
Security Architect – AD/Entra ID
Posted 11 hours ago

Posted 11 hours ago
This is a fully remote position, open to applicants in United States.
• Oversee the evaluation, design, and development of Active Directory and Azure Active Directory technical specifications, solutions, and implementation strategies.
• Formulate and enforce IAM policies, standards, and procedures to ensure regulatory compliance and adherence to industry best practices.
• Introduce and apply emerging security technologies and methodologies to enhance the IAM security architecture continuously.
• Provide technical advice, guidance, expertise, and risk assessments to global project and operational teams.
• Transform requirements into architectural designs and influence the deployment of essential infrastructure elements.
• Maintain proficiency in Microsoft Entra ID and associated core technologies.
• Conduct analysis of Azure Active Directory environments, pinpoint technical and operational challenges, and devise solutions for improvement.
• Sustain and optimize on-premises Active Directory infrastructure, encompassing DNS, GPOs, and domain controllers.
• Engage in or lead intricate or high-severity troubleshooting and incident/problem resolution efforts.
• Assess and resolve technically intricate security issues, internal control challenges, critical incidents, and crisis-resolution situations.
• Implement and uphold MFA and security best practices across user accounts and devices.
• Develop and oversee Microsoft Graph API integrations for automation and custom applications across Microsoft 365 services.
• Create bespoke scripts to automate administrative tasks and facilitate Graph API data retrieval.
• Write and maintain advanced PowerShell scripts for user and resource provisioning, reporting, and service configurations across Entra ID and Active Directory.
• Enforce and uphold security best practices.
• More than 10 years of relevant experience in IT Security and IT Architecture.
• Over 7 years of experience with Active Directory architecture and infrastructure.
• Comprehensive understanding of Active Directory Replication, DNS, Site Links, Site Topology, Group Policy, Global Catalogs, and other core infrastructure components.
• At least 3 years of experience with Azure Active Directory architecture and design.
• Minimum of 5 years in Identity and Access Management (IAM) processes and technologies.
• Demonstrated expertise in designing and implementing IAM solutions in complex environments.
• Proficient in Azure AD/Entra, including Conditional Access, MFA, security best practices, hybrid environments, GPOs, On-Premises Active Directory Migrations, and Azure AD Connect.
• Experience with Microsoft Graph API for data retrieval and automation across Azure AAD.
• Extensive knowledge of identity governance, authentication, authorization, federation, MFA, SSO, and PAM.
• Familiarity with federation technologies (WS-Fed, OAuth, SAML, etc.).
• Responsibilities as Enterprise/Domain Admin and/or Azure Global Admin.
• Proven experience managing Active Directory 2016/2019/2022 infrastructure for the Enterprise.
• Strong proficiency in PowerShell and Microsoft Graph API is essential.
• Knowledge of the Microsoft Security Stack, including Defender for Office 365, Defender for Identity, Defender for Cloud Apps, Entra ID, Microsoft Purview Information Protection, Data Loss Prevention, and Compliance Center experience, including Litigation Hold, Retention, and eDiscovery.
• Excellent communication and interpersonal skills, with the capacity to collaborate effectively with stakeholders at all levels.
• Open to embracing emerging technologies, including AI tools.
• Willingness to travel up to 10% of the time.
• Sedentary work with substantial wrist, hand, and/or finger movement for a minimum of 8 hours daily.
• Close visual acuity required for viewing a computer terminal and/or extensive reading for at least 8 hours daily.
• Certifications such as CISSP, CISM, or Microsoft Certified: Identity and Access Administrator Associate are advantageous.
• Primarily remote workforce (U.S. based only; some travel may be needed for certain roles, and on-site work may be required for Federal positions).
• Group Medical Insurance options: Zero Deductible PPO Plan (GuidePoint covers 90% of employee premiums and 70% for family plans) or High Deductible Health Plan with HSA (GuidePoint covers 100% of employee premiums and 75% for family plans).
• HSA contribution: $850 per employee annually / $1750 per family annually.
• Group Dental Insurance: GuidePoint pays 100% of the premium for employees and 75% for family plans.
• 12 corporate holidays.
• Flexible Time Off (FTO) program.
• Healthy mobile phone and home internet allowance.
• Eligibility for retirement plan after 2 months at open enrollment.
• Pet Benefit Option.
• Opportunities for collaboration, mentorship, and guidance from experienced colleagues.
OpenLoop
Funcional Health Tech
Salesforce
CNO Financial Group
Get handpicked remote jobs straight to your inbox weekly.