IAM Engineer

Intone Inc

Salem (NH)

Hybrid

USD 120,000 - 160,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Intone Inc. in New Hampshire is seeking an IAM Engineer for a six-month contract to design, implement, and harden identity security controls across a global tenant.

This hands-on role focuses on enterprise passkey deployment, phishing-resistant MFA, and conditional access policy engineering from day one. You will retire legacy authentication methods, govern app registrations, and collaborate with Global Service Desk to improve identity verification and recovery processes while delivering

Responsibilities

  • Define enrollment strategy for end users and evaluate compatibility across platforms.
  • Partner with helpdesk and security awareness teams on rollout communications, training, and support escalation paths.
  • Retire SMS and voice call as permitted authentication methods tenant-wide, establishing phishing-resistant MFA as the enterprise standard.
  • Define and enforce Conditional Access Authentication Strengths to require phishing-resistant methods for privileged and high-risk accounts.

Job description

This is a 6-month contract position for an IAM Engineer based in Salem, New Hampshire. You will design, implement, and harden identity security controls across a global enterprise tenant. This role is hands-on and delivery-focused, with immediate priority on enterprise passkey deployment, retirement of legacy authentication methods in favor of phishing-resistant MFA, Conditional Access policy engineering, application integration governance, and identity risk detection. You will lead this work from day one and demonstrate measurable adoption and legacy-method retirement within the first phase of engagement.

Responsibilities
  • Design and lead the enterprise rollout of Microsoft Entra passkey (FIDO2/platform authenticator) support, including device-bound and synced passkey strategies, and configure Authentication Methods policies to enable passkeys alongside existing MFA methods.
  • Define enrollment strategy for end users (self-service registration, Temporary Access Pass provisioning, admin-assisted enrollment for high-privilege accounts) and evaluate compatibility across platforms (Windows Hello for Business, mobile authenticator apps, hardware security keys).
  • Partner with helpdesk and security awareness teams on rollout communications, training, and support escalation paths; monitor adoption metrics and authentication method usage reporting post-deployment.
  • Retire SMS and voice call as permitted authentication methods tenant-wide, establishing phishing-resistant MFA as the enterprise standard; baseline current registration and usage of SMS and voice methods by user population, region, role, and device type.
  • Define and enforce Conditional Access Authentication Strengths to require phishing-resistant methods, with staged scoping beginning with privileged and high-risk accounts and expanding to the full user base; build and govern the exception framework for populations where passkeys are not immediately viable.
  • Partner with the Global Service Desk to harden identity verification and account recovery procedures.
  • Architect, build, and maintain Conditional Access policies governing sign-in risk, device compliance, location, application sensitivity, and user/group scoping.
  • Manage policy lifecycle using report-only mode, staged rollout, and What If tool validation prior to enforcement; design break-glass/emergency access account exclusions and safeguards to prevent tenant lockout.
  • Integrate Conditional Access with device compliance (Intune), session controls (Conditional Access App Control), sign-in risk (Entra ID Protection), and Global Secure Access where applicable; continuously review and optimize policies to reduce gaps, redundant rules, and conflicting conditions.
  • Document policy intent, scope, and exceptions for audit and compliance purposes.
  • Review, govern, and remediate OAuth/OpenID Connect and SAML application permissions across the enterprise application portfolio; assess delegated vs. application permissions and apply least-privilege principles and admin consent workflows.
  • Configure and maintain admin consent policies, permission classifications, and periodic access reviews for enterprise applications.
  • Support integration of enterprise SaaS applications via SSO (SAML/OIDC), provisioning (SCIM), and federation, coordinating with application owners and vendors.
  • Identify and remediate risky or over-privileged application grants and maintain an accurate inventory/catalog of enterprise applications, owners, and permission scopes.
  • Own the intake, review, and approval process for new App Registrations in Entra ID; define and enforce secure configuration standards including redirect URI validation, credential/secret vs. certificate usage, token configuration, and API permission scoping.
  • Establish governance guardrails (naming conventions, ownership assignment, secret expiration monitoring, and lifecycle management) to prevent registration sprawl; advise development and platform teams on secure app registration patterns.
  • Conduct periodic audits of existing app registrations to identify stale, unused, or non-compliant entries.
  • Configure and tune sign-in risk and user risk policies in Entra ID Protection, balancing security posture with user experience across a global user base.
  • Investigate and respond to risk detections (leaked credentials, anonymous IP, impossible travel, malware-linked IP, etc.), coordinating remediation with SOC/security operations.
  • Integrate Identity Protection signals with Conditional Access for automated risk-based access decisions; produce regular reporting on risk trends, remediation SLAs, and policy effectiveness for security leadership.
  • Support incident response involving compromised identities, including
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Identity & Access Engineer: Phishing-Resistant MFA Lead
Identity & Access Engineer: Phishing-Resistant MFA Lead

Intone Inc • Salem (NH)

Hybrid
USD 120,000 - 160,000
Entra ID Engineer
Entra ID Engineer

VOLTO Consulting • Indianapolis (IN)

On-site
USD 110,000 - 165,000
Infrastructure Engineer
Infrastructure Engineer

Huxley • Boston (MA)

On-site
USD 120,000 - 150,000
IAM Architect
IAM Architect

Conexess Group • Farmington Hills (MI)

On-site
USD 130,000 - 170,000
IT Security and IAM Engineer/Administrator
IT Security and IAM Engineer/Administrator

Cypress HCM • Cincinnati (OH)

On-site
USD 70,000 - 90,000
Benefits
Community Involvement
PTO
+2
IAM & Security Engineer: Entra ID, AD, RBAC
IAM & Security Engineer: Entra ID, AD, RBAC

Cypress HCM • Cincinnati (OH)

On-site
USD 70,000 - 90,000
Identity and Access Management Architect
Identity and Access Management Architect

Deal Exchange, LLC • Southfield (MI)

Hybrid
USD 110,000 - 140,000
IAM Engineer
IAM Engineer

The Clearing House • North Carolina

Hybrid
USD 90,000 - 130,000
Senior Identity and Access Management Engineer
Senior Identity and Access Management Engineer

Insight Global • Atlanta (GA)

On-site
USD 140,000 - 180,000
IAM Engineer - Entra, MFA & Access Governance
IAM Engineer - Entra, MFA & Access Governance

Insight Global • United States

On-site
USD 100,000 - 150,000