1

Azure Ad Engineer Jobs in Washington (NOW HIRING)

Azure AD B2C / CIAM (Primary Product Area: Federation & Interoperability (FI)): Own the technical lifecycle of the Customer Identity and Access Management (CIAM) platform. Engineer all custom ...

Azure AD B2C / CIAM (Primary Product Area: Federation & Interoperability (FI)): Own the technical lifecycle of the Customer Identity and Access Management (CIAM) platform. Engineer all custom ...

Role Summary A highly specialized SME Systems Engineer with expertise in Federation and Interoperability (FI), focusing primarily on Customer Identity and Access Management (CIAM) via Azure AD B2C.

Azure Engineer II

Ashburn, VA · On-site

$57 - $76.25/hr

Azure Cloud Engineer II Position Summary We are seeking a highly skilled Azure Cloud Engineer to ... Manage Azure identity and security services including Entra ID (Azure AD), Conditional Access, RBAC ...

Azure Engineer II

Ashburn, VA · Hybrid

$57 - $76.25/hr

Azure Cloud Engineer II Position Summary We are seeking a highly skilled Azure Cloud Engineer to ... Manage Azure identity and security services including Entra ID (Azure AD), Conditional Access, RBAC ...

Azure Engineer II

Ashburn, VA · On-site

$115K - $145K/yr

Azure Cloud Engineer II Position Summary We are seeking a highly skilled Azure Cloud Engineer to ... Manage Azure identity and security services including Entra ID (Azure AD), Conditional Access, RBAC ...

Senior Azure Cloud Engineer

Washington, DC · On-site

$63 - $84.25/hr

The Sr. Azure Cloud Engineer role serves as the Subject Matter Expert leading the development ... Configure and manage Azure services, including virtual networks, VMs, storage accounts, Azure AD ...

Senior Azure Cloud Engineer

Washington, DC · On-site

$63 - $84.25/hr

The Sr. Azure Cloud Engineer role serves as the Subject Matter Expert leading the development ... Configure and manage Azure services, including virtual networks, VMs, storage accounts, Azure AD ...

next page

Showing results 1-20

Azure Ad Engineer information

What does an Azure AD Engineer do?

An Azure AD Engineer is responsible for managing and maintaining Microsoft Azure Active Directory (Azure AD), which is a cloud-based identity and access management service. Their duties include configuring user authentication, implementing security protocols, integrating applications with Azure AD, and troubleshooting identity-related issues. They also help organizations ensure secure access to resources, manage user identities, and support single sign-on (SSO) and multi-factor authentication (MFA) solutions.

What are the key skills and qualifications needed to thrive as an Azure AD Engineer, and why are they important?

To thrive as an Azure AD Engineer, you need a solid understanding of identity and access management concepts, experience with Azure Active Directory, and typically a bachelor’s degree in computer science or a related field. Familiarity with tools like Microsoft Azure Portal, PowerShell scripting, and certifications such as Microsoft Certified: Azure Administrator Associate are highly valuable. Strong problem-solving abilities, attention to detail, and effective communication skills help in troubleshooting issues and collaborating with stakeholders. These skills are crucial for ensuring secure, efficient, and reliable identity solutions within an organization’s cloud infrastructure.

What are some common challenges Azure AD Engineers face when managing hybrid identity environments?

Azure AD Engineers often encounter challenges when integrating on-premises Active Directory with Azure Active Directory, such as managing synchronization issues, ensuring seamless single sign-on, and maintaining consistent security policies. Troubleshooting authentication failures and keeping up with frequent Azure updates can also be demanding. Effective collaboration with security, networking, and support teams is essential to address these complexities while maintaining a secure and reliable identity infrastructure.

How much do Azure AD engineers make?

Azure AD engineers typically earn between $80,000 and $130,000 annually, depending on experience, location, and certifications such as Microsoft Certified: Azure Solutions Architect. Salaries can vary based on the complexity of the environment and the size of the organization.
Infographic showing various Azure Ad Engineer job openings in Washington as of August 2026, with employment types broken down into 100% Full Time. Highlights an 89% In-person, and 11% Remote job distribution.

Azure AD / Entra ID Engineer

Fairfax, VA • On-site

Client First Technologies
51 - 200 employees

Full-time

Posted 23 days ago


Job description

Description:

Overview 


Client First Technologies currently is seeking an Azure AD / Entra ID Engineer to provide engineering, integration, and security support for a Federal customer’s Microsoft Entra ID Business-to-Business (B2B) interagency collaboration program. This role is responsible for designing, implementing, securing, and sustaining enterprise B2B identity integrations that enable secure collaboration with external federal agencies and partners. The position combines advanced-level identity architecture experience with site integration engineering, security control implementation, and production of required interconnect documentation (ISA, MOU, MOA, MFR). Operating within the customer’s governance frameworks and federal security standards, this role ensures secure, scalable, and repeatable B2B enablement while meeting stakeholder coordination and 24-hour support resolution targets. 


This is a full-time, remote position.   


CFT offers a full benefits package, a collaborative work environment and a strong company culture.  Veterans and military spouses are encouraged to apply. 


Requirements:

Responsibilities 


  • Provide advanced-level engineering and operational support for Microsoft Entra ID (Azure AD) within a hybrid identity environment, supporting secure interagency B2B collaboration across Federal enterprises 
  • Lead and support technical site assessments for new B2B partner integrations, evaluate identity architectures, authentication flows, conditional access policies, cross-tenant access settings, and security posture 
  • Develop and execute detailed integration and enablement plans aligned to federal security standards, policies, and customer-specific requirements 
  • Configure and manage Entra ID B2B collaboration settings, cross-tenant access policies, multi-tenant organizations (MTO)/cross-tenant sync, external identities, guest lifecycle governance, conditional access, and authentication controls 
  • Support intake procedures and enablement workflows to ensure repeatable, scalable onboarding of new partner organizations and programs 
  • Provide Tier 3 engineering support for B2B authentication, identity federation, provisioning, and access control incidents, ensuring issue resolution within established timeframes 
  • Design and implement secure authentication integrations, including federation, SSO configurations, external identity governance, and least-privilege access controls 
  • Draft and maintain required interconnect artifacts per customer/program, including Interconnect Security Agreements (ISA), Memoranda of Understanding (MOU), Memoranda of Agreement (MOA), and Memoranda for the Record (MFR), ensuring documentation reflects actual implemented technical controls 
  • Develop repeatable templates, runbooks, and documentation standards to reduce cycle time and improve consistency across B2B partner enablement 
  • Coordinate with cybersecurity, infrastructure, and application stakeholders to ensure integrations meet federal cybersecurity requirements and VA Handbook 6500 standards 
  • Participate in release management activities, ensuring proper communication, coordination, and execution of B2B-related changes across stakeholders 
  • Develop and maintain knowledge repositories, technical documentation, and training materials supporting B2B operations and enablement 
  • Support custom identity integration engineering efforts where required to meet agency-specific collaboration needs 
  • Contribute to continuous improvement initiatives that enhance scalability, automation, and security posture of the B2B program 


Qualifications 


  • Bachelor’s degree in Information Technology, or a related field (or equivalent professional experience) 
  • Minimum of seven (7) years of progressive IT experience, including five (5) years of hands-on Microsoft Entra ID / Azure AD engineering within large-scale enterprise or federal environments 
  • Demonstrated experience conducting tenant assessments, designing and implementing Entra ID B2B and external identity solutions in hybrid Active Directory environments (on-prem AD authoritative) 
  • Proven ability to lead identity-focused site assessments, develop integration and enablement plans, and execute secure cross-tenant collaboration and synchronization configurations 
  • Hands-on experience configuring conditional access policies, authentication methods, federation, identity governance controls, and cross-tenant access settings 
  • Experience supporting ATO and/or ATC processes, including drafting or contributing to interconnect documentation (ISA, MOU, MOA, MFR) aligned to implemented technical controls 



Preferred Technical Qualifications 


  • Desired Certifications include relevant Microsoft identity and security certifications (e.g., Microsoft Identity and Access Administrator, Azure Solutions Architect Expert, Microsoft 365 Enterprise Administrator Expert) and/or ITIL Foundation; equivalent advanced-level enterprise experience supporting Entra ID and federal identity integrations may be accepted in lieu of specific certifications 
  • Experience with Microsoft Entra ID / Azure AD, including External Identities (B2B), Cross-Tenant Access Policies, Conditional Access, Identity Protection, Access Reviews, Privileged Identity Management (PIM), Hybrid Identity, Federation Services 
  • Experience with Hybrid Identity Architecture, including On-prem Active Directory integration, directory synchronization, identity lifecycle management, and authentication flow design 
  • Experience with Security & Compliance Frameworks, including VA Handbook 6500, RMF control mapping, ATO/ATC support documentation, NIST 800-53 familiarity 
  • Experience with B2B Integration Engineering, including identity federation, SSO configurations, secure partner onboarding workflows, guest lifecycle governance, least privilege access models 
  • Experience with Automation & Scripting, including PowerShell (AzureAD, Microsoft Graph, Entra modules) for identity configuration, policy deployment, reporting, and repeatable enablement processes 
  • Experience with Service Management & Governance, including SLA-driven support models, release management coordination, intake procedures, knowledge repository maintenance 
  • Experience with Documentation & Artifacts, including development of ISA, MOU, MOA, MFR artifacts; security architecture diagrams; integration plans; technical runbooks 
  • Experience with Enterprise Security Engineering, including incident response support, authentication threat mitigation, identity risk monitoring, and secure configuration validation 


Physical Demands 


  • Must be able to sit and stand for extended periods of time 
  • Occasional travel and overtime may be required 



Required Clearances and Screenings 


  • This position is subject to a government background investigation and must meet eligibility for a position designated with Moderate Risk sensitivity. Candidates with current Veterans Affairs (VA) Tier 2/Moderate Background Investigation or equivalent (e.g., DoD Tier 3/NACLC, Active Secret) are preferred