IAM Architect
Openkyber
Identity as a Perimeter and Modernization Program Microsoft Entra ID, Windows Hello for Business, Passkeys, and Conditional Access
1. Project OverviewCenterPoint Energy seeks to modernize enterprise identity security through the deployment and enforcement of phishing-resistant authentication across the Microsoft Entra ID environment. The initiative will establish Windows Hello for Business (WHfB) as the primary enterprise authentication method and implement passwordless authentication through Passkeys, Microsoft Authenticator Passwordless, and FIDO2 security keys where appropriate. The project will further strengthen Zero Trust identity controls through Conditional Access optimization, Continuous Access Evaluation (CAE), device trust validation, Identity Protection integration, and administrative security hardening.
2. Project Objectives- Eliminate reliance on passwords for daily authentication.
- Reduce phishing, MFA fatigue, token theft, and credential compromise risks.
- Establish phishing-resistant authentication as the enterprise standard.
- Improve identity security posture consistent with NIST CSF 2.0 and Zero Trust principles.
- Enhance Conditional Access governance and policy enforcement.
- Strengthen administrator authentication requirements.
- Improve contractor and B2B identity controls.
- Leverage device health and compliance signals as authentication controls.
- Enable Continuous Access Evaluation (CAE) for near real-time access revocation.
- Establish operational processes for passwordless onboarding, recovery, and lifecycle management.
Phase 1 Rapid assessment and planning
Review current state: Microsoft Entra ID tenant configuration Authentication methods policy Passwordless readiness Existing Conditional Access policies MFA deployment status Identity Protection configuration Device compliance posture Enrollment processes Administrative account architecture B2B config settings
Deliverables Current-state assessment Gap analysis Passwordless config Deployment plan
Phase 2 Windows Hello for Business Enforcement (Under progress now, we need some light touch here)
Windows Hello for Business Deployment Configure and enforce WHfB for all CNP devices using GPO and InTune: Employees Corporate laptops Microsoft-managed endpoints Hybrid and cloud-joined devices
Configuration Activities GPO TPM-backed credential enforcement Biometric authentication enablement PIN policy standardization Intune policy deployment Enrollment automation Compliance reporting
Deliverables Deployment configuration Enrollment procedures Support documentation
Phase 3 Enterprise Passwordless Authentication Microsoft Authenticator Passwordless Deploy: Passwordless phone sign-in Phish-resistant MFA controls Authentication method policies Passkey Deployment
Enable and enforce passkeys for: Employees Microsoft Authenticator Passkeys Device-bound passkeys Cross-platform passkeys (approved scenarios) Privileged Administrators (A accounts) Passkeys required Hardware-backed authenticators preferred Dedicated administrative accounts Phishing-resistant authentication enforcement Contractors Passkeys where mobile devices are supported FIDO2 security keys for shared workstation environments Strong authentication onboarding process B2B Users Trust external MFA and require phishing-resistant authentication Passkey registration Temporary Access Pass (TAP) Implement TAP process for: New hires Authentication recovery Device replacement Lost passkeys Lost security keys
Phase 4 FIDO2 Security Key Program Security Key Deployment Implement FIDO2 security keys for specific users such as: Privileged administrators Break-glass accounts Contractors
Deliverables Develop the process for lifecycle management Lost/stolen key process, ordering and replacement FIDO2 inventory process
4. Conditional Access ModernizationConditional Access Policy Review Implement CA Policy Standards Require: Passkeys WHfB FIDO2 Block: Legacy authentication and High-risk authentication methods Weak MFA methods including SMS and Phone Calls
User-Based Policies Improve CA Policy controls for: Employees Contractors B2B users Privileged administrators Service accounts
Application Policies Protect: Microsoft 365 - for example - review mailbox sharing permissions to prevent excessive sharing (including company-wide access). Process to prevent this reoccurring. Azure Portal Service accounts to be protected and allow sign-in access from approved/trusted IP addresses only. Privileged applications SaaS platforms
Session Controls Configure: Sign-in frequency Risk-based access Continuous access evaluation
Deliverables CA policy cleanup for clarity and consistency Optimize and enhance CA policies
5. Device Trust and Health ControlsIntune and Device Compliance Enhancement Implement Conditional Access enforcement based on: Device Health Require: Entra registered/joined devices Managed devices Compliant devices Compliance Signals Validate: BitLocker enabled TPM available Defender active CrowdStrike EDR active (primary) Domain joined and OS supported Secure Boot enabled Palo Alto VPN enabled
Deliverables Device compliance configuration and rollout Compliance policies Reporting dashboard
6. Continuous Access Evaluation (CAE)CAE Enablement Implement and validate: Continuous Access Evaluation Real-time session revocation Token invalidation upon risk events Location change enforcement Privilege change enforcement
Deliverables CAE configuration Validation and operational procedures
7. ReportingDevelop: Authentication adoption metrics Passwordless enrollment metrics CA compliance reporting Device health reporting Executive dashboards Example KPIs % WHfB Enrollment % Passkey Adoption % Passwordless Authentication Usage % CA Coverage % Compliant Devices Privileged Account Passwordless Adoption High-Risk Sign-In Reduction
8. Change Management, Knowledge Transfer & Operational Hand-offProvide: IAM Administrative training Service Desk training IAM operational procedures User communications
For applications and inquiries, contact:View email address on us.fitly.work
- ...Job ID: TX-27R0001715 Hybrid/Local TX Govt SailPoint IAM Developer (15+) with governance, PowerShell/Python, RBAC, OIDC/SSO/MFA/SAML, SailPoint Identity Security Cloud/ISC, REST APIs experience Location: Austin, TX (DPS) Duration: 10 Months Skills: 8 Required IAM Platform...SuggestedContract workLocal area
- ...RESPONSIBILITIES: OpenKyber's client in Tampa, FL is seeking 2 IAM Engineers to take ownership of Identity Governance and Administration... .... Duties: Serve as the IGA Solutions Lead and Architect, owning design, implementation, and ongoing administration...SuggestedHourly payContract work
- ...Job Summary We are seeking an experienced IAM / OCI Identity Engineer to support an ongoing Oracle Fusion ERP implementation . The... ...Candidate The ideal candidate is an OCI IAM Engineer / Identity Architect with strong IDCS and Entra ID experience who understands how...SuggestedFull timeRemote workMonday to Friday
$42 - $47 per hour
...Talent Acquisition Specialist OpenKyber at email address ****@*****.*** . We have Contract role Entra External ID / IAM Application Architect-Hybrid for client at Long Island, NY. Please let me know if you or any of your friends would be interested in this...SuggestedContract work- ...Job Description : To lead the IAM Operations team in all day-to-day responsibilities fulfilling access requests, audit/compliance requests, troubleshooting incidents related to access, and providing strong customer service to end users and role owners. Subject matter expert...Suggested
- ...We are seeking an experienced Lead IAM Security Engineer with deep expertise in Saviynt Identity Governance & Administration (IGA) to help mature and modernize a large enterprise IAM program. This is an engineering-focused role designed for professionals who build, improve...
- ...Role: AWS Security & IAM Engineer Location: Dallas, TX(Hybrid)-3 days in a week Responsible for designing, implementing, and supporting secure AWS Identity and Access Management (IAM) solutions, including user lifecycle management, privileged access controls, and governance...3 days per week
- ...Role: IAM Business Analyst, Process, Persona and Change Location: Onsite - Charlotte NC USA(Hybrid) Practice: Cloud Business Unit Role Purpose: Translate stakeholder needs and observed friction into measurable processes, persona requirements,...
- ...Title: IAM Analyst Location: Arlington, TX (Onsite) Contract Job Description: Design, build, and maintain Business Roles and access templates. Perform role mining, role analysis, and RBAC optimization activities. Partner with business leaders...Contract work
- ...Practical knowledge of Google Cloud Platform projects, networking, IAM, compute, containers, data services, logging and monitoring.... ...decisions. ~ Associate Cloud Engineer or Professional Cloud Architect certification is preferred. Success Measures Case records...Work at office3 days per week
- ...practices. Required Experience Strong experience with Multi-Factor Authentication ( MFA ) and Identity & Access Management ( IAM ) technologies. Background in IT Security, authentication, and access control solutions. Experience troubleshooting complex...For contractorsRemote workWorldwide
- ...Role: Security Engineer Automation / IAM Location: 100% Remote U.S. Only | Core Hours: 8:30 AM 5:00 PM ET Duration: Contract | On-Call: Monthly 247 SOC rotation Seeking an experienced Security Engineer with strong hands-on expertise in security automation...Contract workRemote work
- ...knowledge transfer Provide post-migration support Required Technical Skills: PingOne, Microsoft Entra ID, ForgeRock OpenAM, IAM, SSO, OAuth 2.0, OIDC, SAML, authentication architecture, security best practices. Preferred Qualifications: Government...Remote work
- ...Senior AWS Cognito Phoenix, AZ Hybrid Long Term Contract! Role Overview We are seeking a Senior AWS Cognito and Okta IAM Engineer to design, implement, and support secure identity and access management solutions for cloud-based web, mobile, and enterprise applications...Long term contractImmediate start
- "C2C or W2 Opportunities" Job Title : IAM Architect Work Location: Alpharetta, GA (Onsite) Need local only who can go for F2F interview JD An IAM Architect is responsible for designing, implementing, and governing identity and access management solutions that ensure secure...Local area
- ...Business Systems Analyst - Identity Access Management Location- Hybrid Chicago, IL downtown Duration- 4-6 Months Job Description: As a IAM business systems analyst you will work on the IAM delivery team on IAM projects. You will be responsible for analyzing business...
- ...Job Title: IAM Operations / IAM Automation Engineer Location: Remote US Develops and maintains automation scripts and workflows using PowerShell, Python, Tines, and AI-enabled coding tools to streamline IAM Governance processes and reduce manual workload. Leverages...Remote work
$65.28 per hour
...65.28 Security Clearance: Ability to obtain and maintain Public Trust (or higher if required) Overview This role is for a senior IAM professional who can lead enterprise identity security and governance across Microsoft Entra ID and Microsoft ICAM environments. The...Contract workRemote work- ...Job Summary: We are seeking a Cloud & IAM DevOps Engineer with strong expertise in AWS cloud deployments, CI/CD automation, and Identity & Access Management (IAM). The ideal candidate will have hands-on experience with AWS, Harness, HashiCorp Vault, Kafka, ForgeRock,...
- ...For more information about OpenKyber, visit us at . This is a contract to perm role. Position Title: Principal Cybersecurity Architect Identity, IAM & Zero Trust Location Information Remote Position Responsibilities: As the Principal Cybersecurity Architect specializing...Permanent employmentContract workRemote work
- ...Title: Business Analyst/QA Analyst IAM (InfoSec) Location: Los Angeles Based Duration: 3-6 Months (possible extension... ...proactive liaison between product owners, developers, security architects, and operations teams. Surface risks early, propose...
- ...OpenKyber . I came across your profile and felt it could be a good match for a current opportunity we're working on. Google Cloud Platform IAM Engineer (Associate) | Google Cloud Platform IAM Lead / Manager (VP) Location: Plano, TX - Onsite Duration: 12 Months Important...Live inImmediate start
- ...Looking for a senior Identity & Access Management (IAM) leader to head an enterprise authentication modernization initiative. In this role, you will lead the migration from legacy ForgeRock OpenAM to PingOne Advanced Identity Cloud and Microsoft Entra ID . Position...Remote work
- ...Entra External ID / IAM Application Architect - Long Island, NY - Hybrid / 2 days a week {preferably between M-W} Requisition Name : Entra External ID / IAM Application Architect Start Date : 11/2/2026 Duration : 21 Weeks Services Location : NY/...2 days per week
- ...IAM Consultant Location: Palo Alto, CA OR Irvine, CA (Hybrid - 3 days a week onsite) Duration: 6 months CTH Description: 7+ years... ...enterprise migration from Entra ID / Azure AD to Okta as architect or technical lead Deep expertise in SAML, OIDC, OAuth 2.0,...3 days per week
- ...Java Developer with IAM Introduction: We are seeking a Java Developer with IAM experience to join our team in Houston, TX. The ideal candidate will be responsible for developing and maintaining full-stack Java applications with a focus on IAM and cloud integration....
- ...Job Title: Technical Architect Cybersecurity, IAM/PAM & Infrastructure Security Classification: Senior Enterprise Architect Positions: 1 Work Mode: Hybrid / Remote-eligible Location: Sacramento, CA, with remote work permitted subject to approval Contract: Approximately...Contract workFor contractorsRemote work
- ...Google Architect Remote Role summary This role architects and delivers secure, scalable Google Cloud Platform solutions for a global network... ..., including Compute Engine, GKE, Cloud Storage, VPC, and IAM configurations Implement Infrastructure as Code using Terraform...Remote work
- ...Science, Information Systems, or related field 5+ years' experience in Identity and Access Management engineering Expertise with IAM platforms including cloud (Azure, AWS, Google Cloud Platform). In-depth knowledge of authentication, authorization, and...
- ...Job Title: (IAM) Saviynt Administrator/Architect Location: Spring, TX - Hybrid (3-Days a week Onsite) Duration: 12+ Months Contract Job Description: Required Skills & Experience: ~5 - 10+ years in Identity & Access Management. ~3...Contract work3 days per week
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to IAM Architect. Be the first to apply!

