Senior Architect- Microsoft Entra Identity & Access Management (IAM) Security
VDart Inc
Role: Senior Architect Microsoft Entra Identity & Access Management (IAM) Security
Location: Dallas, TX (Hybrid)
Type: Contract
Role Summary:
- The Senior Architect / Engineer Microsoft Entra IAM Security is responsible for defining, designing, and engineering enterprise identity security solutions using Microsoft Entra ID and the broader Microsoft identity security ecosystem.
- This role provides senior technical leadership for identity architecture, authentication, authorization, privileged access, identity governance, application access, and hybrid/cloud identity security. The architect establishes IAM security patterns and standards while also providing hands-on engineering leadership for complex implementations, migrations, integrations, and security remediation initiatives.
- The position serves as a subject-matter expert for identity-centric Zero Trust security, partnering with cybersecurity, cloud, infrastructure, application, risk, compliance, and enterprise architecture teams to reduce identity-related risk and protect access to critical enterprise resources.
Key Responsibilities:
- Define enterprise Microsoft Entra IAM security architecture, standards, reference architectures, design patterns, and engineering guardrails.
- Architect secure identity solutions across cloud, hybrid, multi-cloud, SaaS, and on-premises environments.
- Develop and implement an identity-centric Zero Trust architecture, emphasizing continuous verification, least privilege, strong authentication, and risk-based access.
- Design enterprise Conditional Access strategies covering users, administrators, workloads, applications, devices, authentication strength, and risk.
- Architect phishing-resistant and passwordless authentication solutions using FIDO2/passkeys, Windows Hello for Business, certificate-based authentication, and other supported authentication methods.
- Design and govern Privileged Identity Management (PIM) and privileged-access models to minimize standing administrative privileges and enforce just-in-time access.
- Establish security architecture for workload identities, managed identities, service principals, application registrations, API permissions, and secrets/certificate management.
- Architect secure application authentication and authorization using OAuth 2.0, OpenID Connect, SAML 2.0, SCIM, Microsoft Graph, and modern authentication patterns.
- Design Entra ID Governance capabilities, including entitlement management, access reviews, lifecycle workflows, separation of duties, and automated identity lifecycle controls.
- Define security architecture for joiner, mover, and leaver (JML) processes and ensure timely provisioning, modification, and removal of access.
- Design and review hybrid identity security, including Active Directory integration, Entra Connect/Cloud Sync, authentication flows, and protection of privileged identity paths.
- Lead IAM threat modeling and security architecture reviews for new applications, platforms, cloud services, and major technology initiatives.
- Identify identity-related attack paths, excessive privileges, legacy authentication dependencies, insecure application permissions, and other IAM security risks.
- Design controls for detecting and responding to identity compromise, credential theft, token abuse, risky sign-ins, privilege escalation, and unauthorized access.
- Define identity logging, monitoring, and alerting requirements and integrate Entra telemetry with SIEM/SOC and security operations processes.
- Provide architecture and engineering leadership during complex identity security incidents and root-cause investigations.
- Develop automation using Microsoft Graph API, PowerShell, REST APIs, and infrastructure-as-code/policy-as-code approaches to improve security consistency and reduce manual administration.
- Lead IAM modernization, tenant consolidation, authentication modernization, application migration, and security-hardening initiatives.
- Evaluate new Microsoft identity capabilities and recommend adoption based on security benefits, operational impact, architectural fit, and organizational risk.
- Mentor IAM engineers and architects and provide technical leadership across IAM/security engineering teams.
Security Architecture Focus
- The successful candidate should demonstrate deep expertise in designing controls that protect identities as a primary enterprise security boundary. Key areas should include:
- Zero Trust identity architecture
- Least privilege and Just-in-Time/Just-Enough Administration
- Conditional Access architecture and policy design
- Phishing-resistant MFA and authentication strength
- Passwordless authentication
- Privileged Access Management / PIM
- Identity Protection and risk-based access
- Workload identity and service principal security
- OAuth consent and application permission governance
- Token and session security
- Identity Governance and access certification
- RBAC and authorization architecture
- Administrative tiering and privileged account separation
- Break-glass/emergency access architecture
- Legacy authentication elimination
- Hybrid identity and Active Directory security
- Identity threat detection and incident response
- Identity security posture management
- Separation of duties and toxic-access controls
Required Technical Skills:
- Deep expertise with Microsoft Entra ID, including Conditional Access, PIM, Identity Protection, ID Governance, Enterprise Applications, App Registrations, workload identities, authentication methods, Microsoft Graph, and hybrid identity.
- Strong knowledge of Active Directory, Entra Connect/Cloud Sync, Microsoft 365 identity integration, Azure RBAC, and the relationship between cloud and on-premises identity security.
- Advanced understanding of identity protocols and standards including OAuth 2.0, OpenID Connect, SAML 2.0, SCIM, Kerberos, LDAP, and modern authentication.
- Strong automation capabilities using PowerShell and Microsoft Graph API, with experience applying automation to identity provisioning, security controls, policy deployment, reporting, and governance.
- Strong understanding of identity-related security threats, including credential theft, token theft/replay, MFA bypass techniques, consent phishing, privilege escalation, compromised service principals, excessive application permissions, and lateral movement involving identity systems.
Architecture & Leadership Expectations
- This is not primarily an Entra administration role. The Senior Architect / Engineer is expected to:
- Translate business, cybersecurity, regulatory, and risk requirements into scalable IAM architectures.
- Make and defend complex identity security architecture decisions.
- Balance security requirements against user experience, operational complexity, resilience, and business requirements.
- Establish reusable enterprise architecture patterns rather than designing one-off solutions.
- Conduct architecture and security reviews and identify material IAM risks.
- Provide technical leadership for complex implementations and security remediation.
- Influence application, cloud, infrastructure, and cybersecurity architecture beyond the IAM organization.
- Communicate identity risks and architectural decisions effectively to both technical teams and senior stakeholders.
- Remain technically hands-on enough to validate designs, develop proofs of concept, troubleshoot complex problems, and guide engineering teams through implementation.
Experience:
- Typically 10+ years of experience in Identity & Access Management, cybersecurity, infrastructure security, or related disciplines, including substantial experience designing Microsoft identity solutions.
- Candidates should have demonstrated experience architecting IAM solutions in large, complex enterprise environments, preferably including hybrid identity, large application portfolios, privileged-access environments, and regulated or security-sensitive workloads.
- Experience leading major identity transformation programs-such as Zero Trust adoption, MFA/passwordless transformation, Conditional Access modernization, Active Directory/Entra modernization, privileged-access transformation, or migration from legacy IAM/federation platforms-is highly desirable.
Preferred Certifications:
- Relevant certifications may include Microsoft Certified: Cybersecurity Architect Expert (SC-100), Microsoft Certified: Identity and Access Administrator Associate (SC-300), CISSP, CCSP, SABSA, TOGAF, Azure security/architecture certifications, or equivalent identity and cybersecurity credentials.
Vacancy posted more than 2 months ago
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior Architect- Microsoft Entra Identity & Access Management (IAM) Security. Be the first to apply!
Related searches
- senior living director Dallas, TX
- senior manager customer operations Dallas, TX
- senior support engineer Dallas, TX
- senior java developer Dallas, TX
- senior software engineer ruby on rails Dallas, TX
- sr finance manager Dallas, TX
- sr marketing manager Dallas, TX
- senior customer service Dallas, TX
- senior business manager Dallas, TX
- senior account executive Dallas, TX
