Senior Architect, Identity & Security

West Monroe

Not Interested
Bookmark
Report This Job

profile Job Location:

Chicago, IL - USA

profile Monthly Salary: Not Disclosed
Posted on: 19 hours ago
Vacancies: 1 Vacancy

Job Summary

Are you ready to make an impact

Senior Principal/Architect (Identity & Security)

Overview

A consulting organization is seeking a Senior Principal/Architect (Identity & Security) to lead cross-functional teams in the design remediation and modernization of complex identity and cloud infrastructure solutions. This role focuses on securing and transforming critical IT environments for a diverse portfolio of clients helping them navigate complex Active Directory modernizations cloud identity migrations and security hardening initiatives. This opportunity provides technical leadership in transforming complex IT environments across key industry verticals including Healthcare Financial Services Private Equity and High Tech.

Responsibilities:

  • Partner with consultants and client leadership to architect build and deploy secure and modern Active Directory and Microsoft Entra ID solutions.
  • Assess current-state identity environments and processes interview stakeholders define critical requirements and present practical solution strategies and roadmaps to client executives.
  • Lead the technical design of future-state Active Directory (AD DS) and Entra ID architectures including Privileged Access Management (PAM) design Tiered Administrative Access Models and identity consolidation strategies.
  • Establish and enforce identity architecture standards best practices and governance to deliver secure compliant and consistent solutions aligned with industry benchmarks (e.g. CIS and Microsoft baselines).
  • Lead security assessment and remediation planning including consolidating findings from tools (e.g. Purple Knight CIS scans) to create and manage prioritized risk-based remediation backlogs.
  • Provide expert technical oversight for security remediation initiatives such as hardening domain controllers remediating privileged access resolving Entra Connect sync issues and restricting legacy protocols.
  • Develop detailed implementation plans migration strategies and remediation backlogs (e.g. in Smartsheet or similar project management tools) for AD consolidation identity synchronization and legacy decommissioning.
  • Establish and manage engagement-level governance quality and risk management including defining quantitative success criteria RACI and managing all technical stakeholder communications.
  • Support key decision-making on project direction including technology selections team workstreams and delivery methodologies.
  • Mentor junior consultants on technical best practices solution design and client engagement.
  • Assist business development efforts through proposals pre-sales technical discovery and client presentations.

Qualifications:

  • Bachelors degree in a relevant field preferred or equivalent experience required.
  • Prior experience in consulting preferred.
  • 812 years of experience in IT architecture engineering and/or security with a deep focus on identity solutions.
  • Expert-level knowledge of Active Directory Domain Services (AD DS) design security and administration including: domain/forest architecture sites/replication DNS Group Policy (GPO) management DC virtualization safeguards and forest recovery principles.
  • Strong experience with Microsoft Entra ID (formerly Azure AD) including Entra Connect Conditional Access and Privileged Identity Management (PIM).
  • Proven experience leading on-prem to cloud identity migrations AD remediations and/or consolidation projects.
  • Proficiency in designing and implementing Privileged Access Management (PAM) solutions (including typical platforms like CyberArk/Delinea) and Tiered Access Models (EAM).
  • Hands-on experience with AD security assessment tools (e.g. Purple Knight PingCastle) and hardening methodologies (CIS Benchmarks Microsoft baselines).
  • Proficiency with AD security hardening techniques such as LAPS adoption resource-based Kerberos constrained delegation remediation (RBKCD) and LDAP signing configuration.
  • Familiarity with migration tools (e.g. Quest On-Demand Migration) and identity-driven application dependencies.
  • Strong communication (written and verbal) presentation client management and team leadership skills.
  • Willingness to travel for out-of-town client engagements.

Bonus skills:

  • Familiarity with compliance standards (e.g. NIST HIPAA ISO).
  • Advanced scripting for automation and analysis (e.g. PowerShell).
  • Knowledge of Infrastructure as Code (Terraform) and DevSecOps practices.
  • Experience with remediation techniques (e.g. KRBTGT password rotation NTLM restriction Group Policy cleanup).
  • Familiarity with application dependency mapping tools (e.g. Device42 Faddom).
  • Familiarity with enterprise Identity Governance and Administration (IGA) platforms (e.g. SailPoint Saviynt) to manage and improve periodic access certifications (e.g. moving from spreadsheets to a tool) and run detective Segregation of Duties (SoD) reports.
  • Experience automating identity lifecycles by replacing nightly batch files from a Human Resources Information System (HRIS) with Application Programming Interface (API)-driven syncs or establishing governance for non-employee/contractor identities.
  • Understanding of System for Cross-domain Identity Management (SCIM) or API-based provisioning to automate Joiner-Mover-Leaver (JML) workflows for Software as a Service (SaaS) apps expanding beyond just core directories and email.
  • Familiarity with security event logging (i.e. security information and event management (SIEM) integration with Active Directory and other tier 0 assets).
  • Familiarity with common customer identity and access management (CIAM) platforms (Microsoft Entra External ID Okta Auth0 etc.) and their migration/implementation patterns.
  • Professional certifications (e.g. Microsoft Identity/SC series CISSP CyberArk/Delinea).

What to Expect

  • A collaborative flexible and outcomes-driven consulting environment.
  • A culture that values inclusion diverse perspectives and teamwork.
  • A business-focused and industry-specific approach to deploying technology that helps clients tackle their most significant challenges and deliver tangible results free from rigid hierarchies.

Ready to get started Join the team and make an impact.

Based on pay transparency guidelines the salaryrange for this role canvary based on your proximity to one of our West Monroe offices (seetable below). Information on our competitive total rewards packageincluding our bonus structure and benefits ishere. Individual salaries are determined by evaluating a variety of factors including geographyexperience skills education and internal equity.

Employees (and their families) are covered by medical dental vision and basic life insurance. Employeesare able toenroll in our companys 401k planpurchase shares from our employee stock ownership program and be eligible toreceive annual bonuses. Employees will also receive unlimited flexible time offand ten paid holidays throughout the calendar year. Eligibility for ten weeks of paid parental leave will also be available upon hire date.

Seattle or Washington D.C.
$203200$239100 USD
Los Angeles
$212900$250500 USD
New York City or San Francisco
$222500$261900 USD
A location not listed above
$193500$227700 USD

Other consultancies talk at you.
At West Monroe we work with you.

Were a global business and technology consulting firm passionate about creating measurable value for our clients delivering real-world solutions.

The combination of business and technology is not new but how we bring them together is unique. Were fluent in both. We know that technology alone is not the answer but how we apply it is. We rely on data to constantly adapt and solve new challenges. Actions that work today with outcomes that generate value for years to come.

At West Monroe we zero in on the heart of the opportunity getting to results faster and preparing people for whats next.

Youll feel the difference in how we work. We show up personally. Were right there in the room with you co-creating through the challenges. With West Monroe collaboration isnt a lofty promise but a daily action. We work together with you to turn vision into clear action with lasting impact.

West Monroeis an Equal Employment Opportunity Employer
We believe in treating each employee and applicant for employment fairly and with dignity. We base our employment decisions on merit experience and potential without regard to race color national origin sex sexual orientation gender identity marital status age religion disability veteran status or any other characteristic prohibited by federal state or local law. To learn more about diversity equity and inclusion at West Monroe visit If you require a reasonable accommodation to participate in our recruiting process please inquire by sending an email to .

Please review our current policy regarding use of generative artificial intelligence during the application process.

If you are based in California we encourage you to read West Monroes Notice at Collection for California residents provided pursuant to the California Consumer Privacy Act (CCPA) and linkedhere.


Required Experience:

Senior IC

Are you ready to make an impactSenior Principal/Architect (Identity & Security)OverviewA consulting organization is seeking a Senior Principal/Architect (Identity & Security) to lead cross-functional teams in the design remediation and modernization of complex identity and cloud infrastructure solut...
View more view more

Key Skills

  • Apache Hive
  • S3
  • Redshift
  • Spark
  • AWS
  • Solr
  • NoSQL
  • Data Warehouse
  • Internet Of Things
  • Kafka
  • DynamoDB
  • ZooKeeper

About Company

Company Logo

West Monroe is a global business and technology consulting firm passionate about creating value for our clients.

View Profile View Profile