Identity & Endpoint Security Engineer (Windows Hello) (Contract)
At KeyData Cyber, we’re shaping the future of identity security. Recognized by Gartner and KuppingerCole as a leading IAM professional services firm, we specialize exclusively in designing, deploying, and managing end-to-end Identity and Access Management programs for organizations across North America.
With 20 years of experience, 50M+ identities managed, and 1,000+ successful deployments, our team is our strongest asset and is built by design to help clients protect critical infrastructure, enable digital transformation, and ensure compliance with confidence.
We deliver comprehensive solutions across IAM domains, including:
- Workforce IAM (Access Management, Identity Governance and Administration, Privileged Access Management)
- Consumer IAM (Identity Verification, Authentication and Access, Threat Detection) in highly regulated industries.
If you’re ready to grow your career alongside some of the industry’s best, come join us — you’re key to our success
As a Identity & Endpoint Security Engineer (Windows Hello), you will be part of our Delivery Services Team. This position will be responsible for designing, configuring, and deploying passwordless authentication solutions using Windows Hello for Business and Microsoft Entra ID. You will play a critical role in modernizing authentication, improving user experience, and enhancing security through enterprise-wide passwordless access initiatives.
Location: Canada
Employment Type: 3 months contract, Remote
Vacancy Status: Immediate Opening: This position is currently available, and hiring is underway.
What You'll Do:
- Assess Active Directory, Microsoft Entra ID, device join status, endpoint management platforms, and authentication dependencies to determine deployment readiness.
- Evaluate endpoint readiness, including Windows versions, TPM availability, hardware security requirements, and biometric capabilities.
- Design and recommend the appropriate Windows Hello for Business deployment model, including cloud Kerberos trust where applicable.
- Identify and address password dependencies across VPN, Wi-Fi, file shares, enterprise applications, Remote Desktop Services (RDP), and VDI environments.
- Define enrollment, recovery, privileged access, exception handling, and operational support requirements.
- Configure and deploy Windows Hello for Business using Microsoft Intune and/or Group Policy.
- Implement Microsoft Entra Kerberos and cloud Kerberos trust to enable secure access to on-premises resources.
- Configure PIN, biometric authentication, hardware security, enrollment policies, and authentication controls.
- Configure Microsoft Entra authentication methods, Conditional Access policies, and passwordless authentication workflows.
- Implement secure onboarding and recovery processes, including Temporary Access Pass (TAP) where applicable.
- Resolve policy conflicts and validate integrations with existing identity providers, endpoint management platforms, and security controls.
- Develop and execute test plans covering enrollment, Windows sign-in, application access, remote connectivity, authentication recovery, and business continuity scenarios.
- Lead pilot deployments across representative user populations and device configurations.
- Troubleshoot authentication failures, Kerberos issues, device registration problems, enrollment failures, and application compatibility concerns.
- Execute phased production rollouts through controlled deployment groups with clearly defined success criteria and rollback procedures.
- Collaborate with infrastructure teams, application owners, and security stakeholders to eliminate remaining password dependencies.
- Develop PowerShell scripts and Microsoft Graph automation for readiness assessments, reporting, monitoring, and administrative tasks.
- Monitor deployment progress, enrollment success rates, authentication issues, and operational exceptions.
- Create and maintain technical documentation, architecture diagrams, configuration standards, troubleshooting guides, and operational runbooks.
- Conduct knowledge transfer sessions and train service desk and engineering teams on enrollment, PIN reset procedures, device replacement, and recovery workflows.
- Integrate passwordless authentication enrollment into employee onboarding and endpoint provisioning processes.
Who We're Looking For:
- 3–5 years of hands-on experience implementing and supporting Windows Hello for Business in enterprise environments.
- Bachelor's or Master's degree in Computer Science, Computer Engineering, Information Technology, Cybersecurity, or equivalent experience.
- Strong experience with Microsoft Entra ID (Azure AD), Active Directory, and Microsoft Intune.
- Practical experience managing Entra-joined and Hybrid Entra-joined Windows devices.
- Hands-on experience implementing cloud Kerberos trust or other Windows Hello for Business trust models.
- Strong understanding of Kerberos authentication, Multi-Factor Authentication (MFA), Conditional Access, Single Sign-On (SSO), and modern authentication protocols.
- Experience configuring Windows authentication and security policies using Intune and Group Policy.
- Ability to troubleshoot authentication issues across endpoints, identity platforms, cloud services, and enterprise applications.
- Proficiency in PowerShell scripting and familiarity with Microsoft Graph APIs.
- Experience supporting production deployments, phased rollouts, change management activities, and operational handovers.
- Strong verbal and written communication skills with the ability to effectively communicate technical concepts to both technical and non-technical audiences.
- Ability to work independently and collaboratively within cross-functional teams.
- Previous consulting experience would be considered an asset.
Nice-to-Have Skills
- Experience implementing FIDO2 security keys, passkeys, and enterprise passwordless authentication strategies.
- Experience with Windows Autopilot and automated endpoint provisioning solutions.
- Familiarity with Public Key Infrastructure (PKI), certificate services, and certificate-based authentication.
- Experience integrating enterprise applications with Microsoft Entra ID.
- Understanding of Privileged Access Management (PAM) concepts and administrative account separation strategies.
- Experience supporting modern workplace and endpoint management initiatives.
- Relevant Microsoft certifications, including Identity and Access Administrator, Endpoint Administrator, or related Microsoft security certifications.
Compensation
The hourly rate range for this position is $50–$58 CAD per hour. The final rate will be determined based on the candidate's experience, overall fit for the role, and expected ramp-up time. This is a 3-month, full-time contract role, working 40 hours per week. At KeyData Cyber, we are committed to fair and competitive compensation. We regularly benchmark across positions, industries, sectors, and experience levels, ensuring our approach recognizes each person's unique strengths, contributions, and the value they bring to the organization.#LI-AS1
Why You’ll Love Working Here
At KeyData Cyber, we put people first, valuing learning, growth, and work-life balance. We offer extensive opportunities to advance your career through leading digital identity projects across North America. Our culture is built on respect, inclusion, and equal opportunity for everyone.
Accessibility & Accommodations
If you require accommodation due to a disability at any time during the recruitment and/or assessment process, please contact Talent Acquisition , and we will make all reasonable efforts to accommodate your request.
Fraud Prevention & Identity Verification
We may use information provided during the application process to help prevent fraud and verify identity. These checks may be conducted automatically through trusted third‑party service providers as part of our standard application screening process.
Apply now to join the KeyData Cyber team and be part of our mission to secure the future of digital identity across North America.
About the Company
End-to-end IAM solutions for a secure, connected world. Protect your business, empower your people. With 20+ years of experience, over 1000 successful deployments and 50M+ identities managed, we have the field expertise to guide your IAM efforts and ensure seamless, secure operations with full lifecycle management—from strategy to implementation to managed services, ensuring hands-on delivery and accountability at every step. We execute with precision. Our tailored, turnkey services are designed to solve complex identity challenges, helping organizations secure their digital ecosystems, ensure compliance, and scale with confidence. Our extensive industry expertise makes us the go-to IAM partner for highly regulated sectors requiring tailored solutions and uncompromising security. We provide peace of mind that your IAM needs are supported by industry veterans who understand the demands of IAM at scale and at any maturity level.
More jobs at KeyData Cyber
-
Identity & Endpoint Security Engineer (Windows Hello)(Contract)(Contract)
USA · Contract · Sep 14, 2026
-
AWS Identity Security Engineer(Contract)
India · Contract · Sep 14, 2026
-
AWS Identity Security Engineer(Contract)
USA · Contract · Sep 14, 2026
-
AWS Identity Security Engineer (Contract)
Canada · Contract · Sep 14, 2026
-
Identity & Endpoint Security Engineer (Windows Hello)
India · Contract · Sep 14, 2026