IAM Architect
Openkyber
ONLY FOR W2 CANDIDATES || URGENTLY LOOKING FOR Lead IAM ENGINEER || Hybrid -- Morrisville, NC or Salem, NH Role: Lead IAM Engineer Location: Hybrid -- Morrisville, NC or Salem, NH Duration: 10+ months Looking for candidates local to Morrisville, NC or Salem, NH or will relocate day 1 and be hybrid 2/3 days a week onsite This is a high-level role looking for a Lead type candidate that also has some architecture/design experience. Design and lead the enterprise rollout of Microsoft Entra passkey) support, including device-bound and synced passkey strategies. Configure Authentication Methods policies to enable passkeys alongside existing MFA/authentication methods, sequenced with the legacy authentication method deprecation Must have enterprise level experience - multi-region environments with 5,000+ identities, or in highly regulated enterprises. Position Summary We are seeking an experienced Microsoft Identity Management contractor to design, implement, and harden identity security controls across a global enterprise tenant. This role is hands-on and delivery-focused, covering enterprise passkey deployment, the retirement of SMS and voice authentication in favor of phishing-resistant MFA, Conditional Access policy engineering, application integration governance, and identity risk detection. The ideal candidate has deep, current expertise in the Microsoft Entra ID platform and is comfortable operating in a large, multi-region enterprise with strict compliance and change-management requirements. The immediate and highest-priority deliverable for this engagement is the enterprise passkey deployment and the accompanying deprecation of SMS and voice authentication methods, both on an accelerated timeline. Candidates should be prepared to lead this work from day one and to demonstrate measurable adoption and legacy-method retirement within the first phase of the engagement. Key Responsibilities 1. Microsoft Passkeys for Enterprise (Passwordless Authentication) Design and lead the enterprise rollout of Microsoft Entra passkey support, including device-bound and synced passkey strategies. Configure Authentication Methods policies to enable passkeys alongside existing MFA/authentication methods, sequenced with the legacy authentication method deprecation described in Section 2. Define enrollment strategy for end users (self-service registration, Temporary Access Pass provisioning, admin-assisted enrollment for high-privilege accounts). Evaluate compatibility across platforms (Windows Hello for Business, mobile authenticator apps, hardware security keys) and browser/device support matrices. Partner with helpdesk/security awareness teams on rollout communications, training, and support escalation paths. Monitor adoption metrics and authentication method usage reporting post-deployment. 2. Deprecation of SMS and Voice Authentication (Phishing-Resistant MFA) Retire SMS and voice call as permitted authentication methods tenant-wide, establishing phishing-resistant MFA as the enterprise standard. Baseline current registration and usage of SMS and voice methods by user population, region, role, and device type. Define and enforce Conditional Access Authentication Strengths to require phishing-resistant methods, with staged scoping that begins with privileged and high-risk accounts and expands to the full user base. Build and govern the exception framework for populations where passkeys are not immediately viable. Partner with the Global Service Desk to harden identity verification and account recovery procedures. 3. Entra Conditional Access Policy Design & Management Architect, build, and maintain Conditional Access policies governing sign-in risk, device compliance, location, application sensitivity, and user/group scoping. Manage policy lifecycle using report-only mode, staged rollout, and What If tool validation prior to enforcement. Design break-glass/emergency access account exclusions and safeguards to prevent tenant lockout. Integrate Conditional Access with device compliance (Intune), session controls (Conditional Access App Control), sign-in risk (Entra ID Protection), and Global Secure Access, where applicable. Continuously review and optimize policies to reduce gaps, redundant rules, and conflicting conditions across a large, distributed policy set. Document policy intent, scope, and exceptions for audit and compliance purposes. 4. Enterprise Application Permissions & Integrations Review, govern, and remediate OAuth/OpenID Connect and SAML application permissions across the enterprise application portfolio. Assess delegated vs. application permissions requested by first- and third-party apps; apply least-privilege principles and admin consent workflows. Configure and maintain admin consent policies, permission classifications, and periodic access reviews for enterprise applications. Support integration of enterprise SaaS applications via SSO (SAML/OIDC), provisioning (SCIM), and federation, coordinating with application owners and vendors. Identify and remediate risky or over-privileged application grants (e.g., via Entra ID reporting or Defender for Cloud Apps). Maintain an accurate inventory/catalog of enterprise applications, owners, and permission scopes. Required Qualifications 5+ years of hands-on experience administering Microsoft Entra ID (Azure AD) in an enterprise environment. Demonstrated experience leading an organization-wide passkey/FIDO2 rollout to full production at enterprise scale, including Windows Hello for Business, with direct ownership of enrollment campaigns and accountability for adoption outcomes. Demonstrated experience retiring legacy authentication methods (SMS, voice, password-only) in a production tenant. Strong working knowledge of Conditional Access policy design, testing, and staged enforcement in complex, multi-region tenants. Practical experience with enterprise application integration (SSO, SAML/OIDC, SCIM provisioning) and OAuth permission governance. Experience managing App Registration lifecycle and enterprise application security standards. Proficiency with Entra ID Protection, including risk policy configuration and investigation workflows. Proficiency with PowerShell and the Microsoft Graph API for identity automation, bulk migration operations, and adoption/compliance reporting at scale. Familiarity with related Microsoft security tooling (Microsoft Defender for Cloud Apps, Microsoft Purview, Intune) as they intersect with identity controls. Strong understanding of enterprise change management, documentation, and compliance/audit expectations. Excellent communication skills for cross-functional coordination (security, helpdesk, application owners, compliance). Preferred Qualifications Microsoft certifications such as SC-300 (Identity and Access Administrator) or equivalent. Prior experience in large, multi-region environments with 5,000+ identities, or in highly regulated enterprises. Familiarity with hybrid identity (Entra Connect/Cloud Sync) and legacy AD-to-cloud migration considerations. Regards, OpenKyber
For applications and inquiries, contact:View email address on us.fitly.work
Vacancy posted 2 days ago
Similar jobs that could be interesting for youBased on the IAM Architect in Maryland, MD vacancy
$75 per hour
...Devops Architect Role: Certified - Application Security Architect(AWS) Level: Senior (8 12 years) Location: Remote Client: OpenKyber... ..., GuardDuty, Inspector, Security Hub, KMS, Secrets Manager, IAM. Define and enforce least-privilege IAM policies, secrets management...SuggestedRemote work$148.2k - $222.4k
...career success. Ready to join us? Here’s what the opportunity supported through our TGS Talent Acquisition Team requires: The IAM Practice Architect is a senior technical leader responsible for the execution and delivery of enterprise Identity and Access Management (IAM)...SuggestedPermanent employmentFull timeTemporary workRemote work- ...motivated, career and customer-oriented Senior NetApps Storage Architect to join our team in Laurel, MD. Join ManTech’s mission-... ...Hypervisor Technologies (NUTANIX, VMWARE VCF, OpenStack). ~ IAM II certification (DoD 8140 required upon start of employment....Suggested
- ...and Access Management specialist in College Park, Maryland. The selected candidate will play a vital role in designing and deploying IAM solutions using Ping technology to protect sensitive data for clients within the Department of Defense and Intelligence Community. Ideal...Suggested
- ...Job Title: Gemini AI Architect Location: San Ramon, CA - Hybrid (3 Days Onsite Weekly) Job Type: Contract Job Overview Our client is seeking... ...Google Cloud Platform: Cloud Run, GKE, Vertex AI, networking, IAM Preferred Skills: Production deployment of agents on...SuggestedContract work
- ...Position: Identity Architect (Enterprise Identity & Directory Services) Location: Remote or In Office Employment Type: W-2... ...Replication, RODCs, and secure delegation Partner with IAM teams to design secure privileged access models (PAWs, tiering,...Work at officeRemote work
- ...GenAI Architect Location: Mount Laurel, NJ Duration: Contract / Full Time Must Have: AI/GenAI- open source/commercial LLM; Python; Azure; Databricks Develop; fine‐tune; and optimize LLMs; multimodal models; and generative AI pipelines for various business...Full timeContract workWork at office
- ...Salesforce Architect Design and architect end-to-end Salesforce solutions across Sales Cloud, Service Cloud, Experience Cloud, and other Salesforce products. Gather and analyze business requirements and translate them into scalable technical solutions. Define...
$136k - $204k
...supported through our TGS Talent Acquisition Team requires:The Practice Architect, Level 1 is a hands-on technical leader who translates... ...GCP, AWS, or Azure), including compute, storage, networking, and IAM fundamentals.• Proven ability to design and document solution architectures...Permanent employmentFull timeTemporary workRemote work$112.9k - $257k
...know how to bake it in. You can identify and implement ways to harden systems and reduce their attack surface.As a Cybersecurity Architect on our project, you’ll lead the architecture and design efforts of innovative cybersecurity solutions and service offerings to protect...Full timeContract workPart timeWork at officeLocal areaRemote work- ...SRE Architect Seattle, WA JD- Experience defining and implementing SLI, SLO, SLA, Error Budget, and Reliability Governance frameworks. Expertise in Dynatrace and other enterprise observability platforms, including APM, Distributed Tracing, RUM, Synthetic Monitoring,...
- ...opening for the below position. If this opportunity interests you, please let me know. Title: Observability Lead/ Victoria Metrics Architect Location: O verland Park, KS or Dallas , TX or Remote Expert Deep, hands-on production ownership. Design and delivery-ready from...Remote work
- Position Title: ITOM Administrator Duration: 12 months (Hybrid) Location: Poughkeepsie, New York Experience ServiceNow ITOM CMDB Discovery Service Mapping Event Management CSDM Identification & Reconciliation Engine...
- ...Job Details: Architect: Responsible for the design of projects from early concept through construction documents including execution of building code and life safety analysis, design narratives, specification editing, and material / product selection. coordinate...
- Svitla Systems Inc. is looking for a Red Hat OpenShift Architect for a full-time on-site position (40 hours per week) in College Park, Maryland... .... Strong understanding of Identity and Access Management (IAM). Knowledge of security and regulatory compliance frameworks, including...Full timeWork at officeRemote work
- BAC (Baltimore Aircoil Company, Inc.) is seeking an organized Recruiting Operations Coordinator to streamline the candidate journey and support the hiring team across scheduling, communications, and systems. You will manage interview logistics, maintain ATS data integrity...
$123.5k - $164.7k
...Principal Architect Las Vegas, Nevada The SHOW comes alive at MGM Resorts International Have you ever wondered what it would be like to work in a place full of excitement, diversity, and entertainment? Are you enthusiastic about being a team player in one of the...Work at officeShift work- ...Senior Architect, AI And Emerging Technology Architecture Collaborative Environment, Transformational Projects, and a Growing Team! As a member of AI and Emerging Technology Architecture, you'll be joining a strategic and collaborative team that is passionate about...Work experience placementLocal area
- Team Carney is seeking an experienced Instructional Systems Specialist for an onsite role in Laurel, Maryland. You will design and develop course materials, assessments, and evaluation strategies for complex instruction targeted to law enforcement, professionals, and technical...
$10k
...technology allowances, and access to a state-of-the-art technology lab. Learn more at Your Mission Join ClearEdge as a Chief Architect, where you will set the technical direction and architecture for one of our core AI-enabled products, supporting deployment across...- ...Job Title: ServiceNow ITOM Architect Location: Philadelphia, PA Duration: Contract Job Description: The ServiceNow Technical Architect will design, build, and oversee custom solutions on the ServiceNow platform. This role focuses on defining platform patterns, managing...Contract workFlexible hours
- ...Role- SAP Architect Contractor Remote role The services You will provide the Client project team: As an SAP Architect Contractor, you will be responsible for designing and implementing SAP solutions to meet business needs and align with architectural standards...For contractorsRemote work
- ...friendly interfaces aligned with business requirements and UX standards. Collaborate with Product Owners, Business Analysts, Architects, and UX teams to translate requirements into solutions. Participate in migration and modernization initiatives from Service...Remote work
$100k - $140k
...customer environment. We require an active Top Secret/SCI clearance with Polygraph. Responsibilities: We will have you design, architect, configure, deploy, upgrade, and support a range of storage and backup platforms, along with the related management tools. You...Full timeWork at office- Our client is seeking a Senior BI Platform Administrator to own and evolve the enterprise Business Intelligence infrastructure across Power BI, Microsoft Fabric, and Snowflake. This is a hands-on technical leadership role at the intersection of data engineering, platform...
- Jr. SAP Vistex Consultant ABAP & S/4HANA Job Type: Contract Location: Remote CST Hours Duration: Long-Term Contract Job Description We are looking for a Junior SAP Vistex Consultant with hands-on or project experience in SAP Vistex, ABAP, and S/4HANA to support development...Long term contractContract workRemote work
- Design end-to-end SAP BTP architecture, including Integration Suite, Extension Suite, and data/analytics services Lead configuration, development, and deployment of BTP services to support scalable and secure business processes Define integration patterns, API...
- The ServiceNow Application Developer will: Serve as a primary administrator for the DCPS ServiceNow instance, supporting day-to-day service operations and maintenance. Configure and maintain ServiceNow applications, including forms, lists, workflows/flows, notifications...Work at office
- Role: SAP S/4HANA SD & Service Module Lead Consultant Location: Boston, MA(Onsite) Duration: 12 Months Type: Contract Key responsibilities Lead full lifecycle projects using SAP Activate: Discover, Prepare, Explore, Realize, Deploy...Contract work
- ...Morris & Ritchie Associates, Inc. (MRA) is looking for a creative and driven Landscape Architect with 5 - 8+ years of experience to join our talented team in Laurel, Maryland . This is a fantastic opportunity to contribute to an exciting mix of commercial, institutional...Temporary workFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to IAM Architect. Be the first to apply!



