Design, implement, and maintain enterprise identity architectures within Microsoft Azure
Serve as the technical authority for identity and access management (IAM) solutions, including Microsoft Entra ID (Azure AD), ADFS, and hybrid identity integrations
Architect and manage endpoint engineering and device management solutions, leveraging Microsoft Endpoint Configuration Manager (MECM/SCCM) and Microsoft Intune
Define and enforce identity and endpoint standards , policies, and configurations to ensure consistency, security, and scalability across the enterprise
Design and support identity federation, single sign-on (SSO), conditional access, and authentication flows across enterprise systems
Integrate identity and endpoint services with Azure-hosted workloads and on-premises infrastructure
Collaborate with Information Assurance and cybersecurity teams to design and implement security controls related to identity, access, and endpoint management
Support compliance, audit, and authorization activities by providing architecture documentation, control mappings, and technical guidance
Lead troubleshooting and resolution of complex identity and endpoint issues, including authentication failures, access problems, and device compliance issues
Evaluate and recommend improvements to identity and endpoint architectures, balancing security, usability, and operational impact
Guide system and platform engineers on identity integration patterns and endpoint management best practices
Maintain authoritative architecture diagrams, standards, and technical documentation for identity and endpoint services
Support lifecycle activities for identity and endpoint platforms, including upgrades, migrations, and modernization efforts
Participate in strategic planning and technical reviews to ensure identity and endpoint services align with enterprise architecture and mission needs
Requirements
Minimum 4 years of relevant experience (with significant depth in identity and endpoint engineering)
Bachelor’s degree in IT, Cybersecurity, or related field OR equivalent combination of education, training, and experience
Proven experience managing identity services within Microsoft Azure
Microsoft Certified: Azure Administrator Associate or higher
Must meet DoD 8570 / 8140 IAT-II requirements (examples in the table include Security+, SSCP, GSEC, etc.)
Microsoft Entra ID (Azure AD)
ADFS and hybrid identity architectures
Microsoft Endpoint Configuration Manager (MECM / SCCM)