Cloud Security, IAM Architect

Posted 4hrs ago

Employment Information

Education
Salary
Experience
Job Type

Report this job

Job expired or something wrong with this job?

Job Description

Microsoft Cloud Security/IAM Architect securing Dataverse and Dynamics environments for federal IT infrastructure. Designing identity controls, sensitive-data protections, auditing, monitoring, and incident-response documentation.

Responsibilities:

  • Design and support Microsoft cloud security and IAM controls beyond default Dynamics security
  • Implement and manage Conditional Access, Privileged Identity Management, least privilege, MFA, and authentication controls
  • Configure and document Dataverse/Dynamics security, including roles, business units, teams, record ownership/sharing, table privileges, column/field security, audit controls, and restricted record access
  • Protect sensitive, whistleblower, confidential investigative, and regulated data
  • Design administrative and emergency access
  • Implement privileged-action logging, audit logging, monitoring, and security testing/validation
  • Develop incident-response playbooks and documentation
  • Integrate Microsoft Purview/DLP, Sentinel, or equivalent SIEM capabilities
  • Support regulated federal IT infrastructure and cybersecurity operations

Requirements:

  • 7+ years of cybersecurity/IAM/cloud security experience
  • 3+ years of Microsoft cloud identity/security experience
  • Experience with Microsoft Entra ID
  • Experience with Conditional Access
  • Experience with Privileged Identity Management
  • Knowledge of RBAC and least privilege
  • Knowledge of MFA and authentication controls
  • Dataverse/Dynamics security knowledge
  • Sensitive-data protection experience
  • Security logging and audit experience
  • Security testing/validation experience
  • Incident-response playbook experience
  • Experience designing administrative/emergency access
  • Experience documenting security control configurations for regulated systems
  • Understanding of Dataverse security roles, business units, teams, record ownership/sharing, table privileges, column/field security, audit, restricted record access, and interaction between Dataverse controls and Power Platform solutions
  • Preferred certifications/qualifications include one or more of: CISSP, SC-100 Cybersecurity Architect, AZ-500 Azure Security Engineer, SC-300 Identity and Access Administrator, or Microsoft Power Platform security experience/certification
  • Strong differentiators include government Inspector General/security experience; whistleblower/confidential investigative records experience; experience with CJIS, healthcare, financial, legal, regulatory, or similarly restricted datasets; and Microsoft Purview/DLP or Sentinel/equivalent SIEM integration

Benefits:

  • Competitive Employee Health Insurance options including dental
  • 100% company paid vision plan
  • 401K plan with generous company match and no vesting period
  • 100% company paid life insurance
  • 100% company paid long and short-term disability insurance
  • Training allowance
  • PTO