Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Defender for Cloud Engineer

Openkyber

Hi, Hope you're doing well!! Please find the requirement below. If you find yourself comfortable with the requirement please reply back with your updated resume or call me back at ) Identity & Access Management (IAM) Engineer Location: 9 Northeastern Blvd Ste 400, Salem, NH 03079 2121 RDU Center Drive, Suite 300, Morrisville, NC 27560. Hybrid Hours: East Coast hours (will be required to travel) Why Open: New Project need Start Date: ASAP Duration: December 2025- July 2027 (10+ months) Position Summary We are seeking an experienced Microsoft Identity Management contractor to design, implement, and harden identity security controls across a global enterprise tenant. This role is hands-on and delivery-focused, covering enterprise passkey deployment, the retirement of SMS and voice authentication in favor of phishing-resistant MFA, Conditional Access policy engineering, application integration governance, and identity risk detection. The ideal candidate has deep, current expertise in the Microsoft Entra ID platform and is comfortable operating in a large, multi-region enterprise with strict compliance and change-management requirements. The immediate and highest-priority deliverable for this engagement is the enterprise passkey deployment and the accompanying deprecation of SMS and voice authentication methods, both on an accelerated timeline. Candidates should be prepared to lead this work from day one and to demonstrate measurable adoption and legacy-method retirement within the first phase of the engagement. Key Responsibilities 1. Microsoft Passkeys for Enterprise (Passwordless Authentication) Design: and lead the enterprise rollout of Microsoft Entra passkey support, including device-bound and synced passkey strategies. Configure Authentication Methods policies to enable passkeys alongside existing MFA/authentication methods, sequenced with the legacy authentication method deprecation described in Section 2. Define enrollment strategy for end users (self-service registration, Temporary Access Pass provisioning, admin-assisted enrollment for high-privilege accounts). Evaluate compatibility across platforms (Windows Hello for Business, mobile authenticator apps, hardware security keys) and browser/device support matrices. Partner with helpdesk/security awareness teams on rollout communications, training, and support escalation paths. Monitor adoption metrics and authentication method usage reporting post-deployment.



2. Deprecation of SMS and Voice Authentication (Phishing-Resistant MFA): Retire SMS and voice call as permitted authentication methods tenant-wide, establishing phishing-resistant MFA as the enterprise standard. Baseline current registration and usage of SMS and voice methods by user population, region, role, and device type. Define and enforce Conditional Access Authentication Strengths to require phishing-resistant methods, with staged scoping that begins with privileged and high-risk accounts and expands to the full user base. Build and govern the exception framework for populations where passkeys are not immediately viable. Partner with the Global Service Desk to harden identity verification and account recovery procedures.



3. Entra Conditional Access Policy Design & Management: Architect, build, and maintain Conditional Access policies governing sign-in risk, device compliance, location, application sensitivity, and user/group scoping. Manage policy lifecycle using report-only mode, staged rollout, and What If tool validation prior to enforcement. Design break-glass/emergency access account exclusions and safeguards to prevent tenant lockout. Integrate Conditional Access with device compliance (Intune), session controls (Conditional Access App Control), sign-in risk (Entra ID Protection), and Global Secure Access, where applicable. Continuously review and optimize policies to reduce gaps, redundant rules, and conflicting conditions across a large, distributed policy set. Document policy intent, scope, and exceptions for audit and compliance purposes.



4. Enterprise Application Permissions & Integrations: Review, govern, and remediate OAuth/OpenID Connect and SAML application permissions across the enterprise application portfolio. Assess delegated vs. application permissions requested by first- and third-party apps; apply least-privilege principles and admin consent workflows. Configure and maintain admin consent policies, permission classifications, and periodic access reviews for enterprise applications. Support integration of enterprise SaaS applications via SSO (SAML/OIDC), provisioning (SCIM), and federation, coordinating with application owners and vendors. Identify and remediate risky or over-privileged application grants (e.g., via Entra ID reporting or Defender for Cloud Apps). Maintain an accurate inventory/catalog of enterprise applications, owners, and permission scopes.



Required Qualifications: 5+ years of hands-on experience administering Microsoft Entra ID (Azure AD) in an enterprise environment. Demonstrated experience leading an organization-wide passkey/FIDO2 rollout to full production at enterprise scale, including Windows Hello for Business, with direct ownership of enrollment campaigns and accountability for adoption outcomes. Demonstrated experience retiring legacy authentication methods (SMS, voice, password-only) in a production tenant. Strong working knowledge of Conditional Access policy design, testing, and staged enforcement in complex, multi-region tenants. Practical experience with enterprise application integration (SSO, SAML/OIDC, SCIM provisioning) and OAuth permission governance. Experience managing App Registration lifecycle and enterprise application security standards. Proficiency with Entra ID Protection, including risk policy configuration and investigation workflows. Proficiency with PowerShell and the Microsoft Graph API for identity automation, bulk migration operations, and adoption/compliance reporting at scale. Familiarity with related Microsoft security tooling (Microsoft Defender for Cloud Apps, Microsoft Purview, Intune) as they intersect with identity controls. Strong understanding of enterprise change management, documentation, and compliance/audit expectations. Excellent communication skills for cross-functional coordination (security, helpdesk, application owners, compliance). Microsoft certifications such as SC-300 (Identity and Access Administrator) or equivalent. Prior experience in large, multi-region environments with 5,000+ identities, or in highly regulated enterprises. Familiarity with hybrid identity (Entra Connect/Cloud Sync) and legacy AD-to-cloud migration considerations.

For applications and inquiries, contact:View email address on us.fitly.work

Vacancy posted 2 days ago
Similar jobs that could be interesting for youBased on the Defender for Cloud Engineer in Arkansas County, AR vacancy
  • $71 - $79 per hour

     ...OpenKyber is looking for an Azure Cloud Architect/Engineer to enable Cloud Cybersecurity controls and compliance requirements and remediation...  ...such as: Extended Detection and Response (XDR): Microsoft Defender for Cloud Apps, Microsoft Defender for Endpoint, Microsoft... 
    Suggested
    Hourly pay
    Contract work
    Work at office
    Remote work
    Visa sponsorship

    Openkyber

    Arkansas County, AR
    2 days ago
  •  ...prepare HLD/LLD documents, and support architecture governance processes. Participate in Architecture Review Boards and confidently defend technical designs and implementation strategies. Integrate ServiceNow with security tools such as Microsoft Defender,... 
    Suggested
    Long term contract

    Openkyber

    Arkansas County, AR
    2 days ago
  • Azure Virtual Machines: Practical experience with Azure Virtual Machines. Azure Backup and Disaster Recovery: Experience with Azure Backup and Disaster Recovery solutions. Azure Monitor: Experience in configuring and managing monitoring solutions using Azure ...
    Suggested

    Openkyber

    Arkansas County, AR
    2 days ago
  • $132.5k - $338.3k

     ...their entire value chain. Whether we’re defending against known cyberattacks, detecting and...  ...one discipline (AppSec, SecOps, IAM, cloud, GRC, or offensive security) Minimum 1...  ...diverse communities—including domain experts, engineers, and designers Proposal and SOW... 
    Suggested
    Full time
    Work experience placement
    Live in
    Work at office
    Local area

    Accenture

    Arkansas County, AR
    3 days ago
  •  ...Role: Lead Platform Engineer, Snowflake Location: Remote Duration: 3 6-month C2H Ideal Candidate Profile: ~5+ years...  ...optimization) ~ Experience with SQL Server, PostgreSQL, and cloud environments (AWS preferred) ~ Background with ETL, data... 
    Suggested
    Remote work

    VDart Inc

    Arkansas County, AR
    2 days ago
  •  ...Job Title: Cyberark Cloud security management Location: Remote Duration: 6 months Requested skills: Cyber Ark - 4-7 years Cloud...  ...skills to operate efficiently among a team of fellow engineers. Strong business acumen and technical documentation skills. For... 
    Remote work

    Openkyber

    Arkansas County, AR
    2 days ago
  • $136k - $184k

     ...Description: Summary: We are seeking a Multi-Disciplinary Systems Engineer to design and deploy the virtualization, storage, and compute...  ...: Identity and Access Administrator Associate VMWare VCP - Cloud Foundation Administrator Microsoft Azure Administrator... 
    Full time
    Temporary work
    Immediate start
    Remote work
    Worldwide
    Relocation package
    Flexible hours

    General Dynamics Information Technology

    Stuttgart, AR
    2 days ago
  • $23.35 per hour

    Who We Are Lennox (NYSE: LII) Driven by 130 years of legacy, HVAC and refrigeration success, Lennox provides our residential and commercial customers with industry-leading climate-control solutions. At Lennox, we win as a team, aiming for excellence and delivering innovative...
    Hourly pay
    Temporary work

    Lennox International Inc

    Stuttgart, AR
    2 days ago
  •  ...with an industry leader in the equipment manufacturing industry that is seeking an innovative and detail-oriented Electrical Design Engineer to join their engineering team. In this role, you will bridge the gap between concept and production. You will be responsible for... 
    Flexible hours

    gpac

    Stuttgart, AR
    2 days ago
  • $116k - $152k

     ...Controls Engineer IVThe Controls Engineer IV designs, modification, evaluation, and execution of complex controls test engineering activities. This role works closely with engineering teams to define, document, analyze, perform, and interpret tests for products, systems... 
    Temporary work

    Lennox International Inc

    Stuttgart, AR
    3 days ago
  •  ...Role: Senior QA Engineer with Playwright Remote (USA / Canada) - Candidates can be either in USA or Canada Job Type: W2 Contract Responsibilities: Verify completed work against acceptance criteria, design intent, and expected behavior, including... 
    Contract work
    Remote work

    Saransh Inc

    Arkansas County, AR
    2 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Defender for Cloud Engineer. Be the first to apply!