Job Summary : The client is standing up a new Identity & Access Management (IAM) function from the ground up and needs a hands-on Level 3 engineer to provide immediate day-to-day engineering and troubleshooting support while their permanent team is built out. The workplace is Microsoft-centric: Microsoft Entra ID is the cloud identity provider (IDP) and SSO/MFA platform, on-premises Active Directory is the source of truth (synced to Entra via Entra ID Connect), and Workday is the HRIS. There is currently no formal identity governance or automation in place — joiner/mover/leaver is handled through a legacy custom-scripted tool — and the client is evaluating platforms to build a modern Identity Governance & Administration (IGA) capability, with Privileged Access Management (PAM) to follow.
Key Responsibilities
Job Responsibilities : • Administer and troubleshoot Microsoft Entra ID, including Conditional Access policies, SSO configuration, MFA, and Entra ID Connect (Azure AD Connect) synchronization with on-premises Active Directory. • Administer on-premises Active Directory, where user accounts are mastered before syncing to Entra ID. • Support SAML/OIDC application onboarding and SSO migrations, including remaining app migrations from a recent acquisition (Catalyst Clinical Research) into the corporate tenant. • Support and help automate the joiner/mover/leaver (JML) lifecycle, currently a manual, custom-scripted process driven by Workday data and executed by the service desk. • Contribute engineering input to the evaluation and future implementation of an Identity Governance & Administration (IGA) platform. • Provide input on future Privileged Access Management (PAM) and Privileged Identity Management (PIM)
rollout as the governance foundation matures. • Attend and actively participate in IAM-related meetings — including ongoing Conditional Access hardening and an active MDM (mobile device management) initiative — to stay aligned with the Director's guidance and priorities. • Document processes and support knowledge transfer as the client builds its permanent, in-house IAM engineering and architecture team.
Skill Requirements
Skill Requirement : • Administer and troubleshoot Microsoft Entra ID, including Conditional Access policies, SSO configuration, MFA, and Entra ID Connect (Azure AD Connect) synchronization with on-premises Active Directory. • Administer on-premises Active Directory, where user accounts are mastered before syncing to Entra ID. • Support SAML/OIDC application onboarding and SSO migrations, including remaining app migrations from a recent acquisition (Catalyst Clinical Research) into the corporate tenant. • Support and help automate the joiner/mover/leaver (JML) lifecycle, currently a manual, custom-scripted process driven by Workday data and executed by the service desk. • Contribute engineering input to the evaluation and future implementation of an Identity Governance & Administration (IGA) platform. • Provide input on future Privileged Access Management (PAM) and Privileged Identity Management (PIM) rollout as the governance foundation matures. • Attend and actively participate in IAM-related meetings — including ongoing Conditional Access hardening and an active MDM (mobile device management) initiative — to stay aligned with the Director's guidance and priorities. • Document processes and support knowledge transfer as the client builds its permanent, in-house IAM engineering and architecture team.