Defender for Cloud Engineer
Openkyber
Hi, Hope you're doing well!! Please find the requirement below. If you find yourself comfortable with the requirement please reply back with your updated resume or call me back at ) Identity & Access Management (IAM) Engineer Location: 9 Northeastern Blvd Ste 400, Salem, NH 03079 2121 RDU Center Drive, Suite 300, Morrisville, NC 27560. Hybrid Hours: East Coast hours (will be required to travel) Why Open: New Project need Start Date: ASAP Duration: December 2025- July 2027 (10+ months) Position Summary We are seeking an experienced Microsoft Identity Management contractor to design, implement, and harden identity security controls across a global enterprise tenant. This role is hands-on and delivery-focused, covering enterprise passkey deployment, the retirement of SMS and voice authentication in favor of phishing-resistant MFA, Conditional Access policy engineering, application integration governance, and identity risk detection. The ideal candidate has deep, current expertise in the Microsoft Entra ID platform and is comfortable operating in a large, multi-region enterprise with strict compliance and change-management requirements. The immediate and highest-priority deliverable for this engagement is the enterprise passkey deployment and the accompanying deprecation of SMS and voice authentication methods, both on an accelerated timeline. Candidates should be prepared to lead this work from day one and to demonstrate measurable adoption and legacy-method retirement within the first phase of the engagement. Key Responsibilities 1. Microsoft Passkeys for Enterprise (Passwordless Authentication) Design: and lead the enterprise rollout of Microsoft Entra passkey support, including device-bound and synced passkey strategies. Configure Authentication Methods policies to enable passkeys alongside existing MFA/authentication methods, sequenced with the legacy authentication method deprecation described in Section 2. Define enrollment strategy for end users (self-service registration, Temporary Access Pass provisioning, admin-assisted enrollment for high-privilege accounts). Evaluate compatibility across platforms (Windows Hello for Business, mobile authenticator apps, hardware security keys) and browser/device support matrices. Partner with helpdesk/security awareness teams on rollout communications, training, and support escalation paths. Monitor adoption metrics and authentication method usage reporting post-deployment.
2. Deprecation of SMS and Voice Authentication (Phishing-Resistant MFA): Retire SMS and voice call as permitted authentication methods tenant-wide, establishing phishing-resistant MFA as the enterprise standard. Baseline current registration and usage of SMS and voice methods by user population, region, role, and device type. Define and enforce Conditional Access Authentication Strengths to require phishing-resistant methods, with staged scoping that begins with privileged and high-risk accounts and expands to the full user base. Build and govern the exception framework for populations where passkeys are not immediately viable. Partner with the Global Service Desk to harden identity verification and account recovery procedures.
3. Entra Conditional Access Policy Design & Management: Architect, build, and maintain Conditional Access policies governing sign-in risk, device compliance, location, application sensitivity, and user/group scoping. Manage policy lifecycle using report-only mode, staged rollout, and What If tool validation prior to enforcement. Design break-glass/emergency access account exclusions and safeguards to prevent tenant lockout. Integrate Conditional Access with device compliance (Intune), session controls (Conditional Access App Control), sign-in risk (Entra ID Protection), and Global Secure Access, where applicable. Continuously review and optimize policies to reduce gaps, redundant rules, and conflicting conditions across a large, distributed policy set. Document policy intent, scope, and exceptions for audit and compliance purposes.
4. Enterprise Application Permissions & Integrations: Review, govern, and remediate OAuth/OpenID Connect and SAML application permissions across the enterprise application portfolio. Assess delegated vs. application permissions requested by first- and third-party apps; apply least-privilege principles and admin consent workflows. Configure and maintain admin consent policies, permission classifications, and periodic access reviews for enterprise applications. Support integration of enterprise SaaS applications via SSO (SAML/OIDC), provisioning (SCIM), and federation, coordinating with application owners and vendors. Identify and remediate risky or over-privileged application grants (e.g., via Entra ID reporting or Defender for Cloud Apps). Maintain an accurate inventory/catalog of enterprise applications, owners, and permission scopes.
Required Qualifications: 5+ years of hands-on experience administering Microsoft Entra ID (Azure AD) in an enterprise environment. Demonstrated experience leading an organization-wide passkey/FIDO2 rollout to full production at enterprise scale, including Windows Hello for Business, with direct ownership of enrollment campaigns and accountability for adoption outcomes. Demonstrated experience retiring legacy authentication methods (SMS, voice, password-only) in a production tenant. Strong working knowledge of Conditional Access policy design, testing, and staged enforcement in complex, multi-region tenants. Practical experience with enterprise application integration (SSO, SAML/OIDC, SCIM provisioning) and OAuth permission governance. Experience managing App Registration lifecycle and enterprise application security standards. Proficiency with Entra ID Protection, including risk policy configuration and investigation workflows. Proficiency with PowerShell and the Microsoft Graph API for identity automation, bulk migration operations, and adoption/compliance reporting at scale. Familiarity with related Microsoft security tooling (Microsoft Defender for Cloud Apps, Microsoft Purview, Intune) as they intersect with identity controls. Strong understanding of enterprise change management, documentation, and compliance/audit expectations. Excellent communication skills for cross-functional coordination (security, helpdesk, application owners, compliance). Microsoft certifications such as SC-300 (Identity and Access Administrator) or equivalent. Prior experience in large, multi-region environments with 5,000+ identities, or in highly regulated enterprises. Familiarity with hybrid identity (Entra Connect/Cloud Sync) and legacy AD-to-cloud migration considerations.
For applications and inquiries, contact:View email address on us.fitly.work
- DescriptionWe are looking for an experienced Cloud Engineer to lead the design, reliability, and ongoing improvement of cloud infrastructure. This role focuses on building secure, resilient, and high-performing AWS environments while partnering closely with engineering...Suggested
- ...Design, deploy, and support cloud infrastructure and services across Azure, AWS, Salesforce, and other cloud platforms . Build and maintain CI/CD pipelines, Infrastructure as Code (Terraform/YAML), and cloud automation using Azure DevOps. Manage Docker, Kubernetes, serverless...Suggested
$61k - $101k
...Salary: $61,000 - 101,000 per year Requirements: We need experience supporting cloud infrastructure, DevOps, platform engineering, site reliability engineering, or software delivery automation. We need hands-on experience designing or maintaining CI/CD pipelines...SuggestedFull timeContract workWork at office- ...ensuring our platform remains fast, reliable, and scalable is more important than ever.We're looking for an experienced Platform Engineer specializing in Performance Engineering to help define how Weave approaches performance at scale.This isn't a traditional performance...SuggestedRemote work
- ...lives. Our platform sits at the intersection of financial data, cloud-scale infrastructure, and trust, and it has to work, every time... ...: Build patterns and shared tooling that allow the broader engineering teams to operate confidently in the cloud without external reliance...SuggestedWork at office
- DescriptionWe are seeking a Principal Platform Engineer to help shape the technical direction of our cloud platform capabilities and serve as a senior technical partner across engineering, security, and architecture. This role operates at an organizational level, driving...
- ...clients and communities.Job DescriptionWe’re building a new product engineering team to create AI-powered platforms from scratch. Our AI Personal Lines team has already shown what’s possible, standing up cloud infrastructure and delivering a production-ready application in...Work experience placement
- OverviewJob PurposeIS Cybersecurity Engineering maintains, improves, implements, and advises... ...supporting Information Security in order to defend ICE networks, preserve company... ...security, proxies, API security, Python, cloud security, data Loss prevention, container...
- Weave is looking for engineers hungry for fun challenges who can join our self-empowered teams and contribute in both technical and non-... ...sharing expertise and encouraging best practices.Work in a hybrid cloud infrastructure, considering the implementation of functionality...
$180k - $200k
...we'd love to meet you.What You’ll Do We’re seeking a Manager, Engineering to lead and scale our Transformers team as we build next-generation... ...for developing and delivering scalable, secure, and innovative cloud-based systems that are the heart of NetDocuments’ Document...Immediate startFlexible hours- ...The Opportunity: We are seeking a Lead Data Engineer with experience in projects emphasizing complex data solutions. This is a hands-on... ...with migrating legacy systems to data marts/lake Uses additional cloud technologies (e.g., understands concept of Cloud services like...For contractors
- ...Hypercraft's Software Defined Vehicle ecosystem. Carbon is the engineering platform behind every Hypercraft vehicle. It provides the tools... ...Protobuf /gRPC Distributed systems Linux CI/CD Cloud platforms No candidate is expected to have experience in every...Relocation package
- ...Job Description- Senior Database Engineer Location-Remote Role Overview We are looking for a Senior Database Engineer to design, develop... .../Unix environments and scripting. Experience working with cloud database services such as AWS, Azure, or Google Cloud Platform...Remote work
- ...Job Title: Senior Azure Cloud Infrastructure Engineer( 12+years): Location: Wilmington, MA (Hybrid: 2-3 days/week onsite) | Locals only Employment Type: 12+ month contract Technical Skills Required: Needs a 100% Azure cloud infrastructure person IAC Working with the...Contract workLocal area2 days per week3 days per week
- ...Senior Azure AI Document Intelligence Engineer OCR Introduction: We are currently seeking a Senior Azure AI Document Intelligence Engineer with expertise in Optical Character Recognition (OCR) to join our team. This role will be based in Irving, TX with a hybrid work...Contract work
- ...moments. Your Role at Pura: We are seeking a Staff Software Engineer (Platform Team) to join our team and be a technical leader in... ...direction based on the needs of the business ~ Deep experience with cloud platforms and services (We use AWS), including architecture,...Local areaRemote work
$97.5k - $130k
...Azure Data Engineer Salary: $97,500-$130,000 Job Summary We are seeking an experienced Azure Data Engineer with strong Databricks expertise to design, develop, and support scalable cloud-based data solutions. This role is responsible for building and maintaining modern...$180k - $200k
...year Requirements: ~ Bachelors degree in Computer Science, Engineering, or a related discipline; an advanced degree is preferred. ~5... ...with business strategy. ~ Strong background in distributed, cloud-based product development, ideally with Azure or AWS. ~ Solid...Full timeImmediate startFlexible hours- ...Salesforce orgs leveraging Public Sector Solutions, Experience Cloud, Service Cloud, and Sales Cloud, each with unique business processes... ...or university in Computer Science, Information Systems, Engineering, or a related field. Minimum of five years of professional Salesforce...Local area
- ...Architectural Designer & Drafter in Utah to create permit-ready construction documents, 3D models, and detailed plans supporting engineering, manufacturing, and installation teams. The role requires producing site plans, floor plans, elevations, sections, and architectural...
- ...Key Responsibilities: Lead and manage architectural projects from conception to completion Collaborate with clients, engineers, and other stakeholders to ensure project success Produce detailed drawings, specifications, and cost estimates Ensure compliance...
- ...Workplaces®. We are looking for a visionary Staff Data Platform Engineer to lead the design, architecture, and implementation of our... ...backend software engineering with a "Data Fanatic" mindset. ~ Cloud Mastery: Strong expertise in cloud environments, container...Casual workLocal areaImmediate start
- ...migration and building the shared agent surfaces that power all AI features across the company. Partnering with cross-functional engineering teams, you will eliminate technical debt, elevate UI infrastructure, and lay the foundation that accelerates every product feature...
- ...winner of the Security Today Govies Award for 2025. ABOUT THIS ROLE As a Senior DevOps Engineer at LVT, you will play a pivotal role in designing, scaling, and securing the cloud infrastructure and platform engineering solutions that power our next-generation Agentic...Full timeWork at officeFlexible hours
- Title: ServiceNow Lead Technical Consultant - ITOM Certifications Required: CSA, Discovery, Agent Client Connector, CMDB Location: Remote Additional Details Lead level ITOM consultant who knows Discovery, CMDB and Agent Client Connector (ACC) to ...Remote work
$92.39k - $106.4k
...and other factors. Implement complex Ethernet switch configuration and testing. Responsibilities: Provides design, engineering and maintenance assistance on the UCSD campus WLAN/LAN/WAN. Provides consultation, evaluation, installation and testing of network...Hourly payContract workWork at officeLocal areaWeekend workAfternoon shift$51.6k - $121.1k
...clear written deliverables and briefings. Partner with data engineers/data architects to support data definitions, lineage, and... ...non essential skills required: Experience working with cloud data platforms (AWS, Azure, etc.). Familiarity with data warehousing...Local area- RESPONSIBILITIES: A client with OpenKyber is seeking a Support Operations Analyst III to join their team in Tucson, AZ. Weekend hours are required certain months out of the year. Generally during, but not limited to, October, January - April. This is to meet the needs of...Hourly payContract workWeekend work
- Role: Program Manager - Database Business Intelligence Projects Location: McLean, VA Key Responsibilities Job Description: We are seeking an experienced Program Manager or seasoned Pre-Sales professional with a strong data background to lead and manage a large-scale...
- ...The following requirement is open with our client. Title : BI Engineer Location : Charlotte, NC 28202 Hybrid / Onsite Rate : $56/hr on... ...architecture, load balancing, Windows/Linux environments, Google Cloud Platform cloud infrastructure, automation, scripting, and CI/CD...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Defender for Cloud Engineer. Be the first to apply!



