IT IAM Engineer (Microsoft)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
IT IAM Engineer (Microsoft): Designing, implementing, and operating secure identity and access management solutions across hybrid environments with an accent on Microsoft Entra ID and Active Directory. Focus on automating identity lifecycle management, enforcing access governance via RBAC/ABAC, and implementing Zero Trust security principles.
Location: Porto
Company
is a global transformation partner specializing in tech strategy, digital solutions, and systems engineering across Europe and Asia.
What you will do
- Design and operate IAM solutions using Microsoft Entra ID and Active Directory in hybrid environments.
- Manage identity lifecycles (Joiner-Mover-Leaver) and automate provisioning/deprovisioning processes.
- Implement authentication mechanisms including SSO, MFA, and Conditional Access.
- Manage authorization models based on RBAC and ABAC principles to ensure least privilege.
- Utilize Privileged Identity Management (PIM) and just-in-time access to reduce standing privileges.
- Automate IAM processes via PowerShell and Microsoft Graph API to improve scalability and efficiency.
Requirements
- Several years of professional experience in Identity and Access Management.
- Hands-on experience with Microsoft Entra ID and Active Directory in hybrid setups.
- Proficiency with SAML, OAuth2, and OpenID Connect protocols.
- Strong understanding of access control models and governance principles.
- English: Fluent (C1)
Nice to have
- Experience with HR system integrations and SCIM provisioning.
- Proficiency in automation using PowerShell or Microsoft Graph API.
Culture & Benefits
- Opportunity to work on a global scale within a multidisciplinary team.
- Culture focused on engineering excellence and innovation.
- Inclusive work environment that welcomes people from all backgrounds.
- Collaborative atmosphere emphasizing knowledge sharing and joint problem-solving.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →