{"schemaVersion":"jobsearcher.job.v1","id":"8a7040e2362f5488df10f4b7","url":"https://jobsearcher.com/jobs/8a7040e2362f5488df10f4b7","canonicalUrl":"https://jobsearcher.com/jobs/8a7040e2362f5488df10f4b7","title":"Cloud Engineer","description":"Cloud EngineerAbout Tryfacta: Tryfacta is a leading, nationally renowned Workforce Management Solution provider for private & public sector firms across the US. We specialize in Healthcare, IT, Business Support, and Professional & Craft/Light Industrial ecosystems. Founded in March 1996, we have a presence in all 50 States. Tryfacta has Ranked number 1 as one of the fastest-growing companies by Inc. Magazine (Inc. 5000)! Tryfacta is certified by the Joint Commission for Healthcare Staffing Services & has numerous ISO Certifications that capture our commitment to continuous improvement.Job Summary: Tryfacta is seeking a Cloud Engineer for our client in San Francisco, CA 94102. This is a temporary contract assignment.Position Title: Cloud EngineerLocation: San Francisco, CA 94102Duration of Assignment: 10/01/2026 – 09/30/2027Responsibilities for this position include, but are not limited to:Design and document scalable Azure Entra ID tenant topologies, including multi-organization frameworks and external B2B/B2C collaboration structures.Establish and enforce enterprise-wide identity standards, architecture guardrails, and naming conventions across all business units and branches.Architect and manage secure deployment matrices for workload identities, including Service Principals, Managed Identities, and application registrations.Configure and deploy a comprehensive Conditional Access policy suite tailored to role-based risks and user sign-in risk levels.Implement and scale passwordless authentication mechanisms across the enterprise, including FIDO2 security keys, Passkeys, and Windows Hello for Business.Deploy and tune Identity Protection policies to enable automated risk-based authentication and real-time remediation of compromised accounts.Build and automate end-to-end Joiner, Mover, and Leaver (JML) user lifecycle workflows utilizing Microsoft Graph API, PowerShell, and Azure Functions.Engineer self-service entitlement management catalogs and automate compliance-driven access reviews using Azure Logic Apps.Integrate and onboard SaaS, on-premises, and custom-developed applications (.NET/C#) using standard OAuth 2.0, OpenID Connect, and SAML 2.0 protocols.Write and maintain clean, reusable script libraries using PowerShell, Azure CLI, and Microsoft Graph SDKs to automate repetitive identity workflows.Align and map Entra ID technical controls to regulatory frameworks, including NIST, FedRAMP, SOC 2, and ISO 27001.Translate complex business and compliance requirements into comprehensive Technical Design Documents (TDD).To be considered for this position, you should have:Strong experience with Microsoft Entra ID / Azure AD architecture and administration.Proficiency in PowerShell scripting, Microsoft Graph API, and REST APIs.Knowledge of OAuth 2.0, OpenID Connect, SAML, and SCIM protocols.Experience with Conditional Access, MFA, and Identity Governance.Familiarity with Azure AD Connect, Hybrid Identity, and Single Sign-On (SSO).Understanding of Zero Trust principles and modern authentication methods.Additional Skills/Qualifications Desired:Microsoft certifications such as SC-300 (Identity and Access Administrator) or AZ-104 (Azure Administrator).Experience with Azure Functions, Logic Apps, or Power Automate for workflow automation.Background in security compliance frameworks (e.g., ISO 27001, NIST).Translate business requirements into secure identity solutions.Communicate complex identity concepts to non-technical stakeholders.Drive identity modernization initiatives.Ability to partner with cloud solution architects, DBAs, DevOps, and infrastructure admins.Azure AD B2C / External Identities (CIAM).Cross-cloud identity (AWS, GCP federation).Identity-related incident response.Strong problem-solving and analytical skills.Excellent communication and collaboration abilities.Ability to work in a fast-paced, dynamic environment.Certifications: Microsoft Identity and Access Administrator, Azure Solutions Architect, Security-focused certifications.Tryfacta is an Equal Opportunity/Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, protected veteran or disabled status, or genetic information.","company":"Tryfacta","rawCompany":"tryfacta","city":"Millbrae","state":"CA","isRemote":false,"isActive":false,"createdAt":"2026-09-11T13:00:29.161Z","occupations":[{"code":"15-1299.08","title":"Computer Systems Engineers/Architects","slug":"computer-systems-engineers-architects"},{"code":"15-1211.00","title":"Computer Systems Analysts","slug":"computer-systems-analysts"},{"code":"15-1244.00","title":"Network and Computer Systems Administrators","slug":"network-and-computer-systems-administrators"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"541511","title":"Custom Computer Programming Services","slug":"custom-computer-programming-services"},{"code":"513210","title":"Software Publishers","slug":"software-publishers"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Cloud Engineer","description":"Cloud EngineerAbout Tryfacta: Tryfacta is a leading, nationally renowned Workforce Management Solution provider for private & public sector firms across the US. We specialize in Healthcare, IT, Business Support, and Professional & Craft/Light Industrial ecosystems. Founded in March 1996, we have a presence in all 50 States. Tryfacta has Ranked number 1 as one of the fastest-growing companies by Inc. Magazine (Inc. 5000)! Tryfacta is certified by the Joint Commission for Healthcare Staffing Services & has numerous ISO Certifications that capture our commitment to continuous improvement.Job Summary: Tryfacta is seeking a Cloud Engineer for our client in San Francisco, CA 94102. This is a temporary contract assignment.Position Title: Cloud EngineerLocation: San Francisco, CA 94102Duration of Assignment: 10/01/2026 – 09/30/2027Responsibilities for this position include, but are not limited to:Design and document scalable Azure Entra ID tenant topologies, including multi-organization frameworks and external B2B/B2C collaboration structures.Establish and enforce enterprise-wide identity standards, architecture guardrails, and naming conventions across all business units and branches.Architect and manage secure deployment matrices for workload identities, including Service Principals, Managed Identities, and application registrations.Configure and deploy a comprehensive Conditional Access policy suite tailored to role-based risks and user sign-in risk levels.Implement and scale passwordless authentication mechanisms across the enterprise, including FIDO2 security keys, Passkeys, and Windows Hello for Business.Deploy and tune Identity Protection policies to enable automated risk-based authentication and real-time remediation of compromised accounts.Build and automate end-to-end Joiner, Mover, and Leaver (JML) user lifecycle workflows utilizing Microsoft Graph API, PowerShell, and Azure Functions.Engineer self-service entitlement management catalogs and automate compliance-driven access reviews using Azure Logic Apps.Integrate and onboard SaaS, on-premises, and custom-developed applications (.NET/C#) using standard OAuth 2.0, OpenID Connect, and SAML 2.0 protocols.Write and maintain clean, reusable script libraries using PowerShell, Azure CLI, and Microsoft Graph SDKs to automate repetitive identity workflows.Align and map Entra ID technical controls to regulatory frameworks, including NIST, FedRAMP, SOC 2, and ISO 27001.Translate complex business and compliance requirements into comprehensive Technical Design Documents (TDD).To be considered for this position, you should have:Strong experience with Microsoft Entra ID / Azure AD architecture and administration.Proficiency in PowerShell scripting, Microsoft Graph API, and REST APIs.Knowledge of OAuth 2.0, OpenID Connect, SAML, and SCIM protocols.Experience with Conditional Access, MFA, and Identity Governance.Familiarity with Azure AD Connect, Hybrid Identity, and Single Sign-On (SSO).Understanding of Zero Trust principles and modern authentication methods.Additional Skills/Qualifications Desired:Microsoft certifications such as SC-300 (Identity and Access Administrator) or AZ-104 (Azure Administrator).Experience with Azure Functions, Logic Apps, or Power Automate for workflow automation.Background in security compliance frameworks (e.g., ISO 27001, NIST).Translate business requirements into secure identity solutions.Communicate complex identity concepts to non-technical stakeholders.Drive identity modernization initiatives.Ability to partner with cloud solution architects, DBAs, DevOps, and infrastructure admins.Azure AD B2C / External Identities (CIAM).Cross-cloud identity (AWS, GCP federation).Identity-related incident response.Strong problem-solving and analytical skills.Excellent communication and collaboration abilities.Ability to work in a fast-paced, dynamic environment.Certifications: Microsoft Identity and Access Administrator, Azure Solutions Architect, Security-focused certifications.Tryfacta is an Equal Opportunity/Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, protected veteran or disabled status, or genetic information.","datePosted":"2026-09-11T13:00:29.161Z","dateModified":"2026-09-11T13:00:29.161Z","hiringOrganization":{"@type":"Organization","name":"Tryfacta","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Millbrae","addressRegion":"CA","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"8a7040e2362f5488df10f4b7"},"url":"https://jobsearcher.com/jobs/8a7040e2362f5488df10f4b7"}}