Azure Cloud Engineer – ICAM

Identity & Access Management
Entra ID - PIM / SSO / Zero Trust

About the Role

EdgeByte is seeking an Azure Cloud Engineer – Identity & Access Management (ICAM) to architect, implement, secure, and support enterprise identity solutions across Microsoft Azure, Microsoft Entra ID, hybrid-cloud, and on-premises environments.

This role requires hands-on experience with identity architecture, authentication, authorization, federation, identity lifecycle management, privileged access, application integration, and Zero Trust principles. The engineer will support workforce identities, administrators, external users, applications, service accounts, and workload identities across modern and legacy environments.

The position will support customers across commercial, state and local government, education, federal, and other regulated industries. Responsibilities may include Microsoft Entra ID, Active Directory integration, SSO, MFA, Conditional Access, identity governance, PIM, application federation, certificate-based authentication, and automated identity provisioning.

Reponsibilities:

  • Design and implement Microsoft Entra ID and hybrid identity architectures.
  • Configure SSO, MFA, Conditional Access, passwordless authentication, and identity security controls.
  • Integrate applications using SAML, OAuth 2.0, OIDC, SCIM, and related identity standards.
  • Support Active Directory, Entra Connect/Cloud Sync, LDAP, Kerberos, and hybrid authentication.
  • Manage Enterprise Applications, App Registrations, service principals, managed identities, and application permissions.
  • Implement PIM, RBAC, identity governance, access reviews, and identity lifecycle management.
  • Support PKI, certificate-based authentication, PIV/CAC, FIDO2, and other strong-authentication technologies where required.
  • Troubleshoot authentication, authorization, federation, provisioning, and directory synchronization issues.
  • Automate identity operations using PowerShell, Microsoft Graph, APIs, Terraform, or similar technologies.
  • Develop identity architecture diagrams, implementation plans, standards, runbooks, and technical documentation.
  • Apply Zero Trust, least privilege, privileged-access, and identity-security principles across customer environments.
  • Collaborate with cloud, cybersecurity, networking, infrastructure, application, and DevOps teams.
  • Required Qualifications:

  • CompTIA Security+
  • Microsoft Certified: Identity and Access Administrator Associate (SC-300)
  • Microsoft Certified: Azure Administrator Associate (AZ-104)
  • 8+ years of enterprise IT, cloud, infrastructure, cybersecurity, or identity engineering experience.
  • 4+ years of hands-on cloud or identity engineering experience.
  • Strong experience with Microsoft Entra ID and Active Directory.
  • Experience with SSO, MFA, Conditional Access, RBAC, PIM, and identity governance.
  • Knowledge of SAML, OAuth 2.0, OIDC, Kerberos, LDAP, SCIM, and modern authentication.
  • Experience integrating enterprise, SaaS, and legacy applications with centralized identity providers.
  • Understanding of PKI, certificates, privileged access, passwordless authentication, and Zero Trust principles.
  • Experience troubleshooting complex authentication, authorization, federation, provisioning, and identity issues.
  • Experience with Enterprise Applications, App Registrations, service principals, managed identities, and application permissions.
  • Experience with PowerShell, Microsoft Graph, APIs, Terraform, or similar automation technologies.
  • Strong technical documentation, troubleshooting, and communication skills.
  • U.S. work authorization and ability to satisfy customer-specific access requirements.
  • Preferred Qualifications:

  • Advanced Microsoft Entra ID Governance, PIM, Identity Protection, or Conditional Access experience.
  • Experience with PKI, PIV/CAC, FIDO2, certificate-based authentication, or passwordless technologies.
  • Experience with Okta, Ping Identity, SailPoint, CyberArk, BeyondTrust, Duo, or similar identity platforms.
  • Experience with SCIM provisioning, Microsoft Graph integrations, APIs, or identity automation.
  • Experience with Entra Application Proxy and modernization of authentication for legacy applications.
  • Experience with hybrid identity migrations, tenant consolidation, Active Directory modernization, or tenant-to-tenant migrations.
  • Experience implementing privileged-access management, administrative tiering, and least-privilege architectures.
  • Knowledge of NIST 800-53, NIST 800-63, Zero Trust, FedRAMP, CMMC, CIS, ISO 27001, or similar frameworks.
  • Experience supporting regulated, commercial, government, defense, financial, healthcare, or other security-sensitive environments.
  • Relevant Microsoft identity, Azure, cloud, security, or architecture certifications.
  • POSITION DETAILS
    Job ID
    CLD-ENG-ID001
    Department
    Identity & Access Management
    Job Family
    ICAM / Identity
    Specialty
    Entra ID - PIM / SSO / Zero Trust
    Experience Level
    Intermediate
    Labor Category
    T2
    Position Status
    Pipeline
    Work Arrangement
    Remote
    Location
    Any State
    Salary Range
    $75,000 - $150,000
    Clearance
    Ability to obtain and maintain customer-required security clearance
    Travel Requirement
    Up to 10%
    Posted Date
    August 28, 2026
    Closing Date
    October 30, 2026
    Apply Now