×
Register Here to Apply for Jobs or Post Jobs. X

IAM SME – Entra External

Job in Encino, Los Angeles County, California, 91316, USA
Listing for: Group Nine LLC
Full Time position
Listed on 2026-07-26
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection
Job Description & How to Apply Below
Position: IAM SME – Entra External ID
Location: Encino

IAM SME – Entra External

We are hiring an IAM SME to lead a secure SSO implementation of Entra External  duties include migrating from Azure AD B2C to Microsoft Entra External , establishing federation with external client portals (SAML/OIDC), providing reference SSO integration, and ensuring strong security, documentation, and knowledge transfer.

Key Responsibilities
  • Organize discovery workshops to assess existing authentication methods, workflows, and types of external users.
  • Evaluate Azure tenant readiness, licensing, security and compliance requirements, and establish a project plan with milestones and RACI assignments.
  • Identify prerequisites such as network configuration, required ports, and environment setup strategy, collaborating with application teams to address dependencies.
  • Develop an authentication architecture for external users with Entra External .
  • Define user registration and login processes, IdP federation strategies (SAML/OIDC), and tailor branding and UX for user journeys.
  • Design Conditional Access and MFA policies, including bypass options for partner-initiated flows when necessary (in partnership with app teams).
  • Create architecture diagrams and high/low-level design documents.
  • Prepare the development environment, configure the Entra External t, and register required applications.
  • Set up federation and integration patterns for external client portals.
  • Apply session and token management best practices to ensure smooth portal navigation and proper sign-out behavior.
  • Establish a migration strategy and tools using Microsoft Graph APIs, along with scripts and infrastructure.
  • Plan and conduct pilot migration, then advance to full-scale migration readiness.
  • Maintain attribute mapping and ensure identity data integrity during migration.
  • Lead UAT validation, manage issue triage and remediation tracking, and refine policies and UX from feedback.
  • Verify conditional access/MFA enforcement versus bypass scenarios, and test end-to-end SSO functionality.
  • Create comprehensive documentation covering configuration, federation, migration steps, and operational runbooks.
  • Host working sessions and transfer knowledge to enable internal teams to manage additional client SSO integrations independently.
  • Perform security reviews for identity flows, token lifetimes, claims issuance, and federation trust boundaries.
  • Support cutover planning, rollback strategies, and post-migration stabilization.
  • Collaborate with security operations teams to ensure logging, monitoring, and auditability of authentication events.
  • Provide ongoing advisory support during early operations (hypercare) post go-live.
Required Skills & Experience
  • 10+ years in Identity & Access Management with hands-on SSO and federation implementations.
  • Strong expertise in:
    • Microsoft Entra External
    • OAuth2 / OIDC, SAML 2.0, JWT, token/session management
    • Application registrations, redirect URIs, certificates/secrets, custom domains concepts
  • Experience with Azure AD B2C and migration patterns to Entra External .
  • Working knowledge of Microsoft Graph API for user migration and identity operations.
  • Practical experience designing and implementing Conditional Access + MFA strategies.
  • Strong documentation and stakeholder management skills; ability to run workshops and KT sessions.
Nice-to-Have
  • Experience integrating SSO with mobile apps (browser-based handoff, deep links, sign-out redirection patterns).
  • Familiarity with Identity Governance/RBAC best practices for least privilege access.
  • Experience hands on experience migrations at large scale.
Preferred Certifications
  • Microsoft Certified:
    Identity and Access Administrator Associate
  • Microsoft Certified:
    Cybersecurity Architect Expert
Soft Skills:
  • Strong analytical, problem-solving, and troubleshooting skills.
  • Excellent communication and stakeholder management abilities.
  • Ability to work independently and collaboratively in a fast-paced environment.
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary