RemoteFull Time

Salary

$55 - $59 / hr

Location

Canada

Posted

Aug 21, 2026

Role overview

Title: Senior IAM Engineer/Architect

Location: Halifax, CA (Remote)

Type: Contract

Description:

  • Strong hands-on experience with Microsoft Entra ID, Azure AD B2C and Entra External ID.
  • Expert-level knowledge of OAuth 2.0, OIDC, SAML 2.0, JWT, access tokens, ID tokens and OAuth grant types.
  • Hands-on experience with Entra App Registrations, Enterprise Applications, Service Principals, API permissions and admin consent.
  • Strong implementation experience with Azure AD B2C Custom Policies, including Technical Profiles, Claims, Claims Transformations and Orchestration Steps.
  • Experience designing customer and employee authentication journeys, including MFA and Conditional Access.
  • Hands-on experience integrating REST APIs with Azure AD B2C Custom Policies.
  • Strong experience implementing and troubleshooting Azure Application Proxy and Application Proxy Connectors.
  • Experience with HTTP Header-based SSO and legacy application onboarding/migration.
  • Strong troubleshooting skills across authentication, federation, tokens, claims, SAML assertions and OAuth/OIDC flows.
  • Hands-on experience with Application Insights, KQL and Workbooks for analysing and debugging B2C authentication flows.
  • Experience troubleshooting Conditional Access, MFA, consent, token validation and application authentication issues.
  • Strong understanding of authentication vs authorization, delegated permissions, application permissions, scopes and application roles.
  • Experience supporting enterprise IAM applications in production environments, including incident and root-cause analysis.
  • Working knowledge of.NET/C#, ASP.NET Core, MSAL and Microsoft Graph API is preferred. And having automation experience in PowerShell or Python will be added advantages.
  • Candidates should have strong enterprise IAM architecture, implementation and production troubleshooting experience rather than portal administration-only experience.
  • 12+ years of IAM experience preferred, with significant hands-on experience in Entra ID and Azure AD B2C for senior/architect-level positions.

Day-to-Day Job Duties

  • Design, implement, and manage identity and access management (IAM) solutions using Microsoft Entra ID and Azure AD B2C.
  • Configure and maintain authentication and authorization protocols including OAuth 2.0, OpenID Connect (OIDC), and SAML 2.0.
  • Develop and manage access control mechanisms, including access tokens, API permissions, and OAuth grant types.
  • Implement and manage Azure Application Proxy connectors and HTTP header-based Single Sign-On (SSO) solutions.
  • Onboard enterprise applications into Azure AD and configure secure authentication and authorization flows.
  • Design and enforce Conditional Access policies aligned with security and compliance standards.
  • Troubleshoot authentication, token, and federation-related issues across enterprise and customer-facing applications.
  • Develop and maintain Azure AD B2C custom policies, including claims transformations and user journey orchestration.
  • Implement Multi-Factor Authentication (MFA) for customer-facing applications.
  • Integrate external systems using REST APIs within Azure AD B2C frameworks.
  • Monitor and diagnose authentication flows using Application Insights, Kusto Query Language (KQL), and workbooks.
  • Debug and optimize B2C authentication flows to improve performance and reliability.
  • Collaborate with application teams, security teams, and stakeholders to ensure secure IAM implementations.
  • Provide production support, including incident management, root cause analysis, and issue resolution.

Basic Qualifications:

  • (Required skills with minimum years of experience)
  • 5+ years of experience in Identity and Access Management (IAM) engineering or architecture.
  • 5+ years of hands-on experience with Microsoft Entra ID (Azure AD) and Azure AD B2C.
  • Strong expertise in authentication and authorization protocols:
  • OAuth 2.0 (3+ years)
  • OpenID Connect (OIDC) (3+ years)
  • SAML 2.0 (3+ years)
  • 3+ years of experience working with access tokens, API permissions, and OAuth grant types.

Proven experience with:

  • Azure AD enterprise application onboarding (2+ years)
  • Conditional Access policy design and implementation (2+ years)
  • Azure Application Proxy and SSO configurations (2+ years)
  • 3+ years of hands-on troubleshooting experience in authentication, token, and federation issues.
  • Strong experience with Azure AD B2C:
  • Custom policies and user journeys (3+ years)
  • Claims transformations and REST API integrations (2+ years)
  • Experience with monitoring and diagnostics tools:
  • Application Insights (2+ years)
  • KQL and Azure Workbooks (2+ years)
  • Solid understanding of MFA implementation and identity security best practices.
  • Nice to Have
  • Programming experience in.NET / C#.
  • Experience providing production support in IAM environments.
  • Familiarity with CI/CD pipelines and DevOps practices for IAM deployments.
  • Experience with identity governance, risk-based authentication, or zero trust frameworks.
  • Certifications such as:
  • Microsoft Certified: Identity and Access Administrator Associate
  • Microsoft Certified: Azure Solutions Architect Expert