Job Specifications
Job Description:
IAM Consultant
Location: Alpharetta, GA
No of Position: 2
The IAM Engineer– Passwordless & WHfB will lead the design and implementation of modern authentication solutions across the enterprise. This role focuses on assessing the current identity landscape, architecting Windows Hello for Business and passwordless strategies, integrating with Microsoft Entra ID and Intune, and guiding large‐scale rollout and operational readiness. The architect will ensure security, compliance, and user experience are optimized while providing clear documentation, technical leadership, and cross-team enablement.
Architecture & Design
Assess current identity and authentication posture (password policies, MFA, PKI, hybrid join, device management).
Recommend the appropriate Windows Hello for Business (WHfB) trust model (Cloud Kerberos, Hybrid Key, Hybrid Certificate) and define migration paths.
Design integrations with Microsoft Entra ID, Active Directory, Intune, Conditional Access, Identity Protection, and Defender for Endpoint.
Define device provisioning and compliance requirements (Autopilot, VDI, TPM, HSTI) and establish backup/recovery strategies.
Implementation & Rollout
Configure WHfB policies (Intune/GPO), Authentication Methods, and Conditional Access for passwordless authentication.
Implement or integrate PKI components, certificate templates, CRLs/AIA, and support smart card migration/ADFS deprecation where needed.
Run pilots, evaluate results, and manage phased rollouts across regions and device types.
Validate SSO/Kerberos flows to on‐prem resources and establish monitoring via Entra logs, Intune reporting, and Log Analytics.
Troubleshooting & Operations
Build runbooks, break‐glass steps, and tiered support workflows.
Diagnose WHfB issues (TPM/attestation, PIN reset, dsregcmd, trust model anomalies).
Optimize user experience, authentication performance, and fallback MFA posture.
Security & Compliance
Align solutions with NIST 800‐63/800‐53, ISO 27001, and phishing‐resistant authentication best practices.
Ensure IAM policies meet governance, audit, and risk‐mitigation requirements.
Documentation & Enablement
Produce HLD/LLD documentation, migration plans, test/UAT guides, and support FAQs.
Deliver training and communication materials for admins, helpdesk teams, and end users.
Will wait for your response.
Vishnu Singh
Email : vishnu@datumtg.com
Phone : 470 451 0404
About the Company
Datum Technologies Group is the go-to partner for comprehensive technology solutions and staffing services.
We are industry veterans with expertise in managed services, technology project delivery, and global workforce solutions, with a proven track record of delivering innovative solutions to help businesses optimize operations, reduce costs, and achieve their digital transformation objectives.
Know more