Microsoft Entra ID (IAM) Engineer
Become the Microsoft Entra ID Expert Driving Enterprise Identity Security
A globally recognized real estate investment and development organization known for innovation, operational excellence, and investing in leading-edge technology. Our enterprise technology organization supports a large, complex global environment where security, automation, and scalability are foundational to everything we do.
About the role
We're looking for a Microsoft Entra ID (IAM) Engineer who wants to own and evolve our enterprise identity platform. This is an opportunity to become one of our organization's technical leaders for Microsoft Entra ID while partnering with Infrastructure, Security, Messaging, and Application teams to modernize identity, strengthen security, and leverage AI-powered automation across the enterprise. If you're passionate about Microsoft identity technologies, Zero Trust security, automation, and solving complex enterprise challenges, this is an opportunity to make a lasting impact.
Why join us?
- Join one of the world's premier real estate investment and development firms
- Work with modern Microsoft cloud technologies and AI-powered solutions
- Be part of a team driving enterprise-wide identity modernization
- Competitive compensation and comprehensive benefits package
- Generous PTO and vacation program
- Ongoing training and professional development
- Opportunity to influence enterprise security strategy
- Collaborative culture focused on innovation and continuous improvement
- Long-term career growth within a global organization
Responsibilities
Microsoft Entra ID Leadership
- Serve as the organization's subject matter expert for Microsoft Entra ID
- Design, administer, and optimize enterprise Microsoft Entra ID environments
- Lead enterprise identity modernization initiatives
- Design secure authentication and authorization architectures
- Administer Enterprise Applications within Entra ID
- Manage identity lifecycle processes including Joiners, Movers, and Leavers
- Design and implement Role-Based Access Control (RBAC)
- Administer Privileged Identity Management (PIM)
- Configure and optimize:
- Conditional Access
- Multi-Factor Authentication (MFA)
- Identity Protection
- Identity Governance
- Access Reviews
- Lifecycle Workflows
- Support hybrid identity and directory synchronization
Identity & Access Management
- Configure and manage Single Sign-On using:
- SAML
- OAuth
- OpenID Connect (OIDC)
- Troubleshoot authentication, federation, and directory issues
- Partner with application owners to integrate secure authentication solutions
- Implement Zero Trust identity strategies
- Maintain least-privilege access across enterprise systems
Microsoft 365 & Messaging
- Support Microsoft 365 identity services
- Administer Exchange Online
- Support Exchange Hybrid environments
- Troubleshoot authentication and mail flow issues
- Support secure email technologies including:
- SPF
- DKIM
- DMARC
- Maintain awareness of secure email gateway technologies such as Cisco IronPort
AI & Automation
- Utilize Microsoft Copilot to improve operational efficiency
- Develop PowerShell automation for identity administration
- Automate provisioning, deprovisioning, and identity governance
- Evaluate Microsoft Graph API capabilities
- Use AI-driven tools for troubleshooting, analytics, and operational improvements
- Identify opportunities to automate repetitive IAM processes
Security & Compliance
- Apply Zero Trust principles throughout the enterprise
- Monitor identity-related threats and security events
- Support identity governance initiatives
- Conduct access reviews and certification campaigns
- Partner with Security teams on audits and compliance initiatives
- Improve enterprise security posture through continuous optimization
Documentation & Architecture
- Maintain technical documentation and operational runbooks
- Create architecture diagrams using Microsoft Visio
- Document identity architectures and operational procedures
- Develop standards and best practices for enterprise identity management
Collaboration
- Partner with Infrastructure, Security, Messaging, and Application teams
- Recommend improvements to enterprise identity architecture
- Participate in enterprise technology initiatives
- Participate in an on-call rotation as needed
Requirements
- Bachelor's degree or equivalent experience
- 5+ years of enterprise Microsoft Entra ID administration
- Expert-level knowledge of Microsoft Entra ID (Azure AD)
- Extensive experience designing enterprise identity solutions
- Deep expertise with:
- Conditional Access
- Identity Protection
- Enterprise Applications
- Single Sign-On (SSO)
- Multi-Factor Authentication (MFA)
- Privileged Identity Management (PIM)
- Identity Governance
- Lifecycle Workflows
- Role-Based Access Control (RBAC)
- Strong Active Directory administration experience
- Experience supporting hybrid identity environments
- Experience administering Microsoft 365 and Exchange Online
- Strong PowerShell scripting and automation experience
- Experience with Microsoft Graph API
- Strong understanding of Zero Trust architecture
- Experience troubleshooting enterprise authentication issues
- Knowledge of email authentication technologies:
- SPF
- DKIM
- DMARC
- Excellent communication and collaboration skills
Preferred Qualifications
- Microsoft Certified: Identity and Access Administrator Associate (SC-300)
- Microsoft Azure certifications
- Microsoft 365 certifications
- Microsoft Security certifications
- Experience with Microsoft Copilot
- Experience implementing AI-powered operational improvements
- Experience with Cisco IronPort or similar secure email gateway technologies
- Microsoft Visio experience
- Experience supporting large enterprise environments
- Passion for automation and continuous improvement
Pay
$130,000 - $160,000 per year