Microsoft Entra ID & Active Directory Engineer
Job Summary
Microsoft Entra ID (Advanced Implementation)
- Implement and optimize Conditional Access policies based on approved designs
- Support and operationalize:
- Riskbased access policies
- Authentication Strengths and phishingresistant MFA
- Lead operational implementation of Privileged Identity Management (PIM):
- Role assignments
- Approval workflows
- JustinTime access configuration
- Secure application and workload identities:
- App registrations and service principals
- OAuth permission governance
OnPrem Active Directory (Security & Hardening)
- Support and enforce AD security best practices:
- Tiered admin model (Tier 0 / 1 / 2)
- Privileged account separation
- Lead AD hardening activities:
- LAPS
- Protected Users
- Delegation and admin access restrictions
- Troubleshoot complex AD security and authentication issues
Hybrid Identity & Integration
- Support Entra Connect configuration and lifecycle management
- Assist in evaluating authentication models and hybrid trust decisions
- Support integration of identity with:
- Azure subscriptions
- Thirdparty SaaS applications
Threat Detection & Operations
- Support CyberDefence team for Identity (MDI) investigations and tuning
- Act as a technical escalation point during identityrelated incidents
Collaboration & Mentoring
- Mentor midlevel engineers and provide technical guidance
- Participate in design reviews and provide implementation feedback
- Work closely with Identity Architects Security and Platform teams
Qualifications :
- 810 years of experience in identity and access management
- Strong handson experience with:
- Microsoft Entra ID P2
- Conditional Access at scale
- Privileged Identity Management
- Active Directory security
- Experience supporting hybrid AD environments
- Advanced PowerShell scripting and automation
- Strong understanding of identitybased attack techniques and mitigations
- Solid grasp of Zero Trust principles (implementationfocused)
Additional Information :
- Experience with:
- Concepts around IGA
- Defender for Identity
- Passwordless authentication (FIDO2 WHfB)
- VDI or shared device environments
- Certifications:
- SC300
- AZ500
- Microsoft Security certifications
Remote Work :
No
Employment Type :
Full-time
About Company
METRO is a leading international wholesale company with food and non-food assortments that specialises in serving the needs of hotels, restaurants and caterers (HoReCa) as well as independent traders. Around the world, METRO has 15 million customers who can choose whether to shop in o ... View more