IAM Consultant/Developer (Microsoft Entra ID) - Contract role, UK, fully remote
Remote, UKRemoteContract
AI Summary
Hands-on IAM Consultant/Developer delivering Microsoft Entra ID identity migrations, designing target architecture and executing cutover with hybrid identity and SSO integration.
About this role
About Us
Colibri Digital is a specialist consultancy delivering advanced Data, AI and Cloud solutions for clients across financial services, healthcare, government and enterprise technology sectors.
We help organisations build intelligent, scalable and production-grade data platforms that drive measurable business outcomes. We work closely with our clients to move beyond experimentation and into real-world AI and data transformation delivery. Our Consultants operate as trusted advisors and technical leaders within client environments, combining deep technical expertise with strong stakeholder engagement and delivery capability.
The Role
We're looking for a hands-on IAM Consultant/Developer to join Colibri Digital on client engagement, supporting a major Microsoft Entra ID implementation.
We're looking for a hands-on IAM Consultant/Developer to join Colibri Digital on client engagement, supporting a major Microsoft Entra ID implementation.
This is a hands-on delivery role requiring someone who can combine IAM architecture and design with practical implementation experience. You’ll play a key role in delivering the migration to Microsoft Entra ID, working across discovery, target state design, migration execution, security and handover.
This is not a steady-state IAM administration role. We're looking for someone who has previously delivered complex identity migration/implementation projects and is comfortable operating within a fast-paced client consulting environment.
Key Responsibilities
- Discovery & design — audit the existing identity estate (on-prem AD, and/or third-party IdP such as Okta or Ping) and design the target-state architecture in Microsoft Entra ID.
- Migration execution — plan and run the cutover, including phased/staged migration approaches to minimise disruption to live services.
- Hybrid identity — configure and manage synchronization between on-prem and cloud using Microsoft Entra Connect or Entra Cloud Sync during the transition period.
- Authentication & security — implement MFA, Conditional Access policies, and passwordless sign-in aligned to Zero Trust principles.
- Application integration — migrate or re-establish SSO for enterprise applications using SAML, OAuth 2.0, and OIDC.
- Identity governance — stand up Privileged Identity Management (PIM), Entitlement Management (access packages), and Access Reviews as part of the target state.
- Cutover support & troubleshooting — monitor sign-in/audit logs and identity protection signals during and after migration to catch issues early.
- Documentation & handover — leave the operations team with clear runbooks and a clean handover once migration is complete.
Skills, Knowledge & Expertise
Essential:
- Proven experience delivering a migration onto Microsoft Entra ID (formerly Azure AD) — from on-prem AD DS or from a third-party IdP (Okta, Ping, ForgeRock, etc.).
- Strong working knowledge of Conditional Access, Zero Trust security models, and modern authentication protocols (SAML 2.0, OAuth 2.0, OIDC).
- Confident PowerShell scripting for identity lifecycle automation, ideally via the Microsoft Graph PowerShell SDK.
- Comfortable working independently and communicating migration risk/status to non-technical stakeholders.
Desirable:
- KQL for log analysis in Microsoft Sentinel or Azure Monitor.
- Experience with Entra ID B2B/B2C.
- Background with an alternative IAM platform (ForgeRock, Ping, Okta) — genuinely useful for migration work, since you understand what you're migrating from, not just what you're migrating to.
Certifications (nice to have, not mandatory):
- SC-300 (Identity and Access Administrator Associate)
- SC-100 (Cybersecurity Architect Expert)
- SC-500 (Cloud and AI Security Engineer Associate)
- CISSP
Skills
Azure ADAzure MonitorCISSPConditional AccessEntra ID B2BEntra ID B2CForgeRockKQLMicrosoft Entra IDMicrosoft Graph PowerShell SDKMicrosoft SentinelOAuth 2.0OIDCOktaPingPowerShellSAML 2.0SC-100SC-300SC-500Zero-trust
Explore related jobs
More jobs at Nasstar
Similar Azure AD jobs
- Staff Security Operations Engineer - Active Directory (AD) & Azure AD (Entra ID)Sandisk · Batu Kawan, Penang
- Access Provisioner I (Azure Identity Admin with the primary focus on Azure AD)USM · Virginia Beach, VA
Arquitecto O365/ Gestión de Identidades de Azure AD - INGLÉS B2(Híbrido: 3 días en remoto)knowmad mood · Madrid, Spain
Browse these categories
Market data for this role
All reports →- SeriesRole reportsOne role family at a time: how many openings, what changed this week, who is hiring, what it pays.
- SeriesSalary reportsWhat employers publish in job postings, by level and workplace. Not self-reported pay.
- Market overviewState of tech hiring, September 2026: up 4.8%Tech hiring rose 4.8% month over month in September 2026, with 411,122 new listings. Customer support and account executive roles led the growth.
