Live opening · Posted 11 days ago

IAM / Microsoft Entra ID Engineer – Workday Integration

NexQloud · United States (Remote)
Linkedin No
You are 11 days behind. JobBeeper subscribers saw this role while it was still new.

At a glance

The key details from the original listing.

Posted 11 days ago
CompanyNexQloud
LocationUnited States (Remote)
Work modeNo
SourceLinkedin
Listed11 days ago

Your early-applicant advantage

Live timing from JobBeeper.

Live data
7 min from Linkedin publishing this role to us finding it
7 min median time from a role going live to a subscriber being told
6 hours subscribers had this role before this page existed
71,654 roles found in the last 24 hours — the newest are not on this site yet
Start your free trial →

About the role

Description supplied by the original job listing.

🚨 Hiring: IAM / Microsoft Entra ID Engineer – Workday Integration
Job Title: Identity & Access Management (IAM) / Microsoft Entra ID Engineer – Workday Integration
Location: Remote – US
Candidate Requirement: Must be a US Citizen
Employment Type: Contract, project-based — tied to a Fall 2026 milestone (Salesforce permissions go-live)
About the Role:
We are looking for an experienced IAM / Microsoft Entra ID Engineer to improve how employee organization data flows from Workday into Entra ID and drives access. The ideal candidate will have strong hands-on experience with Entra ID and Workday, with Salesforce or other HRIS experience being a strong plus. The role focuses on redesigning how region, area, and site information is managed in Entra ID, including security groups, SSO, provisioning, and Salesforce permissions, while reviewing the existing setup, fixing current workarounds, and ensuring access continues without disruption. No Workday configuration or development is required; the engineer will use Workday as the source of employee organization data.
Project Details:
• Total hours will depend on the audit/interview. This is true consulting, so scope, hours, and duration will be decided after the interview.
• A Gold Star candidate will have Entra ID and Workday experience. Candidates with Entra ID and another HCM / HRIS system will also be considered.
Current Environment:
• The current environment uses repurposed Entra attributes such as nickname, company name, and corp, along with manually concatenated reference IDs — a 9000-series for regional directors and an 8000-series for area managers.
• This single attribute is used by SSO and Salesforce ticketing permissions, so region, area, and site information needs to flow correctly for every job function.
• The solution must support different job functions that may share the same reporting line but require different access visibility.
• Regional directors currently fall outside their own region's reference ID because they report above it.
• Support staff such as recruiters/TA, IT field specialists, and service techs may report directly to regional directors but need visibility across all sites in that region, unlike area managers who cover only a subset of sites.
Key Responsibilities:
• Own the Entra ID side end-to-end, including reviewing current attribute usage and redesigning the attribute schema so region, area, and site come through as clean, correct values.
• Solve the mixed-hierarchy problem where different job functions share the same reporting line but require different access.
• Rebuild the dependent security group rules, conditional access policies, and SSO provisioning logic based on the new attribute structure without breaking existing access.
• Rebuild or adjust the downstream Salesforce ticketing permission flow that depends on Azure attributes, coordinating with the Salesforce administrator as needed.
• Read and consume Workday data as the source of truth, including existing fields, reports, and reference IDs, and map region/area/site values correctly into Entra ID.
• Flag if a Workday-exposed value is not sufficient. Changes to Workday output are out of scope.
• Build or improve automated validation for provisioning rules. Initial testing is currently largely manual, while ongoing provisioning is already automated once rules are established.
• Document the final attribute mapping and access rules so they remain maintainable as the organization structure changes.
Required Qualifications:
• Must be a US Citizen.
• 4+ years of hands-on Microsoft Entra ID / Azure AD engineering experience.
• Strong experience with attribute-based provisioning, dynamic security groups, conditional access, and SSO configuration.
• Direct experience integrating an HRIS into Entra ID. Workday is strongly preferred; SuccessFactors or similar HRIS experience is acceptable.
• Experience mapping organizational hierarchy data such as region, territory, area, or site into identity attributes.
• Experience troubleshooting and rebuilding SSO/provisioning rules for downstream SaaS applications.
• Salesforce experience is a strong plus, especially with SSO-driven ticketing permissions.
• Experience inheriting and reverse-engineering existing IAM configurations that use workarounds such as repurposed fields and concatenated values.
• Ability to redesign the existing setup cleanly rather than continuing to patch it.
• Ability to read and work with Workday-exposed data, including reports, calculated fields, and reference IDs, without configuring Workday itself.
• Strong communication skills and ability to work directly with client IT stakeholders in short, iterative sessions and explain technical tradeoffs in plain language.
Preferred Qualifications:
• Direct experience with Workday-to-Entra ID integration.
• Experience in multi-site or field-services organizations with regional, area, and site-based permission models.
• Familiarity with Salesforce permission sets or territory management where they intersect with SSO-driven access.
Success Metrics:
• Every employee's Azure attribute correctly reflects their region and, where applicable, area/site, including regional directors and shared-hierarchy support staff.
• No manual patching is required going forward.
• SSO and Salesforce ticketing permissions route correctly using the new attributes with no access regressions during cutover.
• Provisioning validation is automated for ongoing hires and organizational changes.
Example Technical Questions:
How would you design Entra ID attributes to carry region, area, and site for a workforce where different job functions share the same reporting line but require different access?
Describe a time you inherited an identity configuration built using workarounds such as repurposed fields or manual concatenation. How did you redesign it and complete the cutover without breaking existing access?
How have you approached pulling organizational hierarchy data from an HRIS such as Workday to drive Azure AD/Entra provisioning?
How would you validate that a new attribute-driven security group rule is working correctly before fully cutting over from the existing rule?
📩 Interested candidates can share their updated resume at knetturi@thecomtek.com
#Hiring #IAM #EntraID #AzureAD #IdentityAccessManagement #MicrosoftEntra #Workday #WorkdayIntegration #HRIS #SSO #Provisioning #DynamicSecurityGroups #ConditionalAccess #Salesforce #SalesforceIntegration #IAMEngineer #AzureEngineer #IdentityManagement #CyberSecurity #RemoteJobs #ContractJobs #ITJobs #TechJobs #ConsultingJobs #NowHiring

Work arrangement
No

Get JobBeeper Mobile App

Never miss a job opening! Get instant job alerts on your phone.

Subscribers see fresh openings within minutes. Download the JobBeeper App on Google Play to get real-time push notifications and apply before anyone else.

⚡ Instant Push Alerts 🎯 Tailored Filters 🚀 Direct Employer Links
GET IT ON Google Play

More openings worth a look

Recently tracked roles with full details and direct application links.

6 roles
Good roles move before most people even see them. Tell JobBeeper what you want and get fresh matches delivered in minutes.
Start your free trial →
⚡ Get fresh job alerts 📱 Get App