID/Azure AD experience in an enterprise environment.
- Demonstrated end-to-end passkey/FIDO2 implementation experience taken into full production, not limited to a pilot or POC.
- Deep Conditional Access experience, including designing, testing, staging, implementing, troubleshooting, and optimizing policies.
- Enterprise application integration experience with SSO, SAML, OIDC/OAuth, and SCIM, with strong App Registration and least-privilege permissions governance.
- Hands-on Entra ID Protection experience covering sign-in risk, user risk, compromised identities, and remediation workflows.
- Strong PowerShell and Microsoft Graph API skills for identity automation, large-scale changes, and reporting.
- Strong communication skills with the ability to collaborate across security, engineering, compliance, and business stakeholders in a formal change-management environment.
Preferred Qualifications
- Microsoft SC-300: Identity and Access Administrator certification.
- Experience supporting 5,000 identities in a global or multi-region Microsoft tenant.
- Experience with Entra Connect/Cloud Sync and legacy Active Directory-to-cloud migrations.
- Familiarity with Microsoft Intune for device-based identity controls.
- Exposure to Microsoft Defender for Cloud Apps, Microsoft Purview, or Global Secure Access.
- Experience designing formal identity governance frameworks, audit documentation, and compliance reporting.
- Prior work in a highly regulated enterprise environment.
Pay
$70–75/hr on W2.
Benefits
Eligible for Health, Dental, Vision, and 401K.