- Company Name
- Datum Technologies Group
- Job Title
- IAM Consultant _ Remote (Passwordless & WHfB)
- Job Description
-
**Job title**
IAM Consultant – Passwordless & Windows Hello for Business
**Role Summary**
Design, implement, and manage modern authentication solutions across an enterprise. Focus on assessing current identity posture, architecting Windows Hello for Business (WHfB) trust models, integrating with Microsoft Entra ID, Intune, and other services, and leading large‑scale rollout and operational readiness.
**Expectations**
- Lead end‑to‑end implementation of passwordless & WHfB strategies.
- Ensure security, compliance, and optimal user experience.
- Provide clear documentation, technical leadership, and cross‑team enablement.
**Key Responsibilities**
1. **Assessment & Design**
- Evaluate current identity and authentication posture (password policies, MFA, PKI, hybrid join, device management).
- Recommend WHfB trust models (Cloud Kerberos, Hybrid Key, Hybrid Certificate) and define migration paths.
- Design integrations with Microsoft Entra ID, Active Directory, Intune, Conditional Access, Identity Protection, and Defender for Endpoint.
- Define device provisioning, compliance, and backup/recovery strategies.
2. **Implementation & Rollout**
- Configure WHfB policies via Intune/GPO, authentication methods, and Conditional Access.
- Deploy PKI components, certificate templates, CRLs/AIA, and support smart card migration or ADFS deprecation.
- Run pilots, evaluate results, and manage phased rollouts across regions and device types.
- Validate SSO/Kerberos flows to on‑prem resources and monitor through Entra logs, Intune reporting, and Log Analytics.
3. **Operations & Troubleshooting**
- Build runbooks, break‑glass procedures, and tiered support workflows.
- Diagnose WHfB issues (TPM/attestation, PIN reset, dsregcmd, trust model anomalies).
- Optimize authentication performance, fallback MFA posture, and user experience.
4. **Security & Compliance**
- Align solutions with NIST 800‑63/800‑53, ISO 27001, and phishing‑resistant authentication best practices.
- Ensure IAM policies meet governance, audit, and risk‑mitigation requirements.
5. **Documentation & Enablement**
- Produce HLD/LLD documentation, migration plans, test/UAT guides, and support FAQs.
- Deliver training and communication materials for admins, helpdesk teams, and end users.
**Required Skills**
- Expertise in Microsoft Entra ID (Azure AD), Intune, Conditional Access, and Identity Protection.
- Strong knowledge of Windows Hello for Business architecture and deployment.
- Experience with PKI, certificate templates, CRLs, AIA, and smart card integration.
- Proficiency in device provisioning (Autopilot, VDI, TPM, HSTI), and security tooling (Defender for Endpoint).
- Skilled in troubleshooting TPM, WSH, dsregcmd, and Kerberos flows.
- Familiarity with NIST, ISO 27001, and modern authentication best practices.
- Ability to produce high‑level and low‑level technical documentation.
- Excellent communication, training, and cross‑team collaboration skills.
**Required Education & Certifications**
- Bachelor’s degree in Computer Science, Information Security, or related field.
- Relevant Microsoft certifications preferred (e.g., MS-100, MS-101, AZ-900, AZ-881).
- Certifications in PKI/Identity (e.g., Microsoft 365 Identity Administrator, Azure Security Engineer Associate) are advantageous.
Alpharetta, United states
On site
10-02-2026