Principal Microsoft Solutions Architect at Progrite Systems Inc

Wayne State University

Seattle, Northern (WA, KY)

Hybrid

USD 150,000 - 195,000

Full time

4 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Wayne State University seeks a Principal Microsoft Solutions & Platform Architect to drive enterprise identity, security, and endpoint modernization across Entra ID, Intune, Autopilot, and Zero Trust initiatives.

This hybrid Seattle-area role combines hands-on engineering with enterprise architecture to roadmap migrations from Hybrid AD to Entra Join, implement cloud Kerberos, and strengthen secure access.

Qualifications

  • 8+ years of Microsoft infrastructure engineering experience.
  • 5+ years in Microsoft Identity and 5+ years in Microsoft 365 administration and architecture.
  • 5+ years of hands-on Intune and endpoint engineering, with enterprise transformation experience.
  • Experience in regulated/compliance-driven environments with security governance.

Responsibilities

  • Lead enterprise-wide initiatives to modernize identity, including Entra-first strategy and migration planning.
  • Define and execute passwordless authentication, and Windows Hello for Business implementations.
  • Lead Intune transformation, GPO-to-Intune migrations, and CIS benchmarks enforcement.
  • Architect and implement Entra Join, Autopilot modernization, and cloud-based device provisioning.
  • Design secure access architectures including Entra Private/Public Access and monitoring.
  • Develop automation and engineering practices with PowerShell and Graph APIs.

Skills

Entra ID
Identity governance
PIM
Intune
Autopilot
Entra Join
Hybrid AD
Zero Trust
Windows Hello
Cloud Kerberos

Tools

Intune
Autopilot
Entra ID
Azure AD
Microsoft Graph
PowerShell

Job description

You are viewing a preview of this job. Log in or register to view more details about this job.

Job Title: Principal Microsoft Solutions & Platform Architect
Location: Seattle, WA – Hybrid
Type: C2H (6 Months)

Position Summary:
The Principal Microsoft Identity & Platform Engineer serves as the organization's technical authority for Microsoft Identity, Security, Endpoint Management, and Zero Trust architecture. This role will lead the design, engineering, deployment, and operational maturity of Microsoft Entra ID, Identity Governance, Policies, Intune, Windows Autopilot, Defender, Global Secure Access, and Microsoft 365 security/E5 capabilities.
The ideal candidate combines deep hands‑on engineering expertise with enterprise architecture capabilities and has successfully delivered complex identity transformations including Active Directory modernization, password less authentication, cloud‑first endpoint management, and Zero Trust initiatives. This individual will partner closely with Technology Operations, Information Security, Infrastructure, Compliance, Service Desk, and business stakeholders to develop and execute Trupanion's Microsoft platform roadmap.
This position is open to candidates in the Seattle area. You will have a hybrid remote/in‑office schedule where you will work from our casual, pet‑friendly office at least 3 days a week. Remote for right candidate

Responsibilities
Identity Modernization
  • Lead enterprise‑wide initiatives to reduce dependency on traditional Active Directory, identify legacy dependencies, and establish a phased roadmap toward a modern, cloud‑first identity environment.
  • Develop and execute an Entra‑first identity architecture strategy, defining the target‑state architecture, migration approach, security controls, governance model, and operational standards.
  • Develop and execute strategies to eliminate, remediate, or modernize legacy authentication dependencies, including applications relying on traditional AD, LDAP, Kerberos, or other legacy authentication mechanisms.
  • Lead ADFS retirement planning and execution, including dependency discovery, application remediation, authentication modernization, testing, phased migration, and final decommissioning.
  • Define standards for identity synchronization, provisioning, deprovisioning, directory architecture, and identity lifecycle management.
  • Develop migration roadmaps for transitioning from Hybrid Entra Join to Entra Join, while addressing dependencies that require continued on‑premises identity services.
Authentication & Access Management
  • Define and execute the organization's password‑less authentication strategy
  • Design and implement Windows Hello for Business and Cloud Kerberos Trust architecture.
  • Establish phishing‑resistant authentication standards aligned with Zero Trust and modern identity security practices.
  • Define authentication lifecycle standards covering enrollment, authentication, recovery, credential management, and deprovisioning.
Endpoint Modernization
  • Lead Microsoft Intune transformation initiatives and define cloud‑first endpoint management standards.
  • Drive GPO‑to‑Intune migration programs, including policy assessment, redesign, testing, and phased deployment.
  • Implement CIS benchmark and security baseline controls through Intune to strengthen endpoint security and compliance.
  • Modernize Windows deployment, provisioning, and device lifecycle management, including enrollment, configuration, maintenance, and retirement standards.
Entra Join & Autopilot Transformation
  • Lead the transition from Hybrid AD Join to Entra Join, developing migration strategies that minimize business disruption and legacy dependencies.
  • Architect and implement Windows Autopilot modernization initiatives to enable scalable, automated, and cloud‑first device provisioning.
  • Design standardized device deployment, enrollment, and provisioning processes across Intune, Entra ID, and Autopilot.
  • Implement Cloud Kerberos Trust and eliminate legacy dependencies that prevent modern Entra Join and cloud‑based endpoint deployments.
Secure Access Architecture
  • Lead evaluation of Microsoft Global Secure Access.
  • Design Entra Private Access architecture.
  • Design Entra Internet Access architecture.
  • Develop coexistence and migration strategies from Zscaler.
  • Conduct proof‑of‑concept testing.
  • Create migration roadmaps and operational support models.
Identity Governance
  • Evaluate and implement Entra Identity Governance capabilities.
  • Design Joiner‑Mover‑Leaver workflows.
  • Develop automated access certification processes.
  • Integrate identity lifecycle management with HR systems.
  • Improve role‑based access governance and compliance.
Automation & Engineering
  • Develop PowerShell automation solutions.
  • Utilize Microsoft Graph APIs.
  • Automate provisioning and reporting.
  • Reduce operational overhead through engineering practices.
  • Build self‑service capabilities for users and support teams.
Required Qualifications
  • 8+ years of Microsoft infrastructure engineering experience, including 5+ years in Microsoft Identity and 5+ years in Microsoft 365 administration and architecture.
  • 5+ years of hands‑on Intune and endpoint engineering, with demonstrated experience leading enterprise transformation programs and designing Zero Trust architectures.
  • Experience working in regulated or compliance‑driven environments, with strong understanding of security, governance, and risk management requirements.
  • Proven ability to lead complex Microsoft modernization initiatives, with strong cross‑functional collaboration and technical leadership skills.
Preferred Microsoft Certifications
  • Microsoft Certified: Identity and Access Administrator Associate
  • Microsoft Certified: Cybersecurity Architect Expert
  • Microsoft Certified: Endpoint Administrator Associate
  • Microsoft Certified: Azure Solutions Architect Expert (AZ-305)
Skills

Microsoft Entra ID, Conditional Access, Identity governance, PIM, Cloud sync, Entra connect, ADFS, SSO, MFA, Authentication flow.

Microsoft Intune, Autopilot, Entra join, hybrid join, Windows update for business, CIS benchmarks, GPO migration

GSA, Entra Private Access, Entra Internet Access, Private Application Access

Powershell, Microsoft Graph, REST APIs, Azure Automation

Independent technical ownership, mentoring, cross‑functional collaboration, and clear communication with technical and non‑technical audiences

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Solutions Architect - AD/Entra Architect
Solutions Architect - AD/Entra Architect

Texas Instruments • Dallas (TX)

On-site
USD 140,000 - 200,000
Solutions Architect - AD/Entra Architect
Solutions Architect - AD/Entra Architect

Texas Instruments Incorporated • Dallas (TX), Northern (KY)

Hybrid
USD 140,000 - 190,000
Senior Identity Engineer (Cloud & Microsoft 365)
Senior Identity Engineer (Cloud & Microsoft 365)

Teledyne Technologies Incorporated • Stillwater (OK)

On-site
USD 110,000 - 170,000
Microsoft Identity & Platform Architect (Entra)
Microsoft Identity & Platform Architect (Entra)

Wayne State University • Seattle (WA), Northern (KY)

Hybrid
USD 150,000 - 195,000
Principal Enterprise Architect
Principal Enterprise Architect

Clarivate • Philadelphia

Hybrid
USD 180,000 - 240,000
Principal Enterprise Architect
Principal Enterprise Architect

Clarivate Analytics US LLC • Philadelphia

Hybrid
USD 180,000 - 240,000
Cloud Platform Architect
Cloud Platform Architect

Madison-Davis, LLC • New York (NY)

Hybrid
USD 140,000 - 200,000
Sr Entra ID Integration Engineer
Sr Entra ID Integration Engineer

Koniag Government Services • Washington

Hybrid
USD 140,000 - 190,000
Medical Insurance
Dental Insurance
Vision Insurance
+8
Workplace Engineer (P4) - Microsoft 365 and Entra Platform
Workplace Engineer (P4) - Microsoft 365 and Entra Platform

Chemical Abstracts Service • Columbus (OH)

On-site
USD 120,000 - 170,000
Hybrid: Microsoft Identity & Security Platform Architect
Hybrid: Microsoft Identity & Security Platform Architect

Trupanion • Seattle (WA)

Hybrid
USD 145,000 - 165,000
Medical, dental & vision benefits
4 weeks PTO + 9 float holidays
5-week sabbatical after 5 years
+2