Microsoft Entra ID (Advanced Implementation)
- Implement and optimize Conditional Access policies based on approved designs
- Support and operationalize:
- Riskbased access policies
- Authentication Strengths and phishingresistant MFA
- Lead operational implementation of Privileged Identity Management (PIM):
- Role assignments
- Approval workflows
- JustinTime access configuration
- Secure application and workload identities:
- App registrations and service principals
- OAuth permission governance
OnPrem Active Directory (Security & Hardening)
- Support and enforce AD security best practices:
- Tiered admin model (Tier 0 / 1 / 2)
- Privileged account separation
- Lead AD hardening activities:
- LAPS
- Protected Users
- Delegation and admin access restrictions
- Troubleshoot complex AD security and authentication issues
Hybrid Identity & Integration
- Support Entra Connect configuration and lifecycle management
- Assist in evaluating authentication models and hybrid trust decisions
- Support integration of identity with:
- Azure subscriptions
- Thirdparty SaaS applications
Threat Detection & Operations
- Support CyberDefence team for Identity (MDI) investigations and tuning
- Act as a technical escalation point during identityrelated incidents
Collaboration & Mentoring
- Mentor midlevel engineers and provide technical guidance
- Participate in design reviews and provide implementation feedback
- Work closely with Identity Architects Security and Platform teams
Qualifications :
- 810 years of experience in identity and access management
- Strong handson experience with:
- Microsoft Entra ID P2
- Conditional Access at scale
- Privileged Identity Management
- Active Directory security
- Experience supporting hybrid AD environments
- Advanced PowerShell scripting and automation
- Strong understanding of identitybased attack techniques and mitigations
- Solid grasp of Zero Trust principles (implementationfocused)
Additional Information :
- Experience with:
- Concepts around IGA
- Defender for Identity
- Passwordless authentication (FIDO2 WHfB)
- VDI or shared device environments
- Certifications:
- SC300
- AZ500
- Microsoft Security certifications
Remote Work :
No
Employment Type :
Full-time
Experience: years
Vacancy: 1