Sr. Microsoft Entra / IAM Security Architect

USG Inc.

Fort Worth (TX)

Hybrid

USD 140,000 - 190,000

Full time

10 days ago
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

USG Inc. seeks a Sr. Architect / Engineer to design and implement Microsoft Entra IAM security across cloud, on-prem, and hybrid environments.

You will lead security architecture decisions and hands-on engineering for authentication, authorization, and zero-trust controls. The role requires deep expertise with Entra ID, PIM, Conditional Access, phishing-resistant MFA, and modern identity patterns, with strong collaboration across cybersecurity, cloud, and enterprise teams.

Qualifications

  • Deep expertise in Microsoft Entra ID and identity security patterns.
  • Strong knowledge of IAM controls, zero trust, and hybrid identity security.
  • Experience with modern authentication protocols and identity governance.

Responsibilities

  • Define enterprise Entra IAM security architecture, standards, and guardrails.
  • Architect secure identity solutions across cloud, hybrid, multi-cloud, SaaS, and on‑premises.
  • Develop and implement identity-centric zero trust architecture and risk-based access.
  • Design Conditional Access strategies for users, admins, devices, and workloads.
  • Architect phishing-resistant and passwordless authentication solutions.
  • Govern Privileged Identity Management and just-in-time access models.
  • Lead architecture reviews, threat modeling, and incident response readiness for IAM.
  • Develop automation with Microsoft Graph API and PowerShell to improve security.

Skills

Microsoft Entra ID
Identity & Access Management
Zero Trust
Conditional Access
PIM
Phishing-resistant MFA
Passwordless authentication
OAuth 2.0 / OpenID Connect / SAML
Microsoft Graph API
PowerShell
Entra Connect/Cloud Sync
Identity governance
Hybrid identity security

Education

Microsoft Certified: Cybersecurity Architect Expert (SC-100)
Microsoft Certified: Identity and Access Administrator Associate (SC-300)
CISSP
CCSP
TOGAF

Tools

PowerShell
Microsoft Graph API
Entra Connect/Cloud Sync

Job description

Position: Sr. Architect / Engineer - Microsoft Entra / Identity & Access Management (IAM) Security
Location: Fort Worth, TX (Hybrid)
Duration: 6 Months
Role Summary
  • The Senior Architect / Engineer -- Microsoft Entra IAM Security is responsible for defining, designing, and engineering enterprise identity security solutions using Microsoft Entra ID and the broader Microsoft identity security ecosystem.
  • This role provides senior technical leadership for identity architecture, authentication, authorization, privileged access, identity governance, application access, and hybrid/cloud identity security. The architect establishes IAM security patterns and standards while also providing hands‑on engineering leadership for complex implementations, migrations, integrations, and security remediation initiatives.
  • The position serves as a subject‑matter expert for identity-centric Zero Trust security, partnering with cybersecurity, cloud, infrastructure, application, risk, compliance, and enterprise architecture teams to reduce identity‑related risk and protect access to critical enterprise resources.
Key Responsibilities
  • Define enterprise Microsoft Entra IAM security architecture, standards, reference architectures, design patterns, and engineering guardrails.
  • Architect secure identity solutions across cloud, hybrid, multi-cloud, SaaS, and on-premises environments.
  • Develop and implement an identity-centric Zero Trust architecture, emphasizing continuous verification, least privilege, strong authentication, and risk-based access.
  • Design enterprise Conditional Access strategies covering users, administrators, workloads, applications, devices, authentication strength, and risk.
  • Architect phishing-resistant and passwordless authentication solutions using FIDO2/passkeys, Windows Hello for Business, certificate-based authentication, and other supported authentication methods.
  • Design and govern Privileged Identity Management (PIM) and privileged‑access models to minimize standing administrative privileges and enforce just‑in‑time access.
  • Establish security architecture for workload identities, managed identities, service principals, application registrations, API permissions, and secrets/certificate management.
  • Architect secure application authentication and authorization using OAuth 2.0, OpenID Connect, SAML 2.0, SCIM, Microsoft Graph, and modern authentication patterns.
  • Design Entra ID Governance capabilities, including entitlement management, access reviews, lifecycle workflows, separation of duties, and automated identity lifecycle controls.
  • Define security architecture for joiner, mover, and leaver (JML) processes and ensure timely provisioning, modification, and removal of access.
  • Design and review hybrid identity security, including Active Directory integration, Entra Connect/Cloud Sync, authentication flows, and protection of privileged identity paths.
  • Lead IAM threat modeling and security architecture reviews for new applications, platforms, cloud services, and major technology initiatives.
  • Identify identity-related attack paths, excessive privileges, legacy authentication dependencies, insecure application permissions, and other IAM security risks.
  • Design controls for detecting and responding to identity compromise, credential theft, token abuse, risky sign‑ins, privilege escalation, and unauthorized access.
  • Define identity logging, monitoring, and alerting requirements and integrate Entra telemetry with SIEM/SOC and security operations processes.
  • Provide architecture and engineering leadership during complex identity security incidents and root‑cause investigations.
  • Develop automation using Microsoft Graph API, PowerShell, REST APIs, and infrastructure-as-code/policy-as-code approaches to improve security consistency and reduce manual administration.
  • Lead IAM modernization, tenant consolidation, authentication modernization, application migration, and security‑hardening initiatives.
  • Evaluate new Microsoft identity capabilities and recommend adoption based on security benefits, operational impact, architectural fit, and organizational risk.
  • Mentor IAM engineers and architects and provide technical leadership across IAM/security engineering teams.
Security Architecture Focus

The successful candidate should demonstrate deep expertise in designing controls that protect identities as a primary enterprise security boundary. Key areas should include:

  • Zero Trust identity architecture
  • Least privilege and Just-in-Time/Just-Enough Administration
  • Conditional Access architecture and policy design
  • Phishing-resistant MFA and authentication strength
  • Passwordless authentication
  • Privileged Access Management / PIM
  • Identity Protection and risk-based access
  • Workload identity and service principal security
  • OAuth consent and application permission governance
  • Token and session security
  • Identity Governance and access certification
  • RBAC and authorization architecture
  • Administrative tiering and privileged account separation
  • Break-glass/emergency access architecture
  • Legacy authentication elimination
  • Hybrid identity and Active Directory security
  • Identity threat detection and incident response
  • Identity security posture management
  • Separation of duties and toxic-access controls
Required Technical Skills
  • Deep expertise with Microsoft Entra ID, including Conditional Access, PIM, Identity Protection, ID Governance, Enterprise Applications, App Registrations, workload identities, authentication methods, Microsoft Graph, and hybrid identity.
  • Strong knowledge of Active Directory, Entra Connect/Cloud Sync, Microsoft 365 identity integration, Azure RBAC, and the relationship between cloud and on‑premises identity security.
  • Advanced understanding of identity protocols and standards including OAuth 2.0, OpenID Connect, SAML 2.0, SCIM, Kerberos, LDAP, and modern authentication.
  • Strong automation capabilities using PowerShell and Microsoft Graph API, with experience applying automation to identity provisioning, security controls, policy deployment, reporting, and governance.
  • Strong understanding of identity-related security threats, including credential theft, token theft/replay, MFA bypass techniques, consent phishing, privilege escalation, compromised service principals, excessive application permissions, and lateral movement involving identity systems.
Architecture & Leadership Expectations
  • Translate business, cybersecurity, regulatory, and risk requirements into scalable IAM architectures.
  • Make and defend complex identity security architecture decisions.
  • Balance security requirements against user experience, operational complexity, resilience, and business requirements.
  • Establish reusable enterprise architecture patterns rather than designing one‑off solutions.
  • Conduct architecture and security reviews and identify material IAM risks.
  • Provide technical leadership for complex implementations and security remediation.
  • Influence application, cloud, infrastructure, and cybersecurity architecture beyond the IAM organization.
  • Communicate identity risks and architectural decisions effectively to both technical teams and senior stakeholders.
  • Remain technically hands‑on enough to validate designs, develop proofs of concept, troubleshoot complex problems, and guide engineering teams through implementation.
Experience
  • Typically 10 years of experience in Identity & Access Management, cybersecurity, infrastructure security, or related disciplines, including substantial experience designing Microsoft identity solutions.
  • Candidates should have demonstrated experience architecting IAM solutions in large, complex enterprise environments, preferably including hybrid identity, large application portfolios, privileged‑access environments, and regulated or security‑sensitive workloads.
  • Experience leading major identity transformation programs---such as Zero Trust adoption, MFA/passwordless transformation, Conditional Access modernization, Active Directory/Entra modernization, privileged‑access transformation, or migration from legacy IAM/federation platforms---is highly desirable.
  • Preferred Certifications
  • Relevant certifications may include Microsoft Certified: Cybersecurity Architect Expert (SC-100), Microsoft Certified: Identity and Access Administrator Associate (SC-300), CISSP, CCSP, SABSA, TOGAF, Azure security/architecture certifications, or equivalent identity and cybersecurity credentials.
Success Profile
  • A successful Senior Entra IAM Security Architect / Engineer combines three capabilities: deep Microsoft Entra expertise, strong cybersecurity architecture knowledge, and hands‑on engineering credibility.
  • The individual should be able to move between executive-level security architecture discussions and detailed technical design---for example, defining an enterprise Zero Trust identity strategy and then working with engineers to determine the appropriate Conditional Access policies, authentication strengths, PIM configuration, workload identity controls, Graph permissions, logging requirements, and implementation approach.
Regards

Krishna

eye

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Identity & Access Management (IAM)- Senior Engineer - Microsoft Entra
Identity & Access Management (IAM)- Senior Engineer - Microsoft Entra

ARK Infotech Spectrum India Pvt. Ltd • Dallas (TX)

Hybrid
USD 110,000 - 150,000
Hybrid work arrangement
IAM Engineer (REMOTE)
IAM Engineer (REMOTE)

Conexess Group • Livonia (MI)

On-site
USD 100,000 - 140,000
Infrastructure Engineer
Infrastructure Engineer

Huxley • Boston (MA)

On-site
USD 120,000 - 150,000
Entra ID Architect
Entra ID Architect

Programmers.io • Boston (MA)

On-site
USD 140,000 - 200,000
Technical Architect (Identity & Entra ID)
Technical Architect (Identity & Entra ID)

Instant Alliance, LLC • Chicago (IL)

Remote
USD 117,000 - 138,000
IAM Architect
IAM Architect

Conexess Group • Farmington Hills (MI)

On-site
USD 130,000 - 170,000
Identity & Security Engineer
Identity & Security Engineer

Coda Search│Staffing • Town of Texas (WI)

Hybrid
USD 110,000 - 170,000
Workforce Identity Architect, VP
Workforce Identity Architect, VP

Mufgamericas • Tampa (FL)

On-site
USD 120,000 - 160,000
Identity and Security Engineer
Identity and Security Engineer

Ledgent Technology • United States

Hybrid
USD 130,000 - 140,000
Lead IAM Solution Architect (Privileged Access & Cloud Identity)
Lead IAM Solution Architect (Privileged Access & Cloud Identity)

Aquent • Alpharetta (GA)

Remote
USD 140,000 - 190,000