Identity Fabric Principal
Brak informacji o wynagrodzeniu
SeniorFull-time·B2B
#434261·Dodano wczoraj·1
Źródło: CycladTech Stack / Keywords
Microsoft Entra IDOAuth2OpenID ConnectSAMLPowerShellSCIMConditional AccessMFAActive Directory Domain ServicesAD FS
Firma i stanowisko
Cyclad works with top international IT companies to deliver cutting-edge technologies shaping the future, focusing on enterprise identity platforms and governance.
Wymagania
- Minimum 10 years professional experience with at least 8 years in a similar role
- English proficiency at B2 level
- Strong experience in enterprise IAM and hybrid identity environments
- Excellent understanding of OAuth 2.0, OpenID Connect, and SAML
- Practical experience with authentication flows: Auth Code + PKCE, Device Code, Client Credentials, and OBO
- Strong knowledge of token and session lifecycle management
- Experience designing claims strategies, identity normalization, and least-privilege access models
- Understanding of API permissions and consent governance models
- Experience with Microsoft Entra ID tenant configuration, governance, and authentication management
- Experience designing and managing Conditional Access and Identity Protection policies, including MFA
- Knowledge of Entra ID Governance capabilities
- Experience integrating Enterprise Apps, App Registrations, service principals, managed identities
- Knowledge of Entra External ID onboarding models and security/UX trade-offs
- Strong understanding of hybrid identity foundations: AD DS, domains, forests, trusts, GPOs, delegation
- Experience operating and troubleshooting AD FS and federation modernization
- Experience with SailPoint IdentityIQ/IdentityNow delivery
- Experience implementing IGA processes: JML, access requests, certifications, reviews, SoD, entitlement modeling
- Experience with provisioning and lifecycle using SCIM, reconciliation, authoritative sources, JIT provisioning
- Advanced PowerShell scripting with Microsoft Graph modules
- Strong automation mindset and governance experience
- Strong understanding of GDPR/EUDPR, privacy-by-design, auditability
- Experience working in restricted or secure environments
- Strong troubleshooting, analytical, and stakeholder management skills
- Strong documentation discipline (runbooks, SOPs, technical docs)
Obowiązki
- Defining and maintaining modern authentication standards for applications and APIs using OAuth2, OpenID Connect, and SAML
- Supporting project teams in implementing and troubleshooting authentication flows, including Auth Code + PKCE, Device Code, Client Credentials, and On-Behalf-Of (OBO)
- Reviewing and hardening token and session configurations, including refresh behavior and session controls
- Designing and standardizing claims and attributes strategies for integrations across multiple identity providers
- Defining API access models and permission strategies, including scopes vs roles, delegated vs application permissions, and consent governance
- Configuring and operating federation integrations (IdP/SP), metadata management, rollover planning, and troubleshooting SSO issues
- Designing and implementing risk-based access controls and step-up authentication using Conditional Access and MFA
- Delivering Microsoft Entra ID tenant configurations and operational governance improvements
- Designing external identity onboarding patterns using Entra External ID (CIAM/B2B/B2C)
- Building, tuning, and rolling out Conditional Access and Identity Protection policies
- Implementing and operating Entra ID Governance capabilities, including entitlement management, access reviews, lifecycle workflows, and access packages
- Supporting application onboarding and integration using Enterprise Apps, App Registrations, service principals, and managed identities
- Supporting hybrid identity dependencies involving AD DS and AD FS, including modernization toward cloud-native identity solutions
- Developing and maintaining PowerShell automation for identity operations, reporting, bulk changes, and governance
- Participating in SailPoint IdentityIQ / IdentityNow governance delivery and aligning with Microsoft identity patterns
- Implementing IGA processes end-to-end, including JML, access requests, approvals, certifications, reviews, SoD, and entitlement modeling
- Designing and improving provisioning and lifecycle integrations using SCIM, reconciliation, authoritative sources, and JIT provisioning
- Embedding GDPR/EUDPR privacy-by-design principles into IAM delivery and extending governance to AI/agent access where applicable
Benefity
- Private medical care including dental (covering 70% of costs) with family package option
- Multisport card for employee and accompanying person
- Life insurance
- Work on large-scale, technically challenging projects with talented engineers
Opieka zdrowotna
Karta sportowa
Ubezpieczenie
Cyclad
321 aktywnych ofert