We are hiring for a Senior Microsoft Engineer to join us!
Role Highlights:
- You must be willing to work in a B2B Contractor Setup (you will have to manage your own contributions). This role is a full-time contractor role without an expiration date or end date
- Role is in a hybrid setup: 2x-3x weekly onsite in BGC
- Working schedule is Mon to Fri, flexible working hours
- Benefits: 40 USD sports allowance + up to 1000 USD annual medical allowance + 23 PTO + 10 holiday leaves + devices are provided
About The Role:
You will be responsible for designing, implementing, securing, and operating enterprise identity and access management services centered around Microsoft Entra ID. You will act as the technical authority for cloud identity, authentication, authorization, governance, and Zero Trust initiatives, ensuring secure and seamless access to applications, services, and resources across hybrid and multi-cloud environments. You will play a key role in driving identity modernization, automation, security hardening, and integration initiatives while collaborating closely with security, network, cloud, and application teams.
Key Responsibilities:
Identity Architecture & Operations
- Design, implement, and maintain enterprise-scale Microsoft Entra ID environments.
- Lead the adoption and optimization of Microsoft Entra ID capabilities, including: Conditional Access, Identity Protection, Privileged Identity Management (PIM) , Access Reviews, Entitlement Management, Authentication Methods and Passwordless Authentication, External Identities (B2B/B2C)
- Design and maintain secure authentication and authorization solutions for cloud and SaaS applications.
- Implement and support Single Sign-On (SSO) and federation technologies using SAML, OAuth 2.0, OpenID Connect, and WS-Federation.
- Integrate enterprise and third-party applications with Microsoft Entra ID.
- Support identity lifecycle management, Joiner-Mover-Leaver processes, and governance controls.
- Lead Zero Trust identity initiatives and continuous security improvements.
- Manage Microsoft 365 identity-related services and integrations.
Cloud Security & Identity Governance
- Design and implement identity governance and access management controls.
- Develop and maintain Conditional Access policies aligned with security and compliance requirements.
- Implement risk-based access controls and identity threat detection capabilities.
- Collaborate with cybersecurity teams on security architecture, audits, compliance initiatives, and incident response activities.
- Ensure adherence to identity security best practices and regulatory requirements.
Automation
- Develop and maintain automation solutions to streamline identity administration and operations, primarily using PowerShell, Microsoft Graph API, ServiceNow, and AI-enabled solutions.
- Automate user provisioning, access reviews, application onboarding, reporting, and governance processes.
- Identify and drive opportunities for automation to reduce manual effort, improve consistency, and increase operational efficiency.
- Implement automated monitoring, reporting, and alerting for identity services and security-related events.
Network & Connectivity Collaboration
- Work closely with network and cloud teams to ensure secure connectivity between users, applications, and identity services.
- Troubleshoot authentication and access issues related to networking components such as: Firewalls, Proxies, Load Balancers, VPN Solutions, Secure Web Gateways, Private Connectivity Services
- Support secure access architectures including Zero Trust Network Access (ZTNA) and cloud-native access solutions.
- Understand and troubleshoot authentication flows across distributed and hybrid environments.
- Provide third-level (L3) support for complex identity and access management incidents and service requests.
- Act as a technical advisor and subject matter expert for identity-related projects and initiatives.
- Work closely with security, cloud, network, application, and infrastructure teams to ensure seamless integration and secure operations.
- Contribute to technical standards, architecture reviews, and strategic roadmap planning.
Qualifications:
- 5+ years of experience in Identity and Access Management (IAM), Microsoft Entra ID, or cloud identity engineering roles.
- Proven experience designing and operating enterprise-scale Microsoft Entra ID environments.
- Strong hands-on experience with: Microsoft Entra ID, Microsoft Graph API, Conditional Access, Identity Protection, Privileged Identity Management (PIM), Identity Governance, Access Reviews, Entitlement Management
- Strong understanding of modern authentication and authorization protocols, including: OAuth 2.0, OpenID Connect (OIDC),SAML 2.0, SCIM, WS-Federation
- Strong scripting and automation skills using PowerShell and Microsoft Graph.
- Demonstrated experience leveraging AI-based solutions within IT operations or engineering workflows.
- Solid understanding of networking concepts relevant to identity services, including: TCP/IP, DNS resolution fundamentals, HTTPS/TLS, Firewalls, Reverse Proxies, VPN technologies, Load Balancing, Network Security Controls
- Good understanding of Zero Trust security principles and identity-centric security architectures.
- Experience working within ITSM / ITIL operating models.
- Excellent analytical and problem-solving skills.
- Strong communication and stakeholder management skills.