{bc}
pinpoint

IAM Consultant/Developer (Microsoft Entra ID) - Contract

Nasstar
Remote, GBR
Contract
Senior
Remote
Discovered 2 weeks ago
Microsoft Entra IDOktaPingMicrosoft Entra ConnectSAML 2.0OAuth 2.0
Free

Job Fit Check

Base Career helps you apply smarter for this job.

?%
Ready to Scan

Key skills for this role

Microsoft Entra IDOktaPing
Smart Apply

Full Job Posting

What You'll Be Doing

Discovery & design — audit the existing identity estate (on-prem AD, and/or third-party IdP such as Okta or Ping) and design the target-state architecture in Microsoft Entra ID.

Migration execution — plan and run the cutover, including phased/staged migration approaches to minimise disruption to live services.

Hybrid identity — configure and manage synchronization between on-prem and cloud using Microsoft Entra Connect or Entra Cloud Sync during the transition period.

Authentication & security — implement MFA, Conditional Access policies, and passwordless sign-in aligned to Zero Trust principles.

Application integration — migrate or re-establish SSO for enterprise applications using SAML, OAuth 2.0, and OIDC.

Identity governance — stand up Privileged Identity Management (PIM), Entitlement Management (access packages), and Access Reviews as part of the target state.

Cutover support & troubleshooting — monitor sign-in/audit logs and identity protection signals during and after migration to catch issues early.

Documentation & handover — leave the operations team with clear runbooks and a clean handover once migration is complete.

What We're Looking For

Proven experience delivering a migration onto Microsoft Entra ID (formerly Azure AD) — from on-prem AD DS or from a third-party IdP (Okta, Ping, ForgeRock, etc.).

Strong working knowledge of Conditional Access, Zero Trust security models, and modern authentication protocols (SAML 2.0, OAuth 2.0, OIDC).

Confident PowerShell scripting for identity lifecycle automation, ideally via the Microsoft Graph PowerShell SDK.

Comfortable working independently and communicating migration risk/status to non-technical stakeholders.

KQL for log analysis in Microsoft Sentinel or Azure Monitor.

Experience with Entra ID B2B/B2C.

Background with an alternative IAM platform (ForgeRock, Ping, Okta) — genuinely useful for migration work, since you understand what you're migrating from, not just what you're migrating to.

SC-300 (Identity and Access Administrator Associate)

SC-100 (Cybersecurity Architect Expert)

SC-500 (Cloud and AI Security Engineer Associate)

CISSP

Apply for this job in 1 click

Skip the repetitive application forms

Install the Base Career Chrome Extension and autofill job applications across major job boards with your profile.

Sarah M.James T.Maya R.

Trusted by over 500,000 job seekers on Base Career

Start Free Today

More from this employer

More jobs at Nasstar