IAM Engineer - MS365 / Entra ID / SSO / MFA
3 days ago
Sheffield
Microsoft 365 / Entra ID / SSO / MFA\n\nRole: IAM Engineer \n Contract: 6+ months initially\n IR35: Inside IR35\n Day Rate: Up to £800 per day (via umbrella) potential for flex DOE\n Location: Hybrid - 2 days/week on‑site in Sheffield, remainder remote\n Start: ASAP\n\nSummary\n\nAn established well known national organisation is seeking a hands‑on IAM Engineer to implement and operate identity, authentication, and access controls across Microsoft 365 and Microsoft Entra ID (Azure AD).\n\nFocus is on SSO, MFA, Conditional Access, identity lifecycle, and privileged access (with CyberArk as a desirable skill). This is a delivery and operations role (not an architect), partnering with Security, Infrastructure, and Service Management to harden controls, reduce risk, and improve user experience.\n\nResponsibilities\n\nEntra ID operations & hardening: tenant hygiene, identity security baseline, Conditional Access (CA) design/maintenance, break‑glass access.\nSSO engineering: onboard and support SAML/OIDC apps; configure enterprise app registrations, claims, tokens, and session settings.\nMFA at scale: method policies (Authenticator, FIDO2, SMS), registration campaigns, CA‑based MFA enforcement, resilient admin access patterns.\nLifecycle & access controls: group‑based access, dynamic groups, PIM (just‑in‑time admin), RBAC reviews, access reviews, least‑privilege enforcement.\nMicrosoft 365 alignment: integrate with Defender for Cloud Apps, govern Exchange/SharePoint/Teams access, improve Secure Score.Required Skills & Experience\n\nProven, hands‑on Microsoft Entra ID administration: app registrations, Conditional Access, Identity Protection, authentication strengths, and policy operations.\nSSO delivery using SAML 2.0 / OIDC / OAuth 2.0: enterprise app onboarding, claims mapping, token troubleshooting (SAML traces, Fiddler, browser dev tools).\nMFA engineering and rollout: CA‑based MFA, method policies, break‑glass procedures, staged/targeted deployments.\nMicrosoft 365 security controls: Exchange, SharePoint/OneDrive, Teams governance and access configuration.Desirable\n\nCyberArk PAM (Core PAS): Safes, platform onboarding, credential rotation, PSM/PSMP, API integration.If you have the relevant skills and interested in hearing more please apply with your latest CV