Cloud Security, IAM Architect
Posted 4hrs ago
Employment Information
Report this job
Job expired or something wrong with this job?
Job Description
Microsoft Cloud Security/IAM Architect securing Dataverse and Dynamics environments for federal IT infrastructure. Designing identity controls, sensitive-data protections, auditing, monitoring, and incident-response documentation.
Responsibilities:
- Design and support Microsoft cloud security and IAM controls beyond default Dynamics security
- Implement and manage Conditional Access, Privileged Identity Management, least privilege, MFA, and authentication controls
- Configure and document Dataverse/Dynamics security, including roles, business units, teams, record ownership/sharing, table privileges, column/field security, audit controls, and restricted record access
- Protect sensitive, whistleblower, confidential investigative, and regulated data
- Design administrative and emergency access
- Implement privileged-action logging, audit logging, monitoring, and security testing/validation
- Develop incident-response playbooks and documentation
- Integrate Microsoft Purview/DLP, Sentinel, or equivalent SIEM capabilities
- Support regulated federal IT infrastructure and cybersecurity operations
Requirements:
- 7+ years of cybersecurity/IAM/cloud security experience
- 3+ years of Microsoft cloud identity/security experience
- Experience with Microsoft Entra ID
- Experience with Conditional Access
- Experience with Privileged Identity Management
- Knowledge of RBAC and least privilege
- Knowledge of MFA and authentication controls
- Dataverse/Dynamics security knowledge
- Sensitive-data protection experience
- Security logging and audit experience
- Security testing/validation experience
- Incident-response playbook experience
- Experience designing administrative/emergency access
- Experience documenting security control configurations for regulated systems
- Understanding of Dataverse security roles, business units, teams, record ownership/sharing, table privileges, column/field security, audit, restricted record access, and interaction between Dataverse controls and Power Platform solutions
- Preferred certifications/qualifications include one or more of: CISSP, SC-100 Cybersecurity Architect, AZ-500 Azure Security Engineer, SC-300 Identity and Access Administrator, or Microsoft Power Platform security experience/certification
- Strong differentiators include government Inspector General/security experience; whistleblower/confidential investigative records experience; experience with CJIS, healthcare, financial, legal, regulatory, or similarly restricted datasets; and Microsoft Purview/DLP or Sentinel/equivalent SIEM integration
Benefits:
- Competitive Employee Health Insurance options including dental
- 100% company paid vision plan
- 401K plan with generous company match and no vesting period
- 100% company paid life insurance
- 100% company paid long and short-term disability insurance
- Training allowance
- PTO


















