IAM Consultant (PKI and Entra ID) - HYBRID - Brooklyn
Brooklyn, NY
OPEN JOB: IAM Consultant (PKI and Entra ID) LOCATION: HYBRID - Onsite at 2 Metrotech Center (Brooklyn) & Remote (2 days in office/3 days remote) WORK HOURS: 35 hour billable week (8 hour days with 1 hour unpaid lunch) DURATION: 1 year SCOPE OF SERVICES:
Assess and develop a roadmap for OTI’s disparate directories consolidation
Provide guidance and implementation support for integration with Entra and other IAM
security enhancements
Architect and implement Citywide-level PKI modernization, including infrastructure
changes for reduced certificate lifespans
Advice on governance, compliance, lifecycle management and automation of digital
certificates
Lead migration planning, risk assessment, and mitigation for directories and PKI
modernization
Perform technical knowledge transfer, upskilling internal teams on new infrastructure
and practices
TASKS:
PKI Architecture, Engineering and Administrator – 40%
Entra ID Architecture, Engineering and Administrator – 30%
Directory Architecture, Engineering and Administrator – 20%
IAM Level 3 Technical Support – 10%
MANDATORY SKILLS/EXPERIENCE:
12 years in IAM architect, engineering, administration and operations with focus on
directory services and PKI
Deep expertise in Active Directory (on-prem and hybrid), Entra ID, and eDirectory
Hands-on experience in designing and operating Microsoft PKI, including certificate
authority management, certificate lifecycle, and automation
Solid understanding of modern authentication/authorization protocols (OAuth, SAML,
Kerberos, etc.)
Experience with security roadmap development, risk assessment, and compliance
(NIST, ISO, SOX or PCI-DSS)
Strong documentation, communication, and stakeholder management skills
DESIRABLE SKILLS/EXPERIENCE:
Experience with cloud PKI services
Familiarity with Entra ID Governance, Conditional Access Policy, and modern security
controls