Job Title: Principal Microsoft Solutions & Platform Architect
Location: Seattle, WA Hybrid (Non-local profiles accepted)
Type: C2H (6 Months)
Visa Status: USC
Only on W2
Position Summary:
The Principal Microsoft Identity & Platform Engineer serves as the organization's technical authority for Microsoft Identity, Security, Endpoint Management, and Zero Trust architecture. This role will lead the design, engineering, deployment, and operational maturity of Microsoft Entra ID, Identity Governance, Policies, Intune, Windows Autopilot, Defender, Global Secure Access, and Microsoft 365 security/E5 capabilities.
The ideal candidate combines deep hands-on engineering expertise with enterprise architecture capabilities and has successfully delivered complex identity transformations including Active Directory modernization, password less authentication, cloud-first endpoint management, and Zero Trust initiatives. This individual will partner closely with Technology Operations, Information Security, Infrastructure, Compliance, Service Desk, and business stakeholders to develop and execute client Microsoft platform roadmap.
This position is open to candidates in the Seattle area. You will have a hybrid remote/in-office schedule where you will work from our casual, pet-friendly office at least 3 days a week. Remote for right candidate
Responsibilities:
Identity Modernization
- Lead enterprise-wide initiatives to reduce dependency on traditional Active Directory, identify legacy dependencies, and establish a phased roadmap toward a modern, cloud-first identity environment.
- Develop and execute an Entra-first identity architecture strategy, defining the target-state architecture, migration approach, security controls, governance model, and operational standards.
- Develop and execute strategies to eliminate, remediate, or modernize legacy authentication dependencies, including applications relying on traditional AD, LDAP, Kerberos, or other legacy authentication mechanisms.
- Lead ADFS retirement planning and execution, including dependency discovery, application remediation, authentication modernization, testing, phased migration, and final decommissioning.
- Define standards for identity synchronization, provisioning, deprovisioning, directory architecture, and identity lifecycle management.
- Develop migration roadmaps for transitioning from Hybrid Entra Join to Entra Join, while addressing dependencies that require continued on-premises identity services.
Authentication & Access Management
- Define and execute the organization's password-less authentication strategy
- Design and implement Windows Hello for Business and Cloud Kerberos Trust architecture.
- Establish phishing-resistant authentication standards aligned with Zero Trust and modern identity security practices.
- Define authentication lifecycle standards covering enrollment, authentication, recovery, credential management, and deprovisioning.
Endpoint Modernization
- Lead Microsoft Intune transformationinitiatives and define cloud-first endpoint management standards.
- Drive GPO-to-Intune migration programs, including policy assessment, redesign, testing, and phased deployment.
- Implement CIS benchmark and security baseline controls through Intuneto strengthen endpoint security and compliance.
- Modernize Windows deployment, provisioning, and device lifecycle management, including enrollment, configuration, maintenance, and retirement standards.
Entra Join & Autopilot Transformation
- Lead the transition from Hybrid AD Join to Entra Join, developing migration strategies that minimize business disruption and legacy dependencies.
- Architect and implement Windows Autopilot modernization initiativesto enable scalable, automated, and cloud-first device provisioning.
- Design standardized device deployment, enrollment, and provisioning processesacross Intune, Entra ID, and Autopilot.
- Implement Cloud Kerberos Trustand eliminate legacy dependencies that prevent modern Entra Join and cloud-based endpoint deployments.
Secure Access Architecture
- Lead evaluation of Microsoft Global Secure Access.
- Design Entra Private Access architecture.
- Design Entra Internet Access architecture.
- Develop coexistence and migration strategies from Zscaler.
- Conduct proof-of-concept testing.
- Create migration roadmaps and operational support models.
Identity Governance
- Evaluate and implement Entra Identity Governance capabilities.
- Design Joiner-Mover-Leaver workflows.
- Develop automated access certification processes.
- Integrate identity lifecycle management with HR systems.
- Improve role-based access governance and compliance.
Automation & Engineering
- Develop PowerShell automation solutions.
- Utilize Microsoft Graph APIs.
- Automate provisioning and reporting.
- Reduce operational overhead through engineering practices.
- Build self-service capabilities for users and support teams.
Required Qualifications
- 8+ yearsof Microsoft infrastructure engineering experience, including 5+ years in Microsoft Identity and 5+ years in Microsoft 365 administration and architecture.
- 5+ years of hands-on Intune and endpoint engineering, with demonstrated experience leading enterprise transformation programsand designing Zero Trust architectures.
- Experience working in regulated or compliance-driven environments, with strong understanding of security, governance, and risk management requirements.
- Proven ability to lead complex Microsoft modernization initiatives, with strong cross-functional collaboration and technical leadership skills.
- Preferred Microsoft Certifications:
- Microsoft Certified: Identity and Access Administrator Associate
- Microsoft Certified: Cybersecurity Architect Expert
- Microsoft Certified: Endpoint Administrator Associate
- Microsoft Certified: Azure Solutions Architect Expert (AZ-305)
Skills
- Microsoft Entra ID, Conditional Access, Identity governance, PIM, Cloud sync, Entra connect, ADFS, SSO, MFA, Authentication flow.
- Microsoft Intune, Autopilot, Entra join, hybrid join, Windows update for business, CIS benchmarks, GPO migration
- GSA, Entra Private Access, Entra Internet Access, Private Application Access
- Powershell, Microsoft Graph, REST APIs, Azure Automation
- Independent technical ownership, mentoring, cross-functional collaboration, and clear communication with technical and non-technical audiences