Job Description
Title; Entra ID Consultant/Architect
\n
Location: Boston, MA / Jersey City, NJ Onsite
\n
Duration: Full Time/Permanent
\n
\n
Experience: 7–10 years
\n
Audience: Senior consultants, principal architects, identity security leaders
\n
Role Overview
\n
We are seeking a Microsoft Entra ID Architect to lead the design, governance, and security architecture of a large‑scale identity platform. This role is suited for a seasoned consultant who has moved beyond implementation and now operates as a trusted advisor to security and infrastructure leadership, shaping identity strategy as a core component of Zero Trust.
\n
The successful candidate will define tenant‑level identity architecture, with particular emphasis on Conditional Access policy design, privileged access controls, and attack‑path reduction. This role requires both deep technical authority and the ability to articulate risk‑based design decisions to executive stakeholders.
\n
Key Responsibilities
\n
- \n
- Serve as the lead architect for Microsoft Entra ID, defining long‑term identity and access strategies aligned to Zero Trust and enterprise security objectives.
- Design and govern Conditional Access frameworks that balance security, usability, and operational scalability across workforce, partner, and privileged identities.
- Define security guardrails and architectural standards
- Architect privileged access models using least‑privilege and just‑in‑time principles, including role design, separation of duties, and blast‑radius reduction.
- Act as a advisor to Security, and Infrastructure translating identity risk into actionable architectural decisions.
- Partner with IAM, cloud security, endpoint, and application teams to ensure consistent policy enforcement across the enterprise.
- Evaluate emerging identity threats and platform capabilities, evolving Conditional Access and identity controls accordingly.
- Review and approve complex identity designs, exceptions, and risk acceptances.
\n
\n
\n
\n
\n
\n
\n
\n
\n
Required Experience & Expertise
\n
- \n
- 7–10 years of progressive experience in Identity & Access Management, with significant focus on cloud identity platforms.
- Deep, hands‑on expertise with Microsoft Entra ID , including tenant architecture and advanced security controls.
- Proven experience designing Conditional Access policies at scale, including risk‑based access, session controls, and authentication strength enforcement.
- Strong understanding of identity attack vectors, token theft, privilege escalation, and identity‑centric threat models.
- Experience operating in regulated, audit‑driven environments with high expectations for control design and documentation.
- Ability to communicate complex security concepts clearly to senior IT, security, and risk executives.
- Extensive experience scripting against Microsoft Graph API for automation, reporting, and advanced identity management tasks.
\n
\n
\n
\n
\n
\n
\n
\n
\n
Preferred Qualifications
\n
- \n
- Experience in consulting or advisory roles supporting large enterprises.
- Background in Zero Trust architecture or identity security strategy.
- Industry certifications in security, identity, or cloud architecture (preferred, not required).
- Experience working in large enterprise environment.
\n
\n
\n
\n
