Identity Engineer
DescriptionHybrid Remote, onsite for design sessions and cutover. in Dallas, TXYou will define and implement a hybrid identity and authentication architecture across Entra ID and on-premises Active Directory, rebuild the administrative model to least privilege, get conditional access enforced in production, and automate joiner, mover and leaver provisioning through Entra ID Governance integrated with Dayforce. Administrative runbooks and identity governance documentation do not exist in this environment today, so you author them. You are one of three identity engineers working the same architecture, so the design settles early and then holds. Someone who wants to redesign in week six breaks two other people's work.We can facilitate w2 and corp-to-corp consultants. For our w2 consultants, we offer a great benefits package that includes Medical, Dental, and Vision benefits, 401k with company matching, and life insurance.Rate: $90.00 to $100.00/hr. w2JN -092026-108523ResponsibilitiesDefine and implement the target hybrid identity architecture across Entra ID and on-premises Active Directory, and cut authentication over to it.Rebuild the administrative access model to least-privilege principles as validated during discovery. Privileged access is not structured this way today.Review and document the application authentication inventory, and get every application onto a sanctioned authentication path.Design, deploy and enforce the conditional access policy set in production, including break-glass.Integrate Entra ID Governance with Dayforce so joiner, mover and leaver provisioning and deprovisioning run automatically, tested and cut over.Author the administrative runbooks and identity governance documentation.Stand up a quarterly identity test cadence with executive sign-off and a standing access review cadence, configure both in the supporting tooling, and hand each to a named client owner.Experience RequirementsDeep hybrid identity: Entra ID and on-premises Active Directory together, Entra Connect, authentication methods, and the failure modes of a hybrid cutover.Has designed and enforced a conditional access policy set in a production tenant, including the part where somebody gets locked out.Has built a tiered or least-privilege administrative model, or rebuilt privileged access along those lines in a live estate.Entra ID Governance for identity governance and automated lifecycle provisioning, integrated with an HR system as the source of truth.Can work at pace alongside two other engineers in the same role without duplicating or contradicting them.Education Requirements