000 – Senior Azure Cloud Engineer – Entra ID

We are seeking a highly skilled Senior Azure Cloud Engineer to support critical mission infrastructure. The ideal candidate will have extensive hands-on experience designing, deploying, and maintaining secure Azure environments, with a primary focus on robust identity and access management using Microsoft Entra ID.

Required Minimum Qualifications

  • Clearance: Must hold a current DoW Secret clearance and be eligible for TS/SCI.
  • Education: Bachelor’s degree in a technical discipline.
  • Experience: A minimum of 5 years of dedicated, hands-on engineering and administration experience within Microsoft Azure.
  • Identity Expertise: Proven Subject Matter Expert (SME) level proficiency in Microsoft Entra ID architecture and management.

Key Skills: Microsoft Entra ID (Core Requirement)

The candidate must demonstrate strong technical proficiency and hands-on experience in the following Entra ID (formerly Azure AD) capabilities:

  • Identity & Access Management (IAM):
    • Demonstrated ability to design and implement secure identity lifecycle management, including automated user provisioning and de-provisioning with SCIM (System for Cross-domain Identity Management).
    • Expertise in architecting and enforcing comprehensive Role-Based Access Control (RBAC) models at all scopes (Management Group, Subscription, Resource Group, and individual Resource) based on the principle of least privilege.
    • Experience creating and managing custom RBAC roles to meet specific mission requirements that are not covered by built-in roles.
    • Proven experience conducting periodic access reviews for privileged and non-privileged accounts to ensure compliance and reduce standing access.
  • Certificate-Based Authentication (CBA) & CAC Integration:
    • Deep expertise in configuring and deploying Entra ID Certificate-Based Authentication (CBA) to enable phishing-resistant, password less authentication natively in the cloud.
    • Hands-on experience integrating Department of War (DoW) Common Access Cards (CAC) and Public Key Infrastructure (PKI) certificates with cloud identities.
    • Proficiency in managing trusted Certificate Authorities (CAs), uploading Certificate Revocation Lists (CRLs), and configuring certificate bindings (e.g., mapping Principal Name or RFC822Name to User Principal Name).
    • Experience enforcing strict CAC-only access to highly sensitive mission environments and applications by leveraging Conditional Access Authentication Strength policies.

 

  • Conditional Access:
    • Deep understanding of building, testing, and enforcing complex Conditional Access policies to secure user access and protect mission data.
    • Experience leveraging a wide range of signals, including user/group membership, named locations (IP ranges), device compliance state (via Intune), and sign-in/user risk levels.
    • Proficiency in applying granular controls, such as enforcing Multi-Factor Authentication (MFA), requiring compliant devices, limiting session lifetimes, and blocking legacy authentication protocols.
    • Skilled in using the “what-if” tool to validate policy changes before deployment to avoid user lockout or mission interruption.
  • Privileged Identity Management (PIM):
    • Expertise in configuring and managing PIM for both Entra ID roles and Azure resource roles to govern privileged access.
    • Proven ability to implement just-in-time (JIT) access, time-bound role assignments, and custom approval workflows for activating privileged accounts.
    • Experience establishing and running access reviews for all privileged roles to ensure only authorized personnel maintain eligibility.
    • Ability to audit PIM activity, configure alerts for suspicious activations, and generate compliance reports.
  • Enterprise Applications & Single Sign-On (SSO):
    • Extensive experience registering and managing Enterprise Applications, including gallery and non-gallery apps, to enable secure SSO.
    • Strong understanding of modern authentication protocols (SAML 2.0, OAuth 2.0, and OpenID Connect) and experience integrating applications using these standards.
    • Proficiency in managing API permissions, application consent policies, and service principal security to prevent illicit consent grant attacks and ensure secure application-to-application communication.
  • Hybrid Identity:
    • Hands-on experience deploying, managing, and troubleshooting hybrid identity solutions using Microsoft Entra Connect or Entra Connect Cloud Sync.
    • In-depth knowledge of various authentication methods, including Password Hash Synchronization (PHS), Pass-Through Authentication (PTA), and Federation (AD FS), and the ability to recommend the appropriate model based on security and operational requirements.
    • Experience monitoring synchronization health with Entra Connect Health and troubleshooting object synchronization errors.
  • Identity Protection & Security:
    • Proven ability to leverage Entra ID Identity Protection to detect, investigate, and remediate identity-based risks.
    • Experience configuring and tuning user risk policies and sign-in risk policies and integrating them with Conditional Access for automated responses, such as forcing a secure password reset or blocking access.
    • Deep understanding of Continuous Access Evaluation (CAE) and its role in enforcing security policies in near real-time by revoking access based on critical events.

Highly Desired Qualifications

Candidates possessing the following supplementary skills will be given strong preference:

  • Microsoft Sentinel: Experience deploying and configuring Sentinel for cloud-native SIEM/SOAR capabilities, including custom analytic rules and playbooks.
  • Microsoft Defender for Cloud: Proficiency in managing Cloud Security Posture Management (CSPM) and Cloud Workload Protection (CWP) to secure Azure resources.
  • Azure Arc: Experience onboarding and managing hybrid, multi-cloud, or on-premises servers and Kubernetes clusters through Azure Arc.

To apply for this job email your details to jobs@dei.net

Scroll to Top