Posted 21 July, 2026
2026-0098 MFA Internet Portals POC (NS) REMOTE - 9 Jul
Park Lane Recruitment Ltd
London, ENG, GB
Full Time
Job Description
- \n
- Deadline Date: Thursday 09 July 2026 \n
- Build a Proof of Concept (POC) environment based on a single Entra ID Identity \n
- Required Security Clearance: NATO SECRET (or UK SC) \n
- \n
- Current National or NATO SECRET clearance \n
- Nationality of one of the NATO member countries \n
- Current work visa for the specific location if applying for an in-country position \n
- \n
- Build a Proof of Concept (POC) environment based on a single Entra ID Identity Provider to a number of MFA technologies as MFA brokers. \n
- Test and document POC applications against a set test criterion. \n
- Build and test security logging with the security department. \n
- Document Service delivery requirements and support documentation. \n
- Work with Quality teams to align test strategy and test acceptance. \n
- This SOW will not exceed EUR 73,750 (Deliverables and Travel). \n
- \n
- The identification of the most fit-for-purpose solution is to be validated, confirmed and accredited. \n
- The solution is to align with other ongoing NCIA efforts, including but not limited to: IT Modernization; NATO Cloud Programs; Protected Business Network; and NATO and NCIA Directives. \n
- The solution is developed in close coordination with NCSC, NCIA and its technical staff. Coordination meetings shall take place at intervals sufficient to ensure information sharing and technical exchange. \n
- Due to the criticality and dependencies of follow-on project elements, the solution is to be completed and accepted no later than end of December 2026. \n
- \n
- Minimum 5 years of experience in Identity and Access Management. \n
- Strong knowledge of authentication protocols (SAML, OIDC). \n
- Sound knowledge of federated identity management and Single Sign-On (SSO) solutions (Okta, Entra ID, and similar). \n
- \n
- Proven experience designing and rolling out MFA at scale in an enterprise environment (5,000+ users). \n
- Experience with certificate-based MFA smart cards, YubiKeys, passkeys/WebAuthn, TOTP, and push-based MFA applications (Microsoft Authenticator, Duo, and similar). \n
- Understanding of risk-based or adaptive authentication strategies. \n
- \n
- Experience in securing web applications and APIs. \n
- Strong understanding of TLS, client certificates, reverse proxies, and Zero Trust principles. \n
- Experience with SSO integration of web applications. \n
- Recent experience configuring MFA technologies on the following platforms (Technology Pillars) as brokers: Moodle; SharePoint; Keycloak; Cognito. \n
- Demonstrated recent experience configuring Entra ID as an MFA Provider to the above MFA brokers. \n
- Ability to produce high-standard documentation for testing and service delivery. \n
- \n
- Excellent verbal and written communication skills. \n
- Full proficiency in English. \n
- Ability to communicate technical information to non-technical users in a clear and concise manner. \n
- \n
- Strong customer service focus with a commitment to user satisfaction. \n
- Patience and empathy when dealing with user issues and concerns. \n
- \n
- Attention to detail in documenting support activities and maintaining accurate records. \n
- \n
- Ability to work effectively as part of a team and share knowledge and resources. \n
- Willingness to collaborate with colleagues to solve complex issues. \n
- \n
- Strong customer relationship skills, including negotiating complex and sensitive situations under pressure. \n
- Must hold the nationality of one of the NATO member nations. \n
