Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Senior Architect- Microsoft Entra Identity & Access Management (IAM) Security

VDart Inc

Role: Senior Architect Microsoft Entra Identity & Access Management (IAM) Security

Location: Dallas, TX (Hybrid)

Type: Contract

Role Summary:

  • The Senior Architect / Engineer Microsoft Entra IAM Security is responsible for defining, designing, and engineering enterprise identity security solutions using Microsoft Entra ID and the broader Microsoft identity security ecosystem.
  • This role provides senior technical leadership for identity architecture, authentication, authorization, privileged access, identity governance, application access, and hybrid/cloud identity security. The architect establishes IAM security patterns and standards while also providing hands-on engineering leadership for complex implementations, migrations, integrations, and security remediation initiatives.
  • The position serves as a subject-matter expert for identity-centric Zero Trust security, partnering with cybersecurity, cloud, infrastructure, application, risk, compliance, and enterprise architecture teams to reduce identity-related risk and protect access to critical enterprise resources.

Key Responsibilities:

  • Define enterprise Microsoft Entra IAM security architecture, standards, reference architectures, design patterns, and engineering guardrails.
  • Architect secure identity solutions across cloud, hybrid, multi-cloud, SaaS, and on-premises environments.
  • Develop and implement an identity-centric Zero Trust architecture, emphasizing continuous verification, least privilege, strong authentication, and risk-based access.
  • Design enterprise Conditional Access strategies covering users, administrators, workloads, applications, devices, authentication strength, and risk.
  • Architect phishing-resistant and passwordless authentication solutions using FIDO2/passkeys, Windows Hello for Business, certificate-based authentication, and other supported authentication methods.
  • Design and govern Privileged Identity Management (PIM) and privileged-access models to minimize standing administrative privileges and enforce just-in-time access.
  • Establish security architecture for workload identities, managed identities, service principals, application registrations, API permissions, and secrets/certificate management.
  • Architect secure application authentication and authorization using OAuth 2.0, OpenID Connect, SAML 2.0, SCIM, Microsoft Graph, and modern authentication patterns.
  • Design Entra ID Governance capabilities, including entitlement management, access reviews, lifecycle workflows, separation of duties, and automated identity lifecycle controls.
  • Define security architecture for joiner, mover, and leaver (JML) processes and ensure timely provisioning, modification, and removal of access.
  • Design and review hybrid identity security, including Active Directory integration, Entra Connect/Cloud Sync, authentication flows, and protection of privileged identity paths.
  • Lead IAM threat modeling and security architecture reviews for new applications, platforms, cloud services, and major technology initiatives.
  • Identify identity-related attack paths, excessive privileges, legacy authentication dependencies, insecure application permissions, and other IAM security risks.
  • Design controls for detecting and responding to identity compromise, credential theft, token abuse, risky sign-ins, privilege escalation, and unauthorized access.
  • Define identity logging, monitoring, and alerting requirements and integrate Entra telemetry with SIEM/SOC and security operations processes.
  • Provide architecture and engineering leadership during complex identity security incidents and root-cause investigations.
  • Develop automation using Microsoft Graph API, PowerShell, REST APIs, and infrastructure-as-code/policy-as-code approaches to improve security consistency and reduce manual administration.
  • Lead IAM modernization, tenant consolidation, authentication modernization, application migration, and security-hardening initiatives.
  • Evaluate new Microsoft identity capabilities and recommend adoption based on security benefits, operational impact, architectural fit, and organizational risk.
  • Mentor IAM engineers and architects and provide technical leadership across IAM/security engineering teams.

Security Architecture Focus

  • The successful candidate should demonstrate deep expertise in designing controls that protect identities as a primary enterprise security boundary. Key areas should include:
    • Zero Trust identity architecture
    • Least privilege and Just-in-Time/Just-Enough Administration
    • Conditional Access architecture and policy design
    • Phishing-resistant MFA and authentication strength
    • Passwordless authentication
    • Privileged Access Management / PIM
    • Identity Protection and risk-based access
    • Workload identity and service principal security
    • OAuth consent and application permission governance
    • Token and session security
    • Identity Governance and access certification
    • RBAC and authorization architecture
    • Administrative tiering and privileged account separation
    • Break-glass/emergency access architecture
    • Legacy authentication elimination
    • Hybrid identity and Active Directory security
    • Identity threat detection and incident response
    • Identity security posture management
    • Separation of duties and toxic-access controls

Required Technical Skills:

  • Deep expertise with Microsoft Entra ID, including Conditional Access, PIM, Identity Protection, ID Governance, Enterprise Applications, App Registrations, workload identities, authentication methods, Microsoft Graph, and hybrid identity.
  • Strong knowledge of Active Directory, Entra Connect/Cloud Sync, Microsoft 365 identity integration, Azure RBAC, and the relationship between cloud and on-premises identity security.
  • Advanced understanding of identity protocols and standards including OAuth 2.0, OpenID Connect, SAML 2.0, SCIM, Kerberos, LDAP, and modern authentication.
  • Strong automation capabilities using PowerShell and Microsoft Graph API, with experience applying automation to identity provisioning, security controls, policy deployment, reporting, and governance.
  • Strong understanding of identity-related security threats, including credential theft, token theft/replay, MFA bypass techniques, consent phishing, privilege escalation, compromised service principals, excessive application permissions, and lateral movement involving identity systems.

Architecture & Leadership Expectations

  • This is not primarily an Entra administration role. The Senior Architect / Engineer is expected to:
    • Translate business, cybersecurity, regulatory, and risk requirements into scalable IAM architectures.
    • Make and defend complex identity security architecture decisions.
    • Balance security requirements against user experience, operational complexity, resilience, and business requirements.
    • Establish reusable enterprise architecture patterns rather than designing one-off solutions.
    • Conduct architecture and security reviews and identify material IAM risks.
    • Provide technical leadership for complex implementations and security remediation.
    • Influence application, cloud, infrastructure, and cybersecurity architecture beyond the IAM organization.
    • Communicate identity risks and architectural decisions effectively to both technical teams and senior stakeholders.
    • Remain technically hands-on enough to validate designs, develop proofs of concept, troubleshoot complex problems, and guide engineering teams through implementation.

Experience:

  • Typically 10+ years of experience in Identity & Access Management, cybersecurity, infrastructure security, or related disciplines, including substantial experience designing Microsoft identity solutions.
  • Candidates should have demonstrated experience architecting IAM solutions in large, complex enterprise environments, preferably including hybrid identity, large application portfolios, privileged-access environments, and regulated or security-sensitive workloads.
  • Experience leading major identity transformation programs-such as Zero Trust adoption, MFA/passwordless transformation, Conditional Access modernization, Active Directory/Entra modernization, privileged-access transformation, or migration from legacy IAM/federation platforms-is highly desirable.

Preferred Certifications:

  • Relevant certifications may include Microsoft Certified: Cybersecurity Architect Expert (SC-100), Microsoft Certified: Identity and Access Administrator Associate (SC-300), CISSP, CCSP, SABSA, TOGAF, Azure security/architecture certifications, or equivalent identity and cybersecurity credentials.

Vacancy posted more than 2 months ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Senior Architect- Microsoft Entra Identity & Access Management (IAM) Security. Be the first to apply!