Identity & Endpoint Security Engineer (Windows Hello)(Contract)(Contract)

KeyData Cyber · USA · Engineering

Posted 2026-09-14

Apply for this role →

As a Identity & Endpoint Security Engineer (Windows Hello), you will be part of our Delivery Services Team. This position will be responsible for designing, configuring, and deploying passwordless authentication solutions using Windows Hello for Business and Microsoft Entra ID. You will play a critical role in modernizing authentication, improving user experience, and enhancing security through enterprise-wide passwordless access initiatives.

Location: United States

Employment Type: 3 months contract, Remote

What You'll Do:

Assess Active Directory, Microsoft Entra ID, device join status, endpoint management platforms, and authentication dependencies to determine deployment readiness.

Evaluate endpoint readiness, including Windows versions, TPM availability, hardware security requirements, and biometric capabilities.

Design and recommend the appropriate Windows Hello for Business deployment model, including cloud Kerberos trust where applicable.

Identify and address password dependencies across VPN, Wi-Fi, file shares, enterprise applications, Remote Desktop Services (RDP), and VDI environments.

Define enrollment, recovery, privileged access, exception handling, and operational support requirements.

Configure and deploy Windows Hello for Business using Microsoft Intune and/or Group Policy.

Implement Microsoft Entra Kerberos and cloud Kerberos trust to enable secure access to on-premises resources.

Configure PIN, biometric authentication, hardware security, enrollment policies, and authentication controls.

Configure Microsoft Entra authentication methods, Conditional Access policies, and passwordless authentication workflows.

Implement secure onboarding and recovery processes, including Temporary Access Pass (TAP) where applicable.

Resolve policy conflicts and validate integrations with existing identity providers, endpoint management platforms, and security controls.

Develop and execute test plans covering enrollment, Windows sign-in, application access, remote connectivity, authentication recovery, and business continuity scenarios.

Lead pilot deployments across representative user populations and device configurations.

Troubleshoot authentication failures, Kerberos issues, device registration problems, enrollment failures, and application compatibility concerns.

Execute phased production rollouts through controlled deployment groups with clearly defined success criteria and rollback procedures.

Collaborate with infrastructure teams, application owners, and security stakeholders to eliminate remaining password dependencies.

Develop PowerShell scripts and Microsoft Graph automation for readiness assessments, reporting, monitoring, and administrative tasks.

Monitor deployment progress, enrollment success rates, authentication issues, and operational exceptions.

Create and maintain technical documentation, architecture diagrams, configuration standards, troubleshooting guides, and operational runbooks.

Conduct knowledge transfer sessions and train service desk and engineering teams on enrollment, PIN reset procedures, device replacement, and recovery workflows.

Integrate passwordless authentication enrollment into employee onboarding and endpoint provisioning processes.

Who We're Looking For:

3–5 years of hands-on experience implementing and supporting Windows Hello for Business in enterprise environments.

Bachelor's or Master's degree in Computer Science, Computer Engineering, Information Technology, Cybersecurity, or equivalent experience.

Strong experience with Microsoft Entra ID (Azure AD), Active Directory, and Microsoft Intune.

Practical experience managing Entra-joined and Hybrid Entra-joined Windows devices.

Hands-on experience implementing cloud Kerberos trust or other Windows Hello for Business trust models.

Strong understanding of Kerberos authentication, Multi-Factor Authentication (MFA), Conditional Access, Single Sign-On (SSO), and modern authentication protocols.

Experience configuring Windows authentication and security policies using Intune and Group Policy.

Ability to troubleshoot authentication issues across endpoints, identity platforms, cloud services, and enterprise applications.

Proficiency in PowerShell scripting and familiarity with Microsoft Graph APIs.

Experience supporting production deployments, phased rollouts, change management activities, and operational handovers.

Strong verbal and written communication skills with the ability to effectively communicate technical concepts to both technical and non-technical audiences.

Ability to work independently and collaboratively within cross-functional teams.

Previous consulting experience would be considered an asset.

Nice-to-Have Skills

Experience implementing FIDO2 security keys, passkeys, and enterprise passwordless authentication strategies.

Experience with Windows Autopilot and automated endpoint provisioning solutions.

Familiarity with Public Key Infrastructure (PKI), certificate services, and certificate-based authentication.

Experience integrating enterprise applications with Microsoft Entra ID.

Understanding of Privileged Access Management (PAM) concepts and administrative account separation strategies.

Experience supporting modern workplace and endpoint management initiatives.

Relevant Microsoft certifications, including Identity and Access Administrator, Endpoint Administrator, or related Microsoft security certifications.#LI-AS1

Apply for this role →

← Back to all jobs