Koniag Data Solutions, a Koniag Government Services company, is seeking an experienced
Entra ID Integration Engineer (Senior) to support enterprise identity and access management operations and IT administrative and operational support services for a federal government client. This position requires an active security clearance or the ability to obtain and maintain a government background investigation and all requisite IT access authorizations prior to performing work. Specific clearance requirements will be confirmed at time of offer. Primary work will be performed at the client site in Washington, DC and approved remote/telework locations.
This role serves as a critical senior technical function responsible for the architecture, engineering, implementation, administration, and continuous improvement of enterprise Microsoft Entra ID (formerly Azure Active Directory) identity and access management capabilities across a complex, geographically distributed federal IT environment spanning on-premises infrastructure, cloud platforms, hybrid environments, and enterprise applications.
The ideal candidate is a highly experienced and technically authoritative identity and access management engineer with deep, hands-on expertise across the full Microsoft Entra ID platform portfolio-including Entra ID tenant administration, Conditional Access, Privileged Identity Management (PIM), Identity Protection, External Identities, Entra ID Governance, and hybrid identity integration with on-premises Active Directory-combined with a comprehensive understanding of enterprise identity architecture, Zero Trust identity principles, and Federal cybersecurity compliance requirements. This individual must possess the technical depth, architectural vision, and operational discipline required to lead the design, implementation, and sustained operation of enterprise-grade Entra ID identity capabilities that protect Government identities, enforce least-privilege access, and support Zero Trust objectives in a highly regulated federal IT environment.
The Entra ID Integration Engineer (Senior) will serve as the program's primary subject matter expert and technical authority for all Microsoft Entra ID platform capabilities, leading the architecture, engineering, implementation, administration, and continuous improvement of enterprise identity and access management infrastructure. This individual works closely with security engineers, network engineers, cloud operations teams, Zero Trust engineers, DevSecOps engineers, application developers, and Government stakeholders to ensure Entra ID capabilities are architected, deployed, and operated in a manner that delivers maximum identity security, operational resilience, and compliance with Federal cybersecurity frameworks and Zero Trust Architecture objectives across the full enterprise environment.
Principal responsibilities will include but are not limited to:
Architecture & Engineering Leadership- Serve as the program's technical authority and subject matter expert for all Microsoft Entra ID platform capabilities, providing authoritative architectural guidance, engineering leadership, and expert technical recommendations to program leadership, functional teams, and Government stakeholders on identity architecture, access management strategy, and Zero Trust identity implementation.
- Lead the design and architecture of enterprise Microsoft Entra ID identity solutions, including tenant architecture design, hybrid identity infrastructure, Conditional Access policy frameworks, Privileged Identity Management configurations, Identity Protection policies, and Entra ID Governance implementations aligned with Federal Zero Trust requirements and program security objectives.
- Develop and maintain enterprise Entra ID architecture documentation, including identity architecture diagrams, authentication flow diagrams, Conditional Access policy frameworks, hybrid identity topology diagrams, and platform configuration baselines, ensuring documentation is current, accurate, and aligned with operational reality.
- Lead identity architecture reviews for new systems, applications, cloud migrations, and infrastructure changes, assessing Entra ID platform impact, identifying identity security risks, and recommending configuration and policy improvements to maintain Zero Trust identity posture.
- Design and implement Zero Trust identity architectures leveraging Microsoft Entra ID capabilities, including continuous access evaluation, risk-based Conditional Access, phishing-resistant MFA enforcement, identity risk detection, and least-privilege access governance.
- Evaluate emerging Microsoft Entra ID platform capabilities, identity security industry developments, and Federal identity policy requirements, providing well-researched recommendations to program leadership and Government stakeholders on opportunities to enhance identity security and advance Zero Trust maturity.
- Provide senior technical leadership and mentorship to junior and mid-level engineers, sharing identity and access management expertise, guiding technical development, and ensuring consistent application of identity engineering best practices across the team.
Entra ID Tenant Administration & Engineering- Lead the engineering, implementation, and administration of the enterprise Microsoft Entra ID tenant, ensuring the tenant is properly configured, secured, and continuously maintained in alignment with Federal security requirements, Microsoft security best practices, and applicable DISA STIGs and CIS Benchmarks.
- Design and maintain the enterprise Entra ID tenant configuration, including directory settings, authentication methods, password policies, self-service password reset (SSPR) configurations, and security defaults enforcement in alignment with Zero Trust identity principles.
- Implement and maintain enterprise Entra ID authentication method policies, ensuring phishing-resistant MFA-including FIDO2 security keys, Windows Hello for Business, and certificate-based authentication-is deployed, enforced, and operationally managed across all user populations.
- Configure and maintain Entra ID domain configurations, custom domain registrations, and tenant branding settings, ensuring the tenant accurately represents the Government organization and supports seamless user authentication experiences.
- Administer Entra ID directory objects, including user accounts, groups, administrative units, and service principals, ensuring accurate provisioning, lifecycle management, and deprovisioning in accordance with defined identity governance procedures.
- Implement and maintain Entra ID group management policies, including dynamic group membership rules, group naming conventions, group lifecycle policies, and group-based access assignment configurations.
- Monitor Entra ID tenant health, service availability, and operational metrics, proactively identifying and resolving tenant configuration issues, service disruptions, and security anomalies.
Conditional Access Engineering- Lead the design, implementation, and continuous optimization of the enterprise Conditional Access policy framework, ensuring all access to Government resources is continuously evaluated against defined trust signals and that access decisions enforce Zero Trust least-privilege principles.
- Design and implement a comprehensive, well-structured Conditional Access policy architecture, including named locations, compliance requirements, sign-in risk policies, user risk policies, session controls, and application-specific access policies that collectively enforce granular, risk-based access control across the enterprise.
- Implement and maintain phishing-resistant MFA enforcement policies, ensuring strong, unphishable authentication factors are required for all privileged access, high-value application access, and access from non-compliant or unmanaged devices.
- Design and implement device compliance-based Conditional Access policies, integrating Microsoft Intune device compliance signals into access control decisions to enforce Zero Trust device trust requirements.
- Implement and maintain sign-in risk and user risk-based Conditional Access policies, leveraging Entra ID Identity Protection risk signals to dynamically adjust authentication requirements and access restrictions based on detected identity risk.
- Implement and maintain Continuous Access Evaluation (CAE) configurations, ensuring access tokens are continuously validated and revoked in near-real time when critical security events or policy changes are detected.
- Manage Conditional Access policy lifecycle, including regular policy review and optimization cycles, policy documentation maintenance, exclusion management, and impact assessment for proposed policy changes.
- Develop and maintain Conditional Access policy documentation, including policy specifications, decision matrices, exclusion registers, and impact assessment records, ensuring the policy framework is well-documented and auditable.
Privileged Identity Management (PIM) Engineering- Lead the engineering, implementation, and administration of Microsoft Entra ID Privileged Identity Management (PIM) capabilities, ensuring all privileged access to Azure resources, Entra ID roles, and enterprise applications is governed through just-in-time access provisioning, approval workflows, and continuous monitoring.
- Design and implement PIM role assignment policies for all Entra ID directory roles and Azure resource roles, defining eligibility criteria, activation requirements, maximum activation durations, approval workflows, and justification requirements for each privileged role.
- Configure and maintain PIM access review campaigns for all privileged role assignments, ensuring periodic certification of privileged access is conducted, documented, and enforced in alignment with least-privilege access governance requirements.
- Implement and maintain PIM alert configurations, ensuring anomalous privileged access activities-including role activations outside business hours, repeated activation failures, and assignments outside PIM governance-are detected and escalated promptly.
- Develop and maintain PIM operational documentation, including privileged role catalogs, activation procedure guides, and access review schedules, ensuring PIM governance processes are well-documented and consistently followed.
Identity Protection Engineering- Lead the engineering, implementation, and administration of Microsoft Entra ID Identity Protection capabilities, ensuring continuous detection, investigation, and remediation of identity-based threats across the enterprise user population.
- Configure and maintain Identity Protection user risk and sign-in risk detection policies, ensuring high-risk identity events trigger appropriate automated remediation actions-including MFA challenges, password resets, and session termination-or are escalated for manual investigation.
- Develop and maintain Identity Protection risk investigation workflows, ensuring security operations personnel have clear procedures for investigating and remediating detected identity risk events in a timely and consistent manner.
- Integrate Identity Protection risk signals with the enterprise SIEM platform and security operations workflows, ensuring identity risk detections are incorporated into the program's broader threat detection, investigation, and incident response processes.
- Monitor Identity Protection detection effectiveness, analyzing risk detection rates, false positive patterns, and remediation outcomes to identify tuning opportunities and improve detection fidelity.
Entra ID Governance Engineering- Lead the engineering, implementation, and administration of Microsoft Entra ID Governance capabilities, including entitlement management, access reviews, lifecycle workflows, and terms of use policies, ensuring identity governance processes are automated, auditable, and aligned with least-privilege access principles.
- Design and implement Entra ID Governance entitlement management configurations, including access package definitions, access package policies, approval workflows, and assignment lifecycle management, ensuring users can request access through governed, auditable processes.
- Configure and maintain Entra ID Governance access review campaigns for group memberships, application assignments, and privileged role assignments, ensuring periodic access certification is consistently conducted and documented across all critical access populations.
- Implement and maintain Entra ID Governance lifecycle workflow configurations, including joiner, mover, and leaver workflow automation, ensuring user account provisioning, access updates, and deprovisioning are triggered automatically based on HR system signals and defined workflow logic.
- Develop and maintain identity governance reporting capabilities, providing program leadership and Government stakeholders with accurate visibility into access certification status, entitlement management activity, and identity lifecycle workflow outcomes.
Hybrid Identity Engineering- Lead the engineering, implementation, and administration of hybrid identity infrastructure, ensuring seamless and secure identity synchronization, authentication, and access management between on-premises Active Directory environments and the Microsoft Entra ID cloud tenant.
- Design and maintain Microsoft Entra Connect or Entra Cloud Sync configurations, including object scoping rules, attribute synchronization mappings, password hash synchronization or pass-through authentication configurations, and synchronization health monitoring.
- Implement and maintain Entra ID seamless single sign-on (SSO) configurations for hybrid environments, ensuring domain-joined on-premises devices can authenticate transparently to cloud resources without additional credential prompts.
- Support the administration and maintenance of Active Directory Federation Services (AD FS) configurations where applicable, including claims rule management, relying party trust configurations, and federation health monitoring.
- Monitor hybrid identity synchronization health, identifying and resolvin