| Location | San Francisco, CA (Remote) |
| Start Date of Assignment: | 10/1/2026 | ||
| Term (including any Option Terms): | Maximum Hours Per Term | |||
| Initial Term: | 10/01/2026 – 09/30/2027 | 1,976 | ||
| 1st Option Term: | 10/01/2027 – 09/30/2028 | 1,976 | ||
| 2nd Option Term: | 10/01/2028 – 09/30/2029 | 1,968 | ||
| Task No. | Description of Tasks and Responsibilities for each Classification |
|---|---|
| 1 | Identity Architecture & Foundation • Design and document scalable Azure Entra ID tenant topologies, including multi-organization frameworks and external B2B/B2C collaboration structures. • Establish and enforce enterprise-wide identity standards, architecture guardrails, and naming conventions across all business units and branches. • Architect and manage secure deployment matrices for workload identities, including Service Principals, Managed Identities, and application registrations. |
| 2 | Security, Authentication & Zero Trust Implementation • Configure and deploy a comprehensive Conditional Access policy suite tailored to role-based risks and user sign-in risk levels. • Implement and scale passwordless authentication mechanisms across the enterprise, including FIDO2 security keys, Passkeys, and Windows Hello for Business. • Deploy and tune Identity Protection policies to enable automated risk-based authentication and real-time remediation of compromised accounts. • Establish secure lifecycle management and automated rotation frameworks for cryptographic keys, certificates, and application secrets. |
| 3 | Identity Governance & Lifecycle Automation • Build and automate end-to-end Joiner, Mover, and Leaver (JML) user lifecycle workflows utilizing Microsoft Graph API, PowerShell, and Azure Functions. • Engineer self-service entitlement management catalogs and automate compliance-driven access reviews using Azure Logic Apps. • Formulate and enforce lifecycle governance policies for guest access, external partners, and B2B user permissions. |
| 4 | Application & API Integration • Integrate and onboard SaaS, on-premises, and custom-developed applications (.NET/C#) using standard OAuth 2.0, OpenID Connect, and SAML 2.0 protocols. • Configure custom token issuance, claims mapping, and MSAL-based authentication across single-page apps, web apps, and web APIs. • Develop and execute custom authentication extensions to dynamically inject external claims or modify default authentication flows. |
| 5 | Automation, Scripting & DevOps (CI/CD) • Integrate identity configurations and policy changes into automated CI/CD pipelines to achieve Identity-as-Code (IaC). • Write and maintain clean, reusable script libraries using PowerShell, Azure CLI, and Microsoft Graph SDKs to automate repetitive identity workflows. |
| 6 | Compliance, Risk Management & Operations • Align and map Entra ID technical controls to regulatory frameworks, including NIST, FedRAMP, SOC 2, and ISO 27001. • Compile and deliver structured audit evidence packages to demonstrate the compliance and efficacy of identity controls. • Author technical runbooks for operational teams to streamline the monitoring, troubleshooting, and optimization of complex token and authentication flows. |
| 7 | Cross-Functional Leadership & Enablement * Translate complex business and compliance requirements into comprehensive Technical Design Documents (TDD). * Collaborate with security, application, DevOps, and infrastructure teams to drive enterprise-wide identity modernization initiatives. * Communicate high-level identity strategies and risk profiles effectively to non-technical stakeholders and executive leadership. |