Principal Microsoft Solutions & Platform Architect

Kalpita Technologies Inc

Seattle (WA)

Hybrid

USD 165,000 - 248,000

Part time

8 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Hybrid schedule
W2 employment
Pet-friendly office

Job summary

Kalpita Technologies Inc. seeks a Principal Microsoft Solutions & Platform Architect to lead organization-wide modernization of identity, security, and endpoint management.

You will own the Entra-first identity strategy, cloud-first device provisioning, and Zero Trust architecture, collaborating across Technology Operations, Security, and Compliance. The role requires deep hands-on engineering plus enterprise architecture experience, with a focus on modernization of Active Directory,

Qualifications

  • 8+ years of Microsoft infrastructure engineering experience, including 5+ years in Microsoft Identity and 5+ years in Microsoft 365 administration and architecture.
  • 5+ years of hands-on Intune and endpoint engineering, with experience leading enterprise transformation programs and Zero Trust architectures.
  • Experience in regulated or compliance-driven environments with strong security, governance and risk management understanding.
  • Proven ability to lead complex Microsoft modernization initiatives and excellent cross-functional collaboration.

Responsibilities

  • Lead enterprise-wide initiatives to modernize identity and reduce legacy dependencies.
  • Develop Entra-first identity architecture strategy and migration roadmaps.
  • Define and implement Windows Autopilot modernization and Intune transformation.
  • Architect Secure Access and Identity Governance capabilities and migration strategies.

Skills

Microsoft Entra ID
Identity governance
Intune
Zero Trust
PowerShell
Microsoft Graph
REST APIs

Education

Microsoft Certifications: Identity and Access Administrator Associate
Microsoft Certified: Cybersecurity Architect Expert
Microsoft Certified: Endpoint Administrator Associate
Microsoft Certified: Azure Solutions Architect Expert (AZ-305)

Tools

Microsoft Graph
PowerShell
Azure Automation
REST APIs

Job description

Job Title: Principal Microsoft Solutions & Platform Architect

Location: Seattle, WA Hybrid (Non-local profiles accepted)

Type: C2H (6 Months)

Visa Status: USC

Only on W2 Position Summary:

The Principal Microsoft Identity & Platform Engineer serves as the organization's technical authority for Microsoft Identity, Security, Endpoint Management, and Zero Trust architecture. This role will lead the design, engineering, deployment, and operational maturity of Microsoft Entra ID, Identity Governance, Policies, Intune, Windows Autopilot, Defender, Global Secure Access, and Microsoft 365 security/E5 capabilities.

The ideal candidate combines deep hands-on engineering expertise with enterprise architecture capabilities and has successfully delivered complex identity transformations including Active Directory modernization, password less authentication, cloud-first endpoint management, and Zero Trust initiatives. This individual will partner closely with Technology Operations, Information Security, Infrastructure, Compliance, Service Desk, and business stakeholders to develop and execute client Microsoft platform roadmap.

This position is open to candidates in the Seattle area. You will have a hybrid remote/in-office schedule where you will work from our casual, pet-friendly office at least 3 days a week. Remote for right candidate

Responsibilities:

Identity Modernization

  • Lead enterprise-wide initiatives to reduce dependency on traditional Active Directory, identify legacy dependencies, and establish a phased roadmap toward a modern, cloud-first identity environment.
  • Develop and execute an Entra-first identity architecture strategy, defining the target-state architecture, migration approach, security controls, governance model, and operational standards.
  • Develop and execute strategies to eliminate, remediate, or modernize legacy authentication dependencies, including applications relying on traditional AD, LDAP, Kerberos, or other legacy authentication mechanisms.
  • Lead ADFS retirement planning and execution, including dependency discovery, application remediation, authentication modernization, testing, phased migration, and final decommissioning.
  • Define standards for identity synchronization, provisioning, deprovisioning, directory architecture, and identity lifecycle management.
  • Develop migration roadmaps for transitioning from Hybrid Entra Join to Entra Join, while addressing dependencies that require continued on-premises identity services.

Authentication & Access Management

  • Define and execute the organization's password-less authentication strategy
  • Design and implement Windows Hello for Business and Cloud Kerberos Trust architecture.
  • Establish phishing-resistant authentication standards aligned with Zero Trust and modern identity security practices.
  • Define authentication lifecycle standards covering enrollment, authentication, recovery, credential management, and deprovisioning.

Endpoint Modernization

  • Lead Microsoft Intune transformationinitiatives and define cloud-first endpoint management standards.
  • Drive GPO-to-Intune migration programs, including policy assessment, redesign, testing, and phased deployment.
  • Implement CIS benchmark and security baseline controls through Intuneto strengthen endpoint security and compliance.
  • Modernize Windows deployment, provisioning, and device lifecycle management, including enrollment, configuration, maintenance, and retirement standards.

Entra Join & Autopilot Transformation

  • Lead the transition from Hybrid AD Join to Entra Join, developing migration strategies that minimize business disruption and legacy dependencies.
  • Architect and implement Windows Autopilot modernization initiativesto enable scalable, automated, and cloud-first device provisioning.
  • Design standardized device deployment, enrollment, and provisioning processesacross Intune, Entra ID, and Autopilot.
  • Implement Cloud Kerberos Trustand eliminate legacy dependencies that prevent modern Entra Join and cloud-based endpoint deployments.

Secure Access Architecture

  • Lead evaluation of Microsoft Global Secure Access.
  • Design Entra Private Access architecture.
  • Design Entra Internet Access architecture.
  • Develop coexistence and migration strategies from Zscaler.
  • Conduct proof-of-concept testing.
  • Create migration roadmaps and operational support models.

Identity Governance

  • Evaluate and implement Entra Identity Governance capabilities.
  • Design Joiner-Mover-Leaver workflows.
  • Develop automated access certification processes.
  • Integrate identity lifecycle management with HR systems.
  • Improve role-based access governance and compliance.

Automation & Engineering

  • Develop PowerShell automation solutions.
  • Utilize Microsoft Graph APIs.
  • Automate provisioning and reporting.
  • Reduce operational overhead through engineering practices.
  • Build self-service capabilities for users and support teams.

Required Qualifications

  • 8 years of Microsoft infrastructure engineering experience, including 5 years in Microsoft Identity and 5 years in Microsoft 365 administration and architecture.
  • 5 years of hands-on Intune and endpoint engineering , with demonstrated experience leading enterprise transformation programs and designing Zero Trust architectures.
  • Experience working in regulated or compliance-driven environments, with strong understanding of security, governance, and risk management requirements.
  • Proven ability to lead complex Microsoft modernization initiatives, with strong cross-functional collaboration and technical leadership skills.
  • Preferred Microsoft Certifications:
  • Microsoft Certified: Identity and Access Administrator Associate
  • Microsoft Certified: Cybersecurity Architect Expert
  • Microsoft Certified: Endpoint Administrator Associate
  • Microsoft Certified: Azure Solutions Architect Expert (AZ-305)

Skills

  • Microsoft Entra ID, Conditional Access, Identity governance, PIM, Cloud sync, Entra connect, ADFS, SSO, MFA, Authentication flow.
  • Microsoft Intune, Autopilot, Entra join, hybrid join, Windows update for business, CIS benchmarks, GPO migration
  • GSA, Entra Private Access, Entra Internet Access, Private Application Access
  • Powershell, Microsoft Graph, REST APIs, Azure Automation
  • Independent technical ownership, mentoring, cross-functional collaboration, and clear communication with technical and non-technical audiences
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Solutions Architect - AD/Entra Architect
Solutions Architect - AD/Entra Architect

118-WW TMG MFG OPS • Dallas (TX)

On-site
USD 150,000 - 190,000
Identity & Access Management Architect
Identity & Access Management Architect

Ellaway Blues Consulting • United States

On-site
USD 140,000 - 190,000
Senior Cloud Engineer
Senior Cloud Engineer

Jobtailor • Alabama

On-site
USD 110,000 - 160,000
Manager, Digital Identity
Manager, Digital Identity

Jobtailor • Chicago (IL)

On-site
USD 130,000 - 180,000
Healthcare
401(k) matching
Professional development
Senior Microsoft 365 Systems Engineer / Architect
Senior Microsoft 365 Systems Engineer / Architect

Ledgent Technology • Irvine (CA)

Hybrid
USD 90,000 - 103,000
Associate Manager, Digital Identity
Associate Manager, Digital Identity

Jobtailor • Illinois

On-site
USD 120,000 - 180,000
Microsoft Entra ID Architect
Microsoft Entra ID Architect

KeyData Cyber • United States

Remote
USD 124,000 - 207,000
Modern Workplace Engineer
Modern Workplace Engineer

Franklin Fitch • United States

On-site
USD 110,000 - 140,000
Entra ID – AD Architect
Entra ID – AD Architect

Jobtailor • Austin (TX)

On-site
USD 150,000 - 190,000
Microsoft 365 Architect
Microsoft 365 Architect

Greenstone Partners Global • United States

On-site
USD 140,000 - 190,000