Logo for GuidePoint Security

Senior Microsoft Security Entra Engineer- Remote (Anywhere in the U.S.)

Role overview

Qualifications

  • Bachelor’s Degree and 3–5+ years of hands-on experience in Microsoft Entra ID
  • Deep working knowledge of Conditional Access, MFA/passwordless, PIM, RBAC, access reviews, and entitlement management
  • Strong hands-on experience with hybrid identity: Entra Connect/Cloud Sync, and on-premises Active Directory
  • Experience integrating or migrating identity with other IdPs (Okta, Ping, ADFS)

Responsibilities

  • Design and implement end-to-end Entra ID environments
  • Design and implement Conditional Access, MFA/passwordless, PIM, RBAC, access reviews, and entitlement management
  • Own hybrid identity design and troubleshooting
  • Investigate and remediate identity risks using Entra ID Protection

Key facts

Other skills

  • Troubleshooting (Problem Solving)
  • Communication
  • Detail Oriented
  • Problem Solving

About the company

GuidePoint Security logo

GuidePoint Security

Cybersecurity

GuidePoint Security is an elite team of highly trained, top certified experts who cut through cyber chaos and confusion to put control back in your hands. We help you make the smartest, most informed decisions, choose and integrate products and services that are the best fit, and build the most effective cybersecurity posture. We provide organizations with holistic perspective on their cyber ecosystem to minimize gaps, vulnerabilities, and optimize resources, including: 1. Understanding the changing threat landscape, vulnerabilities, and gaps 2. New insights of how product decisions align with resource capacity 3. Insightful product comparisons and integration to save time, money, and mistakes

Company details

Company typeSME
IndustryCybersecurity
Company size1001 - 5000

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

GuidePoint Security provides trusted cybersecurity expertise, solutions and services that help organizations make better decisions and minimize risk. By taking a three-tiered, holistic approach for evaluating security posture and ecosystems, GuidePoint enables some of the nation’s top organizations, such as Fortune 500 companies and U.S. government agencies, to identify threats, optimize resources and integrate best-fit solutions that mitigate risk.

General Description

GuidePoint Security is seeking a Senior Entra Engineer to join our Microsoft Cloud Security Team. This role is a deep identity specialization, you'll bring strong, hands-on Microsoft Entra ID expertise across our client engagements, ranging from small businesses to large enterprises. You'll design, implement, and troubleshoot complex Entra environments, including how Entra integrates with other identity providers and with on-premises Active Directory in hybrid scenarios. You'll partner with principal consultants, owning the identity workstream on an engagement, across varied industries and environments.

You'll own your technical delivery independently (80% utilization target), managing your time and communication within assigned engagements, and contribute to internal practice and knowledge-sharing efforts between projects.

Roles and Responsibilities:  

  • Entra ID Architecture: Design and implement end-to-end Entra ID environments, including tenant architecture, dynamic groups, administrative units, and identity lifecycle management at scale.
  • Access Control & Governance: Design and implement Conditional Access (including advanced scenarios like Global Secure Access, token protection, and authentication strengths), MFA/passwordless, PIM, RBAC, access reviews, and entitlement management.
  • Hybrid Identity: Own hybrid identity design and troubleshooting, including Entra Connect / Cloud Sync, Entra Connect Health, password Hash Sync vs. pass-through auth vs. federation (ADFS), and Entra Domain Services.
  • Identity Federation & Integration: Design and support identity federation and integration between Entra ID and other identity providers (Okta, Ping Identity, ADFS, third-party SAML/OIDC IdPs), including migration scenarios moving customers onto Entra.
  • Application Integration: Integrate applications via SSO (SAML/OIDC), enterprise app registrations, SCIM provisioning, and application proxy/Global Secure Access for on-prem app publishing. Advanced understanding of SAML and OIDC tokens, custom claims, and troubleshooting SAML and OIDC-based authentication.
  • External Identities: Design and implement Entra External ID (B2B/B2C) for partner and customer-facing identity scenarios.
  • Workload Identities: Design and implement identity solutions for Workload Identities such as Managed Identities and Workload Identity Federation.
  • Risk & Investigation: Investigate and remediate identity risks using Entra ID Protection, sign-in and audit logs, and Entra recommendations; drive hybrid identity hygiene (stale object cleanup, privileged account reduction, tiered admin models).
  • Adjacent Microsoft Security: Maintain deep knowledge of how Entra ID intersects with Azure, Microsoft Purview, Intune, and Defender XDR, and support those workstreams as engagements require.
  • Other duties as assigned.
  • Adhere to GuidePoint Security Core Values.

Required Education and Experience: 

  • Bachelor’s Degree and 3–5+ years of hands-on, production experience specifically in Microsoft Entra ID, in addition to broader IT administration, identity management, or security operations experience.
  • Deep working knowledge of Conditional Access, MFA/passwordless, PIM, RBAC, access reviews, and entitlement management.
  • Strong hands-on experience with hybrid identity: Entra Connect/Cloud Sync, on-premises Active Directory, and the tradeoffs between password hash sync, pass-through authentication, and federation.
  • Knowledge of core authentication and provisioning protocols: SAML, OAuth 2.0/OIDC, Kerberos, LDAP, and SCIM.
  • Experience integrating or migrating identity with other IdPs (Okta, Ping, ADFS, or similar) alongside or into Entra ID.
  • Comfortable troubleshooting complex, real-world identity issues independently, including sign-in failures, sync errors, and token/claims issues.
  • Basic to intermediate PowerShell scripting for automation and reporting (e.g., Microsoft Graph PowerShell).
  • Experience embracing emerging technologies, including AI tools, to work smarter, solve problems, and drive better business outcomes
  • Strong troubleshooting skills, attention to detail, and clear written and verbal communication; this role frequently leads to client-facing identity conversations.

Preferred Experience:

  • Entra External ID (B2B/B2C) design and implementation.
  • Advanced on-premises AD work: multi-domain/forest design, migrations, tiered administration, legacy auth cleanup.
  • Microsoft Purview (sensitivity labels, DLP, retention, or eDiscovery), Intune, or Defender XDR experience.
  • Microsoft Sentinel or broader SIEM/SOAR experience.
  • Relevant certifications such as SC-300 (Identity and Access Administrator), SC-500, MS-102
  • Azure infrastructure and security (Azure Policy, network security, landing zones, RBAC).

Travel Requirements:

  • Typical travel is limited to company events and should be less than 5%

Physical Requirements:

  • Sedentary work
  • Substantial movement of the wrists, hands, and/or fingers for a minimum of 8 hours a day
  • Required to have close visual acuity to view computer terminal and/or extensive reading for a minimum of 8 hours a day

We use Greenhouse Software as our applicant tracking system and Zoom Scheduler for HR screen request scheduling. At times, your email may block our communication with you. Please be sure to check your SPAM folder so that you don't miss updates on your application.


Why GuidePoint?

GuidePoint Security is a rapidly growing, profitable, privately-held value added reseller that focuses exclusively on Information Security. Since its inception in 2011, GuidePoint has grown to over 1,300 employees, established strategic partnerships with leading security vendors, and serves as a trusted advisor to more than 6,200 customers.

Firmly-defined core values drive all aspects of the business, which have been paramount to the company’s success and establishment of an enjoyable workplace atmosphere. At GuidePoint, your colleagues are knowledgeable, skilled, and experienced and will seek to collaborate and provide mentorship and guidance at every opportunity.  

This is a unique and rare opportunity to grow your career along with one of the fastest growing companies in the nation.

Some added perks….

  • Remote workforce primarily (U.S. based only, some travel may be required for certain positions, working on-site may be required for Federal positions)
  • Group Medical Insurance options: Zero Deductible PPO Plan (GuidePoint pays 90% of the premium for employees and 70% for family plans (spouse/children/family) or High Deductible Health Plan with HSA (GuidePoint pays 100% of the employees premiums and 75% for family plans (spouse/children/family). If you choose the High Deductible / HSA plan, GPS will contribute in 4 equal quarterly installments: ($850 per EE annually / $1750 per family annually (includes spouse/children/family options)
  • Group Dental Insurance: GuidePoint pays 100% of the premium for employees and 75% of family plans
  • 12 corporate holidays and a Flexible Time Off (FTO) program
  • Healthy mobile phone and home internet allowance
  • Eligibility for retirement plan after 2 months at open enrollment
  • Pet Benefit Option

 

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

Security Engineer Related jobs

Other jobs at GuidePoint Security

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.