Azure IAM Engineer (Microsoft Entra ID)
Toronto, Ontario, CanadaContractPosted Jul 8, 2026
Job description
Azure IAM Engineer (Microsoft Entra ID) Experience:
- 6–8 years Essential Skills:
- More than 5 years of IAM experience, with 3+ years in Microsoft Azure / Entra ID.
- Deep knowledge of:
- Azure RBAC
- PIM
- Conditional Access
- Entra ID roles Experience with:
- MFA enforcement
- Authentication methods
- Access policies
- Understanding of:
- Identity lifecycle management
- Access certification processes
- Familiarity with:
- Microsoft Defender for Cloud
- Secure Score recommendations
- Experience with Service. Now or ticketing system integrations for IAM workflows.
- Microsoft Certified
- Identity and Access Administrator (SC-300) preferred.
- Strong documentation and stakeholder communication skills. Role Descriptions:
- Design and implement Azure Entra ID (formerly Azure AD) identity governance frameworks.
- Configure and manage Privileged Identity Management (PIM) for just-in-time privileged access.
- Implement and enforce:
- Conditional Access policies
- MFA
- Phishing-resistant authentication:
- FIDO2
- Passkeys
- Manage RBAC role assignments across:
- Azure subscriptions
- Resource groups
- Management groups
- Remediate:
- Guest user accounts
- Stale identities
- Excessive permission assignments
- Configure and maintain Break Glass (emergency access) accounts with monitoring and alerting.
- Integrate Microsoft Defender for Cloud governance rules with Service. Now for ticketing workflows.
- Support cross-cloud IAM alignment across:
- AWS IAM
- OCI IAM
- Participate in:
- IAM audits
- Access reviews
- Compliance reporting
- Develop:
- IAM runbooks
- RBAC mapping documentation
- Onboarding guides Nice to Have:
- Experience with:
- AWS IAM
- AWS Organizations
- SCPs
- Knowledge of:
- OCI IAM compartments
- Policy structures
- Exposure to:
- SASE
- Zero Trust Network Access (ZTNA) frameworks.