You will architect and modernize enterprise identity, access management, and endpoint systems.
This role is remote.
Responsibilities
Architect and modernize Active Directory forests, domains, trusts, DNS, and GPO structures while defining security hardening standards.
Design and govern ADFS and federation architectures, integrating on-premises and cloud applications using SAML, OAuth, and OpenID Connect.
Optimize Microsoft Entra ID tenant design, identity lifecycle, and access governance, including Conditional Access, PIM, and hybrid identity integration.
Define enterprise standards for endpoint management using Microsoft Intune, ensuring device compliance, encryption, and Zero Trust controls.
Produce architecture diagrams and design documents, acting as the technical authority for identity and endpoint-related decisions.
Required Skills
12+ years of experience in Identity, IAM, Directory Services, or Security Architecture roles.
Deep expertise in Active Directory, ADFS, and Microsoft Entra ID (Azure AD) at an enterprise scale.
Strong knowledge of IAM concepts, federation, SSO, MFA, and access governance models (RBAC, ABAC).
Hands-on experience with endpoint management (Intune, GPOs, device compliance) and authentication protocols (LDAP, SAML, OAuth).
Proven experience designing enterprise-scale hybrid identity and endpoint environments.
Experience supporting cloud transformation and Zero Trust initiatives.
Ability to lead AD consolidation, cleanup, migration, and upgrade initiatives.
Strong understanding of security policies, regulatory standards, and audit requirements.
Preferred Skills
Certifications such as CISSP, CISM, Azure Identity, TOGAF, or ITIL.
Bachelor’s degree in Computer Science, Information Technology, or a related field.
Experience with PAM, IGA, CIAM, and third-party IAM platforms.