Principal Technical Consultant - Identity Focused Security Architect

Security EngineerSecurity EngineerFull TimeRemoteTeam 1,154Since 2007Company Site

Location

United States

Posted

5 days ago

Salary

Not specified

Active DirectoryEntra IDMicrosoft IdentityIGASSOMFAPasswordlessRBACABACPBACOktaPAMIdentity ArchitectureAuthenticationAuthorizationPower ShellPython

Job Description

This description is a summary of our understanding of the job description. Click on 'Apply' button to find out more.

Role Description

The Principal Technical Consultant (PTC) Identity Focused Security Architect is a hands-on delivery leader who designs and leads identity solution implementations in client environments. This role is not purely advisory. You will own identity workstreams end to end, driving architecture, implementation planning, execution oversight, and stakeholder alignment, primarily across Microsoft identity (Active Directory and Entra ID), IGA, and modern authentication patterns (SSO, MFA, passwordless). Experience with other IAM platforms (e.g., Okta) is a strong plus, and PAM experience is a plus as well.

  • Identity architecture and implementation leadership
  • Lead identity workstreams from discovery and current state analysis through target state architecture, implementation planning, delivery oversight, and closeout.
  • Design and deliver Microsoft identity solutions with a deep focus on Active Directory and Microsoft Entra ID, including hybrid identity patterns where applicable.
  • Drive the technical approach for modern authentication and federation capabilities, including SSO, MFA, and passwordless.
  • Identity Governance and Administration (IGA) delivery
  • Lead and or execute IGA-focused deliverables such as:
    • Joiner mover-leaver lifecycle processes
    • Provisioning and deprovisioning patterns
    • Access request workflows where applicable
    • Role and policy model improvement to reduce risk and increase operational clarity
    • Access control model design
  • Apply and communicate access control methodologies, including RBAC, ABAC, and PBAC, translating business requirements into implementable identity and authorization designs.
  • Client-facing consulting and execution
  • Own day-to-day technical leadership with clients: requirements sessions, whiteboarding, design reviews, implementation coordination, and executive-ready communication.
  • Coordinate delivery across client stakeholders (engineering teams through senior security leaders) to align on priorities, sequencing, and execution plans.
  • Produce clear, high-quality deliverables (architecture diagrams, implementation plans, runbooks, and decision documentation).

Qualifications

  • Strong Microsoft identity architecture and implementation experience, especially Active Directory and Entra ID.
  • Hands-on IGA knowledge and delivery experience in real client environments.
  • Strong understanding of access control methodologies: RBAC, ABAC, PBAC.
  • Strong authentication expertise: SSO, MFA, passwordless, with design and implementation level understanding.
  • Demonstrated ability to lead implementation, not just advise: planning, execution oversight, and delivery ownership.
  • Proven client-facing consulting capability: stakeholder management, clear communication, and whiteboard-ready technical leadership.

Requirements

  • Support implementations or integrations with other IAM platforms (Okta or comparable solutions).
  • Contribute to or support PAM initiatives (Privileged Access Management), such as privileged access workflows, vaulting patterns, and privileged lifecycle controls, when in scope.

Preferred Qualifications

  • Experience implementing or supporting Okta or similar IAM platforms.
  • PAM experience (Privileged Access Management).
  • Scripting or automation exposure (PowerShell, Python) to support identity integrations and operationalization.

Benefits

  • Medical, Dental, and Vision Insurance
  • 401(k)
  • Paid company holidays
  • Paid time off
  • Paid parental and caregiver leave
  • Plus more! See benefits here for additional details.

Compensation

$200,000 - $230,000 a year. The compensation range indicated in this posting reflects the On-Target Earnings (“OTE”) for this role, which includes a base salary and any applicable target bonus amount. This OTE range may vary based on the candidate’s relevant experience, qualifications, and geographic location.

Job Requirements

  • Strong Microsoft identity architecture and implementation experience, especially Active Directory and Entra ID.
  • Hands-on IGA knowledge and delivery experience in real client environments.
  • Strong understanding of access control methodologies: RBAC, ABAC, PBAC.
  • Strong authentication expertise: SSO, MFA, passwordless, with design and implementation level understanding.
  • Demonstrated ability to lead implementation, not just advise: planning, execution oversight, and delivery ownership.
  • Proven client-facing consulting capability: stakeholder management, clear communication, and whiteboard-ready technical leadership.
  • Support implementations or integrations with other IAM platforms (Okta or comparable solutions).
  • Contribute to or support PAM initiatives (Privileged Access Management), such as privileged access workflows, vaulting patterns, and privileged lifecycle controls, when in scope.
  • Preferred Qualifications
  • Experience implementing or supporting Okta or similar IAM platforms.
  • PAM experience (Privileged Access Management).
  • Scripting or automation exposure (PowerShell, Python) to support identity integrations and operationalization.

Benefits

  • Medical, Dental, and Vision Insurance
  • 401(k)
  • Paid company holidays
  • Paid time off
  • Paid parental and caregiver leave
  • Plus more! See benefits here for additional details.
  • Compensation
  • $200,000 - $230,000 a year. The compensation range indicated in this posting reflects the On-Target Earnings (“OTE”) for this role, which includes a base salary and any applicable target bonus amount. This OTE range may vary based on the candidate’s relevant experience, qualifications, and geographic location.

Related Categories

Related Job Pages

More Security Engineer Jobs

Principal Product Security Architect

Lumen Technologies

Lumen connects the world. We are igniting business growth by connecting people, data and applications – quickly, securely, and effortlessly. Together, we are building a culture and company from the people up – committed to teamwork, trust and transparency. People power progress. We’re looking for top-tier talent and offer the flexibility you need to thrive and deliver lasting impact. Join us as we digitally connect the world and shape the future. Background Screening If you are selected for a position, there will be a background screen, which may include checks for criminal records and/or motor vehicle reports and/or drug screening, depending on the position requirements. Equal Employment Opportunities We are committed to providing equal employment opportunities to all persons regardless of race, color, ancestry, citizenship, national origin, religion, veteran status, disability, genetic characteristic or information, age, gender, sexual orientation, gender identity, gender expression, marital status, family status, pregnancy, or other legally protected status (collectively, “protected statuses”). We do not tolerate unlawful discrimination in any employment decisions, including recruiting, hiring, compensation, promotion, benefits, discipline, termination, job assignments or training. Disclaimer The job responsibilities described above indicate the general nature and level of work performed by employees within this classification. It is not intended to include a comprehensive inventory of all duties and responsibilities for this job. Job duties and responsibilities are subject to change based on evolving business needs and conditions.

Security Engineer5 days ago
Full TimeRemoteTeam 10,001

This senior technical leadership role is responsible for researching, designing, prototyping, and operationalizing advanced security solutions for Lumen’s Managed and Professional Security Services portfolio. The architect will drive innovation to create market-ready cybersecurity offerings supporting the end-to-end lifecycle from design through SOC operations.

Security architectureSOC operationsSIEMSOARMDRXDRNGFWVulnerability managementCASBSASEThreat intelligenceCloud securityAutomationOrchestrationNISTPCI-DSSHIPAACISSP
United States
$152K - $223K / year

Security Consultant

Tenable

Cloud Security | Operational Technology | Identity Security | and more

Security Engineer5 days ago
ContractRemoteTeam 1,001-5,000Since 2002H1B Sponsor

The Security Consultant plays a key role in implementing and enabling Tenable’s Exposure Management solutions to help organizations effectively manage and reduce cyber risks. This role onboards Tenable technologies, following industry standards and best practices, to deliver cust...

United States + 144 moreAll locations: United States, Canada, Brazil, Colombia, Argentina, Chile, Venezuela, Bolivarian Republic Of, Bolivia, Plurinational State Of, Ecuador, French Guiana, Guyana, Paraguay, Peru, Suriname, Uruguay, Mexico, Costa Rica, El Salvador, Guatemala, Honduras, Nicaragua, Panama, Dominican Republic, Puerto Rico, Bahamas, Guadeloupe, Haiti, Jamaica, Martinique, Montserrat, United Kingdom, Germany, France, Estonia, Portugal, Hungary, Poland, Ukraine, Romania, Bulgaria, Czech Republic, Slovakia, Belarus, Moldova, Republic Of, Sweden, Greece, Belgium, Italy, Ireland, Switzerland, Netherlands, Finland, Malta, Denmark, Lithuania, Croatia, Spain, Austria, Bosnia And Herzegovina, Iceland, Luxembourg, Macedonia, The Former Yugoslav Republic Of, Montenegro, Norway, Serbia, Slovenia, Albania, Cyprus, Latvia, Monaco, South Africa, Egypt, Algeria, Angola, Benin, Botswana, Burkina Faso, Burundi, Cameroon, Cape Verde, Central African Republic, Chad, Congo, Côte D'ivoire, Congo, The Democratic Republic Of The, Equatorial Guinea, Eritrea, Ethiopia, Gabon, Gambia, Ghana, Guinea, Guinea-bissau, Kenya, Lesotho, Liberia, Libyan Arab Jamahiriya, Madagascar, Malawi, Mali, Mauritania, Mauritius, Mayotte, Morocco, Mozambique, Namibia, Niger, Nigeria, Réunion, Rwanda, Senegal, Seychelles, Sierra Leone, Somalia, Sudan, Swaziland, Tanzania, United Republic Of, Togo, Tunisia, Uganda, Zambia, Zimbabwe, Georgia, Turkey, Israel, United Arab Emirates, Armenia, Azerbaijan, Bahrain, Iraq, Jordan, Kuwait, Lebanon, Oman, Qatar, Saudi Arabia, Palestinian Territory, Occupied, Yemen

Senior Corporate Security Engineer

ServiceTitan

The operating system for the trades

Security Engineer5 days ago
Full TimeRemoteTeam 1,001-5,000Since 2012H1B Sponsor

Lead security initiatives for SaaS, endpoints, and identity management at ServiceTitan.

Python
United States
$125.7K - $168.1K / year

SAP Security Specialist

CACI International Inc

Expertise and Technology for National Security

Security Engineer5 days ago
Full TimeRemoteTeam 10,001+Since 1962H1B No Sponsor

SAP Security Specialist supporting modernization for NASA

United States
$90.3K - $189.6K / year