×
Register Here to Apply for Jobs or Post Jobs. X
More jobs:

Identity & Access Management (IAM) Engineer​/​/Hybrid NH,NC​/​/(AV

Job in Salem, Rockingham County, New Hampshire, 03079, USA
Listing for: Vision Infotech
Full Time position
Listed on 2026-08-18
Job specializations:
  • IT/Tech
    Cybersecurity
Salary/Wage Range or Industry Benchmark: 140000 - 180000 USD Yearly USD 140000.00 180000.00 YEAR
Job Description & How to Apply Below
Position: Identity & Access Management (IAM) Engineer//Hybrid NH,NC//(AV)

Identity & Access Management (IAM) Engineer
Location: 9 Northeastern Blvd Ste 400, Salem, NH 03079

2121 RDU Center Drive, Suite 300, Morrisville, NC 27560.

Hybrid

Hours:
East Coast hours (will be required to travel)


Why Open:
New Project need


Start Date: ASAP

Duration:
December 2025
- July 2027 (10+ months)


Position Summary

We are seeking an experienced Microsoft Identity Management contractor to design, implement, and harden identity security controls across a global enterprise tenant. This role is hands-on and delivery-focused, covering enterprise passkey deployment, the retirement of SMS and voice authentication in favor of phishing-resistant MFA, Conditional Access policy engineering, application integration governance, and identity risk detection. The ideal candidate has deep, current expertise in the Microsoft Entra  and is comfortable operating in a large, multi-region enterprise with strict compliance and change-management requirements.

The immediate and highest-priority deliverable for this engagement is the enterprise passkey deployment and the accompanying deprecation of SMS and voice authentication methods, both on an accelerated timeline. Candidates should be prepared to lead this work from day one and to demonstrate measurable adoption and legacy-method retirement within the first phase of the engagement.

Key Responsibilities

  • Microsoft Passkeys for Enterprise (Passwordless Authentication)
  • Design and lead the enterprise rollout of Microsoft Entra passkey support, including device-bound and synced passkey strategies.
  • Configure Authentication Methods policies to enable passkeys alongside existing MFA/authentication methods, sequenced with the legacy authentication method deprecation described in Section 2.
  • Define enrollment strategy for end users (self-service registration, Temporary Access Pass provisioning, admin-assisted enrollment for high-privilege accounts).
  • Evaluate compatibility across platforms (Windows Hello for Business, mobile authenticator apps, hardware security keys) and browser/device support matrices.
  • Partner with helpdesk/security awareness teams on rollout communications, training, and support escalation paths.
  • Monitor adoption metrics and authentication method usage reporting post-deployment.
  • Deprecation of SMS and Voice Authentication (Phishing-Resistant MFA)
  • Retire SMS and voice call as permitted authentication methods tenant-wide, establishing phishing-resistant MFA as the enterprise standard.
  • Baseline current registration and usage of SMS and voice methods by user population, region, role, and device type.
  • Define and enforce Conditional Access Authentication Strengths to require phishing-resistant methods, with staged scoping that begins with privileged and high-risk accounts and expands to the full user base.
  • Build and govern the exception framework for populations where passkeys are not immediately viable.
  • Partner with the Global Service Desk to harden identity verification and account recovery procedures.
  • Entra Conditional Access Policy Design & Management
  • Architect, build, and maintain Conditional Access policies governing sign-in risk, device compliance, location, application sensitivity, and user/group scoping.
  • Manage policy lifecycle using report-only mode, staged rollout, and What If tool validation prior to enforcement.
  • Design break-glass/emergency access account exclusions and safeguards to prevent tenant lockout.
  • Integrate Conditional Access with device compliance (Intune), session controls (Conditional Access App Control), sign-in risk (Entra ), and Global Secure Access, where applicable.
  • Continuously review and optimize policies to reduce gaps, redundant rules, and conflicting conditions across a large, distributed policy set.
  • Document policy intent, scope, and exceptions for audit and compliance purposes.
  • Enterprise Application Permissions & Integrations
  • Review, govern, and remediate OAuth/OpenID Connect and SAML application permissions across the enterprise application portfolio.
  • Assess delegated vs. application permissions requested by first- and third-party apps; apply least-privilege principles and admin consent workflows.
  • Configure and maintain admin consent policies, permission classifications, and periodic access reviews for enterprise applications.
  • Support integration of enterprise SaaS applications via SSO (SAML/OIDC), provisioning (SCIM), and federation, coordinating with application owners and vendors.
  • Identify and remediate risky or over-privileged application grants (e.g., via Entra  or Defender for Cloud Apps).
  • Maintain an accurate inventory/catalog of enterprise applications, owners, and permission scopes.
#J-18808-Ljbffr
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary