IAM/ Cloud Identity Consultant (Entra ID & AWS Identity Center)
HEXADIUS CONSULTING PTE. LTD.
Company Overview
Established in 2009 in Singapore, Hexadius is a boutique professional services firm specializing in cybersecurity advisory, implementation, managed support, and training to help clients manage risks without hindering business growth.
Job Summary
Lead and deliver enterprise identity initiatives involving Microsoft Entra ID and AWS Identity Center. Provide hands-on technical execution and advisory services to design, migrate, integrate, secure, and support scalable identity environments for clients.
Responsibilities
- Lead and validate license transitions (e.g., CSP to Enterprise Agreement) ensuring uninterrupted business operations
- Validate and optimize administrative roles, access models, Conditional Access, MFA, and Identity Protection policies
- Conduct end-to-end validation of identity services post-migration, including application (SAML/OIDC, SCIM) and third-party integrations (AWS Identity Center, Zscaler)
- Support stabilization and post-migration monitoring to maintain zero disruption
- Prepare and maintain migration plans, UAT scenarios, test cases, runbooks, playbooks, and solution documentation (BRD/SDD updates)
- Design and implement secure SSO integration between Entra ID and AWS Identity Center in production environments
- Assess and enhance SAML and SCIM configurations and group-to-role mappings aligned with least privilege principles
- Enforce environment segregation (Dev vs Prod) for identities, groups, and access controls
- Configure and validate secure authentication controls including MFA, Conditional Access, claims, identifiers, and certificates
- Implement production-grade security controls covering access governance, monitoring, audit readiness, and compliance
- Validate role-based access across AWS accounts and end-to-end SSO functionality
- Enable centralized logging and monitoring including Entra ID logs and secure AWS S3 log storage integration
- Ensure identity configurations comply with enterprise security baselines
- Implement and validate identity governance controls, risk-based access policies, and audit/reporting capabilities
- Identify and mitigate access gaps, misconfigurations, and security risks
- Collaborate with client stakeholders to validate project scope, effort estimates, and assumptions
- Provide expert recommendations on identity architecture and best practices
- Facilitate solution design discussions and technical workshops
- Contribute to effort estimation and proposal development
- Produce high-quality client-facing documentation including architecture diagrams, configuration guides, operational runbooks, and support procedures
- Deliver knowledge transfer and transition support to client teams