Own the EXOS identity security standard: the Conditional Access baseline, tiered admin model, privileged access configuration, and phishing-resistant MFA standard that every client inherits.
Enforce MFA on all client remote access, both VPN and internal application access, and block legacy authentication.
Build and run privileged access management: just-in-time admin elevation, separated cloud-only admin accounts, and on-prem tiered administration with LAPS.
Deploy phishing-resistant MFA (FIDO2, passkeys, Windows Hello for Business), starting with privileged accounts and expanding to users.
Stand up scheduled access reviews and stale or over-privileged account reporting, delivered as a recurring remediation list.
Operate identity threat detection and response tooling to catch token theft, impossible travel, and MFA fatigue, and tune it across client tenants.
Automate it with reusable templates and scripting (Microsoft Graph API, PowerShell) so the work scales across our client base.
Produce a per-client identity posture report, and build the runbooks that let the broader team execute the standard.
Qualifications
Worked hands-on in production with Microsoft Entra ID: Conditional Access, Privileged Identity Management, Identity Protection, and access reviews.
Automated identity work at scale with Microsoft Graph API and PowerShell, building reusable multi-tenant tooling.
Deployed phishing-resistant MFA (FIDO2, passkeys, Windows Hello for Business) in real environments.
Hardened on-prem Active Directory: tiered admin models, LAPS, and the hybrid identity attack paths that enable lateral movement.
Worked with identity threat detection and response tooling.
Delivered identity across many client environments in an MSP or MSSP setting (preferred).
Familiar with CIS Benchmarks and the compliance regimes our clients face
Earned relevant certifications such as SC-300, Identity and Access Administrator (a plus, not a substitute for hands-on experience).