Senior Engineer / Architect - Microsoft Entra Identity & Access Management (IAM) Security

JobDiva, Inc.

Fort Worth (TX)

On-site

USD 140,000 - 210,000

Full time

10 days ago
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

NTT DATA's client is seeking a Senior Architect / Engineer – Microsoft Entra IAM Security in Fort Worth, TX to define, design, and engineer enterprise identity security solutions using Microsoft Entra ID and the broader Microsoft identity security ecosystem.

This role provides senior technical leadership for identity architecture, authentication, authorization, privileged access, identity governance, and hybrid/cloud identity security; the architect establishes IAM security patterns and leads

Qualifications

  • 4+ years with Microsoft Entra ID, including Conditional Access, PIM, Identity Protection, ID Governance, Enterprise Applications, App Registrations, workload identities, authentication methods, Microsoft Graph and hybrid identity.

Responsibilities

  • Define enterprise Microsoft Entra IAM security architecture, standards, reference architectures, design patterns, and engineering guardrails.
  • Architect secure identity solutions across cloud, hybrid, multi-cloud, SaaS and on-premises environments.
  • Develop and implement an identity-centric Zero Trust architecture, emphasizing continuous verification, least privilege, strong authentication, and risk-based access.
  • Design enterprise Conditional Access strategies covering users, administrators, workloads, applications, devices, authentication strength, and risk.
  • Architect phishing-resistant and passwordless authentication solutions using FIDO2/passkeys, Windows Hello for Business, certificate-based authentication, and other supported authentication methods.
  • Design and govern Privileged Identity Management (PIM) and privileged-access models to minimize standing administrative privileges and enforce just-in-time access.
  • Establish security architecture for workload identities, managed identities, service principals, application registrations, API permissions and secrets/certificate management.
  • Architect secure application authentication and authorization using OAuth 2.0, OpenID Connect, SAML 2.0, SCIM, Microsoft Graph and modern authentication patterns.
  • Design Entra ID Governance capabilities, including entitlement management, access reviews, lifecycle workflows, separation of duties, and automated identity lifecycle controls.
  • Define security architecture for joiner, mover and leaver (JML) processes and ensure timely provisioning, modification and removal of access.
  • Design and review hybrid identity security, including Active Directory integration, Entra Connect/Cloud Sync, authentication flows and protection of privileged identity paths.
  • Lead IAM threat modeling and security architecture reviews for new applications, platforms, cloud services and major technology initiatives.
  • Identify identity-related attack paths, excessive privileges, legacy authentication dependencies, insecure application permissions and other IAM security risks.
  • Design controls for detecting and responding to identity compromise, credential theft, token abuse, risky sign-ins, privilege escalation and unauthorized access.
  • Define identity logging, monitoring and alerting requirements and integrate Entra telemetry with SIEM/SOC and security operations processes.
  • Provide architecture and engineering leadership during complex identity security incidents and root-cause investigations.
  • Develop automation using Microsoft Graph API, PowerShell, REST APIs and infrastructure-as-code/policy-as-code approaches to improve security consistency and reduce manual administration.
  • Lead IAM modernization, tenant consolidation, authentication modernization, application migration and security-hardening initiatives.
  • Evaluate new Microsoft identity capabilities and recommend adoption based on security benefits, operational impact, architectural fit, and organisational risk.
  • Mentor IAM engineers and architects and provide technical leadership across IAM/security engineering teams.

Skills

Microsoft Entra ID
Conditional Access
PIM
Identity Governance
Azure
OAuth OpenID Connect SAML
PowerShell
Microsoft Graph API
Zero Trust security
Hybrid/Cloud Identity

Tools

Microsoft Graph API

Job description

Company Overview

NTT DATA strives to hire exceptional, innovative and passionate individuals who want to grow with us.

NTT DATA's Client is currently seeking a Senior Architect / Engineer - Microsoft Entra Identity & Access Management (IAM) Security to join their team in Fort Worth, Texas.

Job Description
Senior Architect / Engineer – Microsoft Entra Identity & Access Management (IAM) Security

The Senior Architect / Engineer – Microsoft Entra IAM Security is responsible for defining, designing, and engineering enterprise identity security solutions using Microsoft Entra ID and the broader Microsoft identity security ecosystem.

This role provides senior technical leadership for identity architecture, authentication, authorization, privileged access, identity governance, application access, and hybrid/cloud identity security. The architect establishes IAM security patterns and standards while also providing hands-on engineering leadership for complex implementations, migrations, integrations, and security remediation initiatives.

The position serves as a subject-matter expert for identity-centric Zero Trust security, partnering with cybersecurity, cloud, infrastructure, application, risk, compliance and enterprise architecture teams to reduce identity-related risk and protect access to critical enterprise resources.

Key Responsibilities
  • Define enterprise Microsoft Entra IAM security architecture, standards, reference architectures, design patterns, and engineering guardrails.
  • Architect secure identity solutions across cloud, hybrid, multi-cloud, SaaS and on-premises environments.
  • Develop and implement an identity-centric Zero Trust architecture, emphasizing continuous verification, least privilege, strong authentication, and risk-based access.
  • Design enterprise Conditional Access strategies covering users, administrators, workloads, applications, devices, authentication strength, and risk.
  • Architect phishing-resistant and passwordless authentication solutions using FIDO2/passkeys, Windows Hello for Business, certificate-based authentication, and other supported authentication methods.
  • Design and govern Privileged Identity Management (PIM) and privileged-access models to minimize standing administrative privileges and enforce just-in-time access.
  • Establish security architecture for workload identities, managed identities, service principals, application registrations, API permissions and secrets/certificate management.
  • Architect secure application authentication and authorization using OAuth 2.0, OpenID Connect, SAML 2.0, SCIM, Microsoft Graph and modern authentication patterns.
  • Design Entra ID Governance capabilities, including entitlement management, access reviews, lifecycle workflows, separation of duties, and automated identity lifecycle controls.
  • Define security architecture for joiner, mover and leaver (JML) processes and ensure timely provisioning, modification and removal of access.
  • Design and review hybrid identity security, including Active Directory integration, Entra Connect/Cloud Sync, authentication flows and protection of privileged identity paths.
  • Lead IAM threat modeling and security architecture reviews for new applications, platforms, cloud services and major technology initiatives.
  • Identify identity-related attack paths, excessive privileges, legacy authentication dependencies, insecure application permissions and other IAM security risks.
  • Design controls for detecting and responding to identity compromise, credential theft, token abuse, risky sign-ins, privilege escalation and unauthorized access.
  • Define identity logging, monitoring and alerting requirements and integrate Entra telemetry with SIEM/SOC and security operations processes.
  • Provide architecture and engineering leadership during complex identity security incidents and root-cause investigations.
  • Develop automation using Microsoft Graph API, PowerShell, REST APIs and infrastructure-as-code/policy-as-code approaches to improve security consistency and reduce manual administration.
  • Lead IAM modernization, tenant consolidation, authentication modernization, application migration and security-hardening initiatives.
  • Evaluate new Microsoft identity capabilities and recommend adoption based on security benefits, operational impact, architectural fit, and organisational risk.
  • Mentor IAM engineers and architects and provide technical leadership across IAM/security engineering teams.
Required Technical Skills
  • 4 years' experience with Microsoft Entra ID, including Conditional Access, PIM, Identity Protection, ID Governance, Enterprise Applications, App Registrations, workload identities, authentication methods, Microsoft Graph and hybrid identity.
  • 7 years' experience with Active Directory, Entra Connect/Cloud Sync, Microsoft 365 identity integration, Azure RBAC and the relationship between cloud and on-premises identity security.
  • 5+ years' experience with identity protocols and standards including OAuth 2.0, OpenID Connect, SAML 2.0, SCIM, Kerberos, LDAP and modern authentication.
  • 7 years' experience using PowerShell and Microsoft Graph API, with experience applying automation to identity provisioning, security controls, policy deployment, reporting and governance.
  • 5+ years' experience with identity-related security threats, including credential theft, token theft/replay, MFA bypass techniques, consent phishing, privilege escalation, compromised service principals, excessive application permissions and lateral movement involving identity systems.
About NTT DATA

NTT DATA is a $30 billion trusted global innovator of business and technology services. We serve 75% of the Fortune Global 100 and are committed to helping clients innovate, optimise and transform for long-term success. As a Global Top Employer, we have diverse experts in more than 50 countries and a robust partner ecosystem of established and start-up companies. Our services include business and technology consulting, data and artificial intelligence, industry solutions, and the development, implementation and management of applications, infrastructure and connectivity. We are one of the leading providers of digital and AI infrastructure in the world. NTT DATA is a part of NTT Group, which invests over $3.6 billion each year in R&D to help organisations and society move confidently and sustainably into the digital future. Visit us at us.nttdata.com

NTT DATA endeavours to make https://us.nttdata.com accessible to any and all users. If you would like to contact us regarding the accessibility of our website or need assistance completing the application process, please contact us at https://us.nttdata.com/en/contact-us. This contact information is for accommodation requests only and cannot be used to inquire about the status of applications. NTT DATA is an equal opportunity employer. Qualified applicants will receive consideration for employment without regard to race, colour, religion, sex, sexual orientation, gender identity, national origin, disability or protected veteran status. For our EEO Policy Statement, please. If you'd like more information on your EEO rights under the law, please. For Pay Transparency information, please.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Engineer / Architect - Microsoft Entra Identity & Access Management (IAM) Security
Senior Engineer / Architect - Microsoft Entra Identity & Access Management (IAM) Security

NTT DATA, Inc. • Fort Worth (TX)

On-site
USD 150,000 - 175,000
Identity & Access Management (IAM) Security Engineer - ONSITE in Addison, TX
Identity & Access Management (IAM) Security Engineer - ONSITE in Addison, TX

NTT DATA North America • Addison (TX)

On-site
USD 106,000 - 142,000
Medical, dental, and vision insurance
401k with company match
Paid time off
+3
Identity & Access Management (IAM) Security Engineer - ONSITE in Addison, TX
Identity & Access Management (IAM) Security Engineer - ONSITE in Addison, TX

NTT DATA, Inc. • Addison (TX)

On-site
USD 106,000 - 142,000
Medical, Dental, Vision insurance
401k with company match
Paid time off
+1
Systems Engineering Specialist (Active Directory/Azure AD/Identity)
Systems Engineering Specialist (Active Directory/Azure AD/Identity)

JobDiva, Inc. • Chicago (IL)

Remote
USD 140,000 - 200,000
Medical, dental, and vision insurance
401k program
AD&D insurance
Senior Cloud Platform Architect - AWS & Service Activation-- Hybrid Irving, TX or Charlotte, NC
Senior Cloud Platform Architect - AWS & Service Activation-- Hybrid Irving, TX or Charlotte, NC

NTT DATA North America • Irving (TX)

Hybrid
USD 118,000 - 157,000
Medical, dental, and vision
401k with company match
Paid time off
Sr Security Solutions Architect (Pre-Sales)
Sr Security Solutions Architect (Pre-Sales)

NTT DATA, Inc. • New York (NY)

On-site
USD 150,000 - 190,000
Medical, dental, and vision insurance
401(k) with company match
Windows OS Engineer
Windows OS Engineer

NTT DATA North America • Irving (TX)

On-site
USD 120,000 - 160,000
Principal Engineer
Principal Engineer

NTT DATA North America • Charlotte (NC)

On-site
USD 96,000 - 110,000
Medical, dental, vision insurance
401(k) program
AD&D insurance
Sr Data & AI Architect
Sr Data & AI Architect

JobDiva, Inc. • Auburn Hills (MI)

On-site
USD 96,000 - 116,000
Epic IAM & Security SME (L4) - Hybrid in Plano, TX
Epic IAM & Security SME (L4) - Hybrid in Plano, TX

NTT DATA North America • Plano (TX)

On-site
USD 118,000 - 157,000
Hybrid work model
Medical, dental, and vision insurance
HSA/FSA
+5