IAM SME - Entra External ID
Group Nine LLC
IAM SME – Entra External ID
We are hiring an IAM SME to lead a secure SSO implementation of Entra External ID. Key duties include migrating from Azure AD B2C to Microsoft Entra External ID, establishing federation with external client portals (SAML/OIDC), providing reference SSO integration, and ensuring strong security, documentation, and knowledge transfer.
Key Responsibilities
- Organize discovery workshops to assess existing authentication methods, workflows, and types of external users.
- Evaluate Azure tenant readiness, licensing, security and compliance requirements, and establish a project plan with milestones and RACI assignments.
- Identify prerequisites such as network configuration, required ports, and environment setup strategy, collaborating with application teams to address dependencies.
- Develop an authentication architecture for external users with Entra External ID.
- Define user registration and login processes, IdP federation strategies (SAML/OIDC), and tailor branding and UX for user journeys.
- Design Conditional Access and MFA policies, including bypass options for partner-initiated flows when necessary (in partnership with app teams).
- Create architecture diagrams and high/low-level design documents.
- Prepare the development environment, configure the Entra External ID tenant, and register required applications.
- Set up federation and integration patterns for external client portals.
- Apply session and token management best practices to ensure smooth portal navigation and proper sign-out behavior.
- Establish a migration strategy and tools using Microsoft Graph APIs, along with scripts and infrastructure.
- Plan and conduct pilot migration, then advance to full-scale migration readiness.
- Maintain attribute mapping and ensure identity data integrity during migration.
- Lead UAT validation, manage issue triage and remediation tracking, and refine policies and UX from feedback.
- Verify conditional access/MFA enforcement versus bypass scenarios, and test end-to-end SSO functionality.
- Create comprehensive documentation covering configuration, federation, migration steps, and operational runbooks.
- Host working sessions and transfer knowledge to enable internal teams to manage additional client SSO integrations independently.
- Perform security reviews for identity flows, token lifetimes, claims issuance, and federation trust boundaries.
- Support cutover planning, rollback strategies, and post-migration stabilization.
- Collaborate with security operations teams to ensure logging, monitoring, and auditability of authentication events.
- Provide ongoing advisory support during early operations (hypercare) post go-live.
Required Skills & Experience
- 10+ years in Identity & Access Management with hands-on SSO and federation implementations.
- Strong expertise in:
- Microsoft Entra External ID
- OAuth2 / OIDC, SAML 2.0, JWT, token/session management
- Application registrations, redirect URIs, certificates/secrets, custom domains concepts
- Experience with Azure AD B2C and migration patterns to Entra External ID.
- Working knowledge of Microsoft Graph API for user migration and identity operations.
- Practical experience designing and implementing Conditional Access + MFA strategies.
- Strong documentation and stakeholder management skills; ability to run workshops and KT sessions.
Preferred Certifications (nice to have)
- Microsoft Certified: Identity and Access Administrator Associate
- Microsoft Certified: Cybersecurity Architect Expert
Soft Skills:
- Strong analytical, problem-solving, and troubleshooting skills.
- Excellent communication and stakeholder management abilities.
- Ability to work independently and collaboratively in a fast-paced environment.
Vacancy posted 4 days ago
Similar jobs that could be interesting for youBased on the IAM SME - Entra External ID in United States vacancy
$173k - $237.5k
...Engineer (SE) who will act as a Subject Matter Export (SME) to support both our Workforce IAM and IGA initiatives across the Central US region. You should... ..., LDAP, SailPoint, Saviynt, Okta, or Microsoft Entra ID An understanding of security concepts and the development...SuggestedFull timeRemote workVisa sponsorshipWork visa- ...Job title : IAM Architect - Microsoft Entra ID Location: Virginia Beach, VA ( Remote) Client: Food & Beverage Manufacturing domain. Role Overview We are seeking a Senior IAM Architect to lead the design, implementation, and governance of...SuggestedWork at officeRemote work
- ...Title : IAM SME Location :MD Remote Roles & Responsibilities ~10+ years of IAM experience with strong expertise in Microsoft Entra ID (Azure AD) in enterprise production environments. ~ Act as IAM & SSO SME, supporting engineering and BAU operations...SuggestedPermanent employmentRemote workShift work
- ...A company is looking for an Entra ID Engineer to support the design, implementation, and administration of enterprise identity and access... ...Develop, configure, and maintain Microsoft Entra ID and enterprise IAM environments Implement and support identity lifecycle...SuggestedRemote work
- ...Core Responsibilities: rchitect and implement enterprise-grade IAM solutions using Microsoft Entra ID (Azure AD) and on-premises Active Directory. Lead application onboarding with modern protocols (SAML, OIDC, OAuth) and legacy authentication systems....SuggestedRemote work
- ...IAM-SME Location: San Jose, CA (Remote) Duration: 6-12+ Months Job Description: Skills: ~ IAM products, OAM, Ping Fed, Ping Access, CISCO Duo, Hitachi Group Identity Job Responsibilities: ~ Sound knowledge of SSO, SAML, Oauth 2.0 mechanisms...Work experience placementRemote work
$112.2k - $196.4k
...amazingly talented Principal Entra ID & Active Directory Engineer to... ...related issues. Partner with IAM, Security, Infrastructure, and... ...and Problem Management. SME advisory posture for directory... ...and coordinate identity related external DNS records (such as Entra ID...Remote workFlexible hours- ...SailPoint Developer / IAM SME Lead Location: Remote (prefer someone in VA/DC area but if not local that is fine) Job Description... ...IAM solutions comply with internal security policies and external regulatory standards. Implement and enforce RBAC, access...Local areaImmediate startRemote work
- ...We are seeking a Microsoft Entra ID Engineer to support a large-scale identity and access implementation within a growing environment. This is a hands-on, delivery-focused role responsible for standing up core identity workflows, security policies, and governance controls...Remote work
- ...Job Description: ~10+ years of experience in Identity and Access Management or related fields. ~ Strong knowledge of IAM principles, technologies, and best practices. ~ Hands-on experience with IAM tools such as Okta, Azure AD, SailPoint, or Ping Identity...Remote work
$60 - $75 per hour
...Stewardship. Lead the design and implementation of a unified Microsoft Entra identity architecture, consolidating multiple tenants and legacy... ...-functional teams to design, approve, and implement cloud and IAM solutions, balancing architecture with hands-on execution...Hourly payFull timeContract workRemote work$163.6k - $245.4k
...especially in moments where technology and public trust converge. You will Lead communications strategy across Block's policy and external affairs work to drive economic empowerment for our customers and sellers Partner closely with Policy, Legal, Risk, and other...Full timeLocal areaRemote workFlexible hours$10 - $12 per hour
...Title: Operations Manager / Home Health Agency Assistant Job ID: VIRAYI1 Industry: Home Health Care / Healthcare Services Location... ...• Excellent communication skills to represent the Owner with external partners • Ability to operate independently in a leadership...Hourly payPermanent employmentFull timeImmediate startShift work$40 per hour
job summary: We are searching for a Warehouse Management System Specialist to travel to various sites to provide trainin and user support. Extensive knowledge of SCALE or a similar WMS is required. This will be a home based position with extensive travel. This is ...Hourly payContract workTemporary workWork experience placementRemote workWork from home- ...: Job Title: Advanced Services Engineer - SME Who we are We see the world of cybersecurity from a unique perspective here at Varonis. We're fighting the battle on a different front than conventional cybersecurity companies, relentlessly focused on securing data...Full timeRemote work
- Location: Remote, United States (with travel as required) Reports To: Office of the CTO / Executive Leadership Role Type: Senior advisory and technical overlay — this is not a quota-carrying sales role About Assured Data Protection Assured Data Protection...Full timeWork at officeRemote workFlexible hours
- Relocation Authorized: National - Camp Telework Type: Full-Time Office/Project Work Location: Various Work Locations USA Extraordinary teams building inspiring projects: Since 1898, we have helped customers complete more than 25,000 projects in 160 countries...Full timeWork experience placementWork at officeRemote workRelocation
$70 - $90 per hour
...F&O SME a0MP900000A19Rh.1_1778792124 We are seeking an experienced Enterprise Architect with a strong background in Dynamics 365 Finance & Operations to drive technology initiatives that enhance our operational capabilities. In this remote role, you will lead architectural...Remote work- The ideal candidate will bring a strong background in clinical care, auditing, or coding, along with the ability to translate complex operational concepts into effective, learner-centered training solutions. This role partners with a cross-functional, fully remote team ...Hourly payTemporary workRemote work
$77k - $115.2k
...are included. Territory will be Greater Spokane through Boise, ID. Preferred Qualifications 3 or more years business to business (... ...continuing project management and coordination between internal and external customers. This position requires operation of a Company Vehicle...Permanent employmentFull timeTemporary workFor contractorsWork at officeRemote workNight shift$150k - $200k
...The IAM Business Analyst plays a critical role in leading and supporting large‑scale IAM transformation programs, acting as the bridge... ..., such as: SailPoint Saviynt Okta Microsoft Entra ID (Azure AD) Active Directory Understanding of IAM concepts including...Temporary workRemote work- ...Opportunity (Part-Time) : Cyber Strategy Subject Matter Expert (SME) - building capacity on a USG contract, supporting a partner nation. Bottom Line Up Front: Hoplite Group is seeking a Cyber Strategy Subject Matter Expert (SME) to support a U.S. Government building...Contract workPart timeImmediate startRemote work
- ...Opportunity (Part-Time): Aviation Logistics Subject Matter Expert (SME) - building capacity on a USG contract, supporting a partner nation. Bottom Line Up Front: Hoplite Group is seeking an Aviation Logistics SME to support a U.S. Government building partner capacity...Contract workPart timeImmediate startRemote work
- ...Opportunity (Part-Time): Fighter Pilot Subject Matter Expert (SME) - building capacity on a USG contract, supporting a partner nation . Bottom Line Up Front: Hoplite Group is seeking a Fighter Pilot SME to support a U.S. Government building capacity effort with...Contract workPart timeImmediate startRemote work
$66.8k - $125k
...Oncology and/or Neurology therapeutic experience is highly preferred. • Candidates must be located in the following states: WA, OR, ID, MT, WY, CO (within 60 miles of the nearest major airport). Up to 80% travel is expected. • Must be legally authorized to work in the...Full timeTemporary workWork at officeRemote workHome officeFlexible hoursNight shift$105.7k - $149.28k
...Streams/Tasks, Snowpipe/Kafka Connector, and external stages (S3) Enforce security, compliance,... ...session parameters (SSO/SCIM with Okta/Entra ID) Manage Snowflake objects and... ...Operate secure integrations with AWS (S3, IAM/KMS, PrivateLink/VPC endpoints), catalogs...16 hoursFull timeContract workTemporary workCasual workWork at officeLocal areaRemote workWork from homeWork visaFlexible hours- ...Opportunity (Part-Time): Human Resource Management (HRM) Subject Matter Expert (SME) Bottom Line Up Front: Hoplite Group is seeking an experienced Senior Human Resource Management / Human Capital Development (HRM/HCD) Subject Matter Experts (SMEs) to support a U.S....Contract workPart timeRemote work
- ...Opportunity (Part-Time): Maritime Security Advisor Subject Matter Expert (SME) Bottom Line Up Front: Hoplite Group is seeking an experienced Maritime Security Advisor SME to support a U.S. Government institutional capacity-building (ICB) effort focused on maritime...Contract workPart timeRemote work
- ...Founded in 2004, the company’s motto is Any Language, Anytime, Anywhere! We might have a job for you as an Online Irish teacher. ID Reference 1096201 ~One of our clients would like to have one-to-one online general Irish classes. ~ The student is a beginner and...Contract workFreelanceWork at officeWork from homeWeekday work
$125k - $150k
..., MSSPs, penetration testing firms, and external security partners. * Drive accountability... ...* Strong technical understanding across IAM, EDR, vulnerability management, SIEM, Microsoft... ..., Microsoft 365, Defender, Intune, and Entra ID. * Relevant certifications such as CISSP...Permanent employmentFull timeRemote work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to IAM SME - Entra External ID. Be the first to apply!


