Principal Technical Consultant - Identity Focused Security Architect
Location
United States
Posted
5 days ago
Salary
Not specified
Job Description
Role Description
The Principal Technical Consultant (PTC) Identity Focused Security Architect is a hands-on delivery leader who designs and leads identity solution implementations in client environments. This role is not purely advisory. You will own identity workstreams end to end, driving architecture, implementation planning, execution oversight, and stakeholder alignment, primarily across Microsoft identity (Active Directory and Entra ID), IGA, and modern authentication patterns (SSO, MFA, passwordless). Experience with other IAM platforms (e.g., Okta) is a strong plus, and PAM experience is a plus as well.
- Identity architecture and implementation leadership
- Lead identity workstreams from discovery and current state analysis through target state architecture, implementation planning, delivery oversight, and closeout.
- Design and deliver Microsoft identity solutions with a deep focus on Active Directory and Microsoft Entra ID, including hybrid identity patterns where applicable.
- Drive the technical approach for modern authentication and federation capabilities, including SSO, MFA, and passwordless.
- Identity Governance and Administration (IGA) delivery
- Lead and or execute IGA-focused deliverables such as:
- Joiner mover-leaver lifecycle processes
- Provisioning and deprovisioning patterns
- Access request workflows where applicable
- Role and policy model improvement to reduce risk and increase operational clarity
- Access control model design
- Apply and communicate access control methodologies, including RBAC, ABAC, and PBAC, translating business requirements into implementable identity and authorization designs.
- Client-facing consulting and execution
- Own day-to-day technical leadership with clients: requirements sessions, whiteboarding, design reviews, implementation coordination, and executive-ready communication.
- Coordinate delivery across client stakeholders (engineering teams through senior security leaders) to align on priorities, sequencing, and execution plans.
- Produce clear, high-quality deliverables (architecture diagrams, implementation plans, runbooks, and decision documentation).
Qualifications
- Strong Microsoft identity architecture and implementation experience, especially Active Directory and Entra ID.
- Hands-on IGA knowledge and delivery experience in real client environments.
- Strong understanding of access control methodologies: RBAC, ABAC, PBAC.
- Strong authentication expertise: SSO, MFA, passwordless, with design and implementation level understanding.
- Demonstrated ability to lead implementation, not just advise: planning, execution oversight, and delivery ownership.
- Proven client-facing consulting capability: stakeholder management, clear communication, and whiteboard-ready technical leadership.
Requirements
- Support implementations or integrations with other IAM platforms (Okta or comparable solutions).
- Contribute to or support PAM initiatives (Privileged Access Management), such as privileged access workflows, vaulting patterns, and privileged lifecycle controls, when in scope.
Preferred Qualifications
- Experience implementing or supporting Okta or similar IAM platforms.
- PAM experience (Privileged Access Management).
- Scripting or automation exposure (PowerShell, Python) to support identity integrations and operationalization.
Benefits
- Medical, Dental, and Vision Insurance
- 401(k)
- Paid company holidays
- Paid time off
- Paid parental and caregiver leave
- Plus more! See benefits here for additional details.
Compensation
$200,000 - $230,000 a year. The compensation range indicated in this posting reflects the On-Target Earnings (“OTE”) for this role, which includes a base salary and any applicable target bonus amount. This OTE range may vary based on the candidate’s relevant experience, qualifications, and geographic location.
Job Requirements
- Strong Microsoft identity architecture and implementation experience, especially Active Directory and Entra ID.
- Hands-on IGA knowledge and delivery experience in real client environments.
- Strong understanding of access control methodologies: RBAC, ABAC, PBAC.
- Strong authentication expertise: SSO, MFA, passwordless, with design and implementation level understanding.
- Demonstrated ability to lead implementation, not just advise: planning, execution oversight, and delivery ownership.
- Proven client-facing consulting capability: stakeholder management, clear communication, and whiteboard-ready technical leadership.
- Support implementations or integrations with other IAM platforms (Okta or comparable solutions).
- Contribute to or support PAM initiatives (Privileged Access Management), such as privileged access workflows, vaulting patterns, and privileged lifecycle controls, when in scope.
- Preferred Qualifications
- Experience implementing or supporting Okta or similar IAM platforms.
- PAM experience (Privileged Access Management).
- Scripting or automation exposure (PowerShell, Python) to support identity integrations and operationalization.
Benefits
- Medical, Dental, and Vision Insurance
- 401(k)
- Paid company holidays
- Paid time off
- Paid parental and caregiver leave
- Plus more! See benefits here for additional details.
- Compensation
- $200,000 - $230,000 a year. The compensation range indicated in this posting reflects the On-Target Earnings (“OTE”) for this role, which includes a base salary and any applicable target bonus amount. This OTE range may vary based on the candidate’s relevant experience, qualifications, and geographic location.
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Principal Product Security Architect
Lumen TechnologiesLumen connects the world. We are igniting business growth by connecting people, data and applications – quickly, securely, and effortlessly. Together, we are building a culture and company from the people up – committed to teamwork, trust and transparency. People power progress. We’re looking for top-tier talent and offer the flexibility you need to thrive and deliver lasting impact. Join us as we digitally connect the world and shape the future. Background Screening If you are selected for a position, there will be a background screen, which may include checks for criminal records and/or motor vehicle reports and/or drug screening, depending on the position requirements. Equal Employment Opportunities We are committed to providing equal employment opportunities to all persons regardless of race, color, ancestry, citizenship, national origin, religion, veteran status, disability, genetic characteristic or information, age, gender, sexual orientation, gender identity, gender expression, marital status, family status, pregnancy, or other legally protected status (collectively, “protected statuses”). We do not tolerate unlawful discrimination in any employment decisions, including recruiting, hiring, compensation, promotion, benefits, discipline, termination, job assignments or training. Disclaimer The job responsibilities described above indicate the general nature and level of work performed by employees within this classification. It is not intended to include a comprehensive inventory of all duties and responsibilities for this job. Job duties and responsibilities are subject to change based on evolving business needs and conditions.
This senior technical leadership role is responsible for researching, designing, prototyping, and operationalizing advanced security solutions for Lumen’s Managed and Professional Security Services portfolio. The architect will drive innovation to create market-ready cybersecurity offerings supporting the end-to-end lifecycle from design through SOC operations.
The Security Consultant plays a key role in implementing and enabling Tenable’s Exposure Management solutions to help organizations effectively manage and reduce cyber risks. This role onboards Tenable technologies, following industry standards and best practices, to deliver cust...
Lead security initiatives for SaaS, endpoints, and identity management at ServiceTitan.
SAP Security Specialist supporting modernization for NASA