Security Architect - AD/Entra ID (Remote in the US)

GuidePoint Security LLC

Polska

Hybrid

PLN 548,000 - 743,000

Full time

2 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

GuidePoint Security LLC seeks a highly experienced Security Architect (AD/Entra ID) to lead IAM initiatives and architecture across AD and Entra ID. Role is remote in the US, with responsibility for design, testing, and documentation of identity solutions.

You will implement MFA, build Graph API integrations, and automate tasks with PowerShell, guiding global project teams and aligning IAM with regulatory requirements.

Qualifications

  • 10+ years of IT security and IT architecture experience.
  • 7+ years of Active Directory architecture and infrastructure expertise.
  • 3+ years of Azure Active Directory architecture and design.
  • 5+ years of Identity and Access Management (IAM) experience.
  • Proven IAM design and implementation experience in complex environments.
  • Expertise managing Azure AD/Entra, including Conditional Access, MFA, hybrid environments.
  • Experience with Microsoft Graph API for data retrieval and automation.
  • In-depth knowledge of identity governance, authentication, and federation (MFA, SSO, PAM).
  • Knowledge of federation technologies (WS-Fed, OAuth, SAML).
  • Proven experience managing Active Directory 2016/2019/202x.

Responsibilities

  • Lead the evaluation, design, and development of AD & Azure AD requirements and implementation roadmap to ensure secure, reliable, and cost-effective environments.
  • Develop and enforce IAM policies, standards, and procedures to ensure regulatory compliance and best practices.
  • Ensure continuous improvement of IAM security architecture by implementing emerging technologies and practices.
  • Provide guidance and risk analysis to global project and operational teams.
  • Translate requirements into architectural designs and influence deployment of core infrastructure components.
  • Maintain understanding of Entra ID and related core technologies.
  • Analyze current Azure AD environment and propose technical and operational improvements.
  • Maintain and optimize on-prem AD infrastructure (DNS, GPOs, domain controllers).
  • Implement MFA and security best practices across user accounts and devices.
  • Develop and manage Graph API integrations and automation; create PowerShell scripts for provisioning and reporting.

Skills

Active Directory
Azure Active Directory
IAM
MFA
Microsoft Graph API
PowerShell
Security Architecture
AD/Entra ID

Tools

Microsoft Graph API
PowerShell

Job description

Security Architect - AD/Entra ID (Remote in the US)

Remote

GuidePoint Security provides trusted cybersecurity expertise, solutions and services that help organizations make better decisions and minimize risk. By taking a three-tiered, holistic approach for evaluating security posture and ecosystems, GuidePoint enables some of the nation’s top organizations, such as Fortune 500 companies and U.S. government agencies, to identify threats, optimize resources and integrate best‑fit solutions that mitigate risk.

General Description

We are seeking a highly experienced Security Architect (AD/Entra ID) to join our dynamic team and lead our identity and access management initiatives. The Security Architect will be responsible for the scope, assessment, design, testing, and technical documentation for the implementation, support, and security of identity solutions. The Security Architect will possess and maintain expertise in Microsoft Azure AAD (Entra) and Active Directory platforms utilizing the knowledge to address business requirements.

About the Active Directory/Entra ID Practice

Our team focuses on Securing Microsoft Identities, which includes both on‑prem Active Directory and Entra ID. We partner with other Identity teams, threat assessment teams, and Cloud Security teams to cover IGA, PAM, IAM, AM, pen testing, and all areas within Microsoft on‑prem AD and Entra ID.

  • Active Directory and Entra ID Security Assessments and Remediations
  • Active Directory Engineering (Domain consolidations, mergers and acquisitions, domain designs, Group Policy, CIS benchmarks, etc.)
  • Entra ID Identity design, troubleshooting, implementation

Roles and Responsibilities:

  • Lead the evaluation, design, and development of Active Directory & Azure Active Directory technical requirements, solutions, and implementation roadmap to ensure functional, reliable, secure, and cost-effective technology environment.
  • Develop and enforce IAM policies, standards, and procedures to ensure compliance with regulatory requirements and industry best practices.
  • Ensure continuous improvement within the IAM security architecture by introducing and implementing emerging security technologies and practices.
  • Provide to global project and operational teams technical advice, guidance, expertise, and risk analysis on your area of expertise.
  • Translate requirements into an Architectural design and influence the deployment of key infrastructure components.
  • Maintain a thorough understanding of existing and emerging Microsoft Entra ID and related core technologies.
  • Analyze current Azure Active Directory environment to identify both technical and operational challenges while making recommendations and developing solutions for improvement.
  • Maintain and optimize on‑premises Active Directory (AD) infrastructure, including DNS, GPOs, and domain controllers.
  • Participate in or lead complex or high severity troubleshooting and incident/problem resolutions with other infrastructure teams.
  • Evaluate and ensure the resolution of technically complex security issues, internal control issues, critical incidents and/or crisis resolution management, escalating as necessary.
  • Implement and enforce Multi‑Factor Authentication (MFA) and security best practices across user accounts and devices.
  • Develop and manage integrations using the Microsoft Graph API for automation and custom applications, enabling advanced capabilities across Microsoft 365 services.
  • Create custom scripts to automate administrative tasks and data retrieval from the Graph API, enhancing operational efficiency.
  • Write and maintain Advanced PowerShell scripts to automate user and resource provisioning, reporting, and service configurations across Entra ID and Active Directory.
  • Implement and maintain security best practices.

Required Experience and Education:

  • 10+ years of relevant working experience in IT Security and IT Architecture
  • 7+ years of experience with Active Directory architecture and infrastructure, with an in-depth understanding of Active Directory Replication, DNS, Site Links, Site Topology, Group Policy, Global Catalogs, and other core infrastructure components.
  • 3+ years of experience with Azure Active Directory architecture and design
  • 5+ years of experience with Identity and Access Management (IAM) processes and technologies
  • Proven expertise in designing and implementing IAM solutions in complex environments.
  • Expertise in managing Azure AD/Entra, including Conditional Access, MFA, security best practices, hybrid environments, GPO's, On‑Premises Active Directory Migrations and Azure AD Connect.
  • Experience with Microsoft Graph API for data retrieval and automation across Azure AAD.
  • In‑depth knowledge of identity governance, authentication, authorization, and federation. Including MFA, SSO and PAM
  • Understanding of federation technologies (WS‑Fed, OAuth, SAML, etc.)
  • Proven knowledge in managing Active Directory 2016/2019/202
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Remote AD/Entra ID Security Architect & IAM Expert
Remote AD/Entra ID Security Architect & IAM Expert

GuidePoint Security LLC • Polska

Hybrid
PLN 548,000 - 743,000
Microsoft Security Engineer- Remote (Anywhere in the U.S.)
Microsoft Security Engineer- Remote (Anywhere in the U.S.)

GuidePoint Security LLC • Polska

Hybrid
PLN 469,000 - 587,000
Cyber Security Domain Architect
Cyber Security Domain Architect

Jobgether SRL • Polska

On-site
PLN 230,000 - 340,000
Fully remote work
Lead Azure AI Security Engineer
Lead Azure AI Security Engineer

EPAM • Poland

On-site
PLN 85,000 - 110,000
Microsoft Security Engagement Lead- Remote (Anywhere in the U.S.)
Microsoft Security Engagement Lead- Remote (Anywhere in the U.S.)

GuidePoint Security LLC • Polska

Hybrid
PLN 548,000 - 822,000
Remote workforce
Group Medical Insurance
Dental Insurance
+2
Entra ID Architect
Entra ID Architect

Softeta • Kraków

Hybrid
PLN 180,000 - 280,000
Flexible hours
Hybrid/Remote work
Personal equipment
Remote Microsoft Entra ID Security Engineer
Remote Microsoft Entra ID Security Engineer

GuidePoint Security LLC • Polska

Hybrid
PLN 469,000 - 587,000
Identity Fabric Principal in support of IAM Services (Warsaw)
Identity Fabric Principal in support of IAM Services (Warsaw)

Cronos Europa • Poland

On-site
PLN 296,359 - 381,033
SecOps Security Architect - North Central region (Remote in the U.S.)
SecOps Security Architect - North Central region (Remote in the U.S.)

GuidePoint Security LLC • Polska

Hybrid
PLN 548,000 - 704,000
Cyber Security Domain Architect
Cyber Security Domain Architect

Jobgether SRL • Polska

Remote
PLN 180,000 - 280,000
Fully remote
Strategic impact
Azure/VMware exposure
+5