Talent.com
Senior Architect, Identity & Security
Senior Architect, Identity & SecurityWest Monroe • Chicago, Illinois, USA
Senior Architect, Identity & Security

Senior Architect, Identity & Security

West Monroe • Chicago, Illinois, USA
9 days ago
Job type
  • Full-time
Job description

Are you ready to make an impact

West Monroe is seeking a Senior Architect Identity & Security to lead cross-functional teams in the design remediation and modernization of complex identity and cloud infrastructure solutions. This role focuses on securing and transforming critical IT environments for a diverse portfolio of clients helping them navigate complex Active Directory modernizations cloud identity migrations and security hardening initiatives. This opportunity provides technical leadership in transforming complex IT environments across key industry verticals including Healthcare Financial Services Private Equity and High Tech. While the scope spans hybrid and cloud identity the work is particularly grounded in Active Directory as a core Tier 0 platform with strong Microsoft Entra ID expertise to design and operate modern hybrid identity patterns.

Responsibilities :

  • Partner with consultants and client leadership to architect build and deploy secure and modern Active Directory and Microsoft Entra ID solutions .
  • Assess current-state identity environments and processes interview stakeholders define critical requirements and present practical solution strategies and roadmaps to client executives.
  • Lead the technical design of future-state Active Directory (AD DS) and Entra ID architectures including privileged access management (PAM) design tiered administrative access models (e.g. Microsofts Enterprise Access Model (EAM) and identity consolidation strategies.
  • Establish and enforce identity architecture standards best practices and governance to deliver secure compliant and consistent solutions aligned with industry benchmarks (e.g. CIS and Microsoft baselines) .
  • Lead security assessment and remediation planning including consolidating findings from tools (e.g. Purple Knight Maester CIS Benchmark-based configuration assessments (e.g. CIS-CAT) ) to create and manage prioritized risk-based remediation backlogs.
  • Provide expert technical oversight for security remediation initiatives such as hardening domain controllers remediating privileged access resolving Entra Connect sync issues and restricting legacy protocols.
  • Develop detailed implementation plans migration strategies and remediation backlogs (e.g. in Smartsheet or similar project management tools) for AD restructuring AD consolidation identity synchronization and legacy decommissioning.
  • Establish and manage engagement-level governance quality and risk including defining quantitative success criteria RACI and clear communications to both technical and executive stakeholders.
  • Support key decision-making on project direction including technology selections team workstreams and delivery methodologies.
  • Mentor junior consultants on technical best practices solution design and client engagement.
  • Assist business development efforts through proposals pre-sales technical discovery and client presentations.

Qualifications :

  • Bachelors degree in a relevant field preferred or equivalent experience required.
  • Prior experience in consulting preferred.
  • 812 years of experience in IT architecture engineering and / or security with a deep focus on identity solutions.
  • Expert-level knowledge of Active Directory Domain Services (AD DS) design security and administration including : domain / forest architecture sites / replication DNS Group Policy (GPO) management DC virtualization safeguards and forest recovery principles.
  • Strong experience with Microsoft Entra ID (formerly Azure AD) including Entra Connect Conditional Access modern authentication methods and Privileged Identity Management (PIM).
  • Proven experience leading identity migrations (including on-premises to cloud cross-forest restructurings and Tenant-to-Tenant (cross-tenant) consolidations) AD remediations and / or consolidation projects.
  • Experience designing and implementing hybrid authentication patterns between AD DS and Microsoft Entra ID including pass-through authentication (PTA) Seamless SSO Cloud Kerberos Trust and phishing-resistant authentication methods.
  • Proficiency in designing and implementing enterprise Privileged Access Management (PAM) solutions (including typical platforms like CyberArk Delinea or similar) and t iered administrative access models (e.g. Tier 0 / 1 / 2 Microsofts Enterprise Access Model (EAM)) .
  • Hands-on experience with Active Directory and Microsoft Entra ID security assessment and testing tools (e.g. Purple Knight PingCastle Maester Microsoft Defender for Identity or similar AD threat detection platforms) and hardening methodologies (e.g. CIS Benchmarks and Microsoft security baselines).
  • Proficiency with AD security hardening techniques such as KRBTGT password rotations restricting NTLM Group Policy object ( GPO ) cleanup Local Administrator Password Solution (LAPS) implementing resource-based Kerberos constrained delegation (RBKCD) and configuring LDAP signing.
  • Familiarity with migration and directory protection tools (e.g. Quest On-Demand Migration) and identity-driven application dependencies.
  • Strong communication (written and verbal) presentation client management and team leadership skills.
  • Willingness to travel for out-of-town client engagements.
  • Nice to have :

  • Familiarity with compliance standards (e.g. NIST HIPAA ISO).
  • Advanced scripting for automation and analysis (e.g. PowerShell ).
  • Knowledge of Infrastructure as Code (Terraform) and DevSecOps practices.
  • Familiarity with application dependency and network flow mapping tools (e.g. Device42 Faddom ) used to discover AD-integrated application dependencies and support migration planning or micro segmentation boundaries.
  • Familiarity with Active Directory resilience and recovery tooling (e.g. Semperis ADEngine ) is a plus.
  • Experience migrating from on-premises Active Directory Certificate Services (AD CS) to cloud-native PKI solutions is a plus.
  • Familiarity with enterprise Identity Governance and Administration (IGA) platforms (e.g. SailPoint Saviynt) to manage and improve periodic access certifications (e.g. moving from spreadsheets to a tool) and run detective Segregation of Duties (SoD) reports.
  • Experience automating identity lifecycles by replacing nightly batch files from a Human Resources Information System (HRIS) with Application Programming Interface (API) -driven syncs or establishing governance for non-employee / contractor identities .
  • Understanding of System for Cross-domain Identity Management (SCIM) or API-based provisioning to automate Joiner-Mover-Leaver (JML) workflows for Software as a Service (SaaS) apps expanding beyond just core directories and email.
  • Experience with Tier-0 threat monitoring and detection strategies including security event logging and SIEM integration with Active Directory and other Tier 0 assets.
  • Professional certifications (e.g. Microsoft Identity / SC series CISSP CyberArk Delinea)
  • Occasional exposure to CIAM platforms (e.g. Microsoft Entra External ID Okta Auth0) and associated migration / implementation patterns is a plus but not a core requirement.
  • Based on pay transparency guidelines the salaryrange for this role can vary based on your proximity to one of our West Monroe offices (see table below). Information on our competitive total rewards package including our bonus structure and benefits is here . Individual salaries are determined by evaluating a variety of factors including geography experience skills education and internal equity.

    Employees (and their families) are covered by medical dental vision and basic life insurance. Employeesare able toenroll in our companys 401k plan purchase shares from our employee stock ownership program and be eligible to receive annual bonuses. Employees will also receive unlimited flexible time off and ten paid holidays throughout the calendar year. Eligibility for ten weeks of paid parental leave will also be available upon hire date.

    Seattle or Washington D.C.

    $203200 $239100 USD

    Los Angeles

    $212900 $250500 USD

    New York City or San Francisco

    $222500 $261900 USD

    A location not listed above

    $193500 $227700 USD

    Other consultancies talk at you.

    At West Monroe we work with you.

    Were a global business and technology consulting firm passionate about creating measurable value for our clients delivering real-world solutions.

    The combination of business and technology is not new but how we bring them together is unique. Were fluent in both. We know that technology alone is not the answer but how we apply it is. We rely on data to constantly adapt and solve new challenges. Actions that work today with outcomes that generate value for years to come.

    At West Monroe we zero in on the heart of the opportunity getting to results faster and preparing people for whats next.

    Youll feel the difference in how we work. We show up personally. Were right there in the room with you co-creating through the challenges. With West Monroe collaboration isnt a lofty promise but a daily action. We work together with you to turn vision into clear action with lasting impact.

    West Monroe is an Equal Employment Opportunity Employer

    We believe in treating each employee and applicant for employment fairly and with dignity. We base our employment decisions on merit experience and potential without regard to race color national origin sex sexual orientation gender identity marital status age religion disability veteran status or any other characteristic prohibited by federal state or local law. To learn more about diversity equity and inclusion at West Monroe visit If you require a reasonable accommodation to participate in our recruiting process please inquire by sending an email to .

    Please review our current policy regarding use of generative artificial intelligence during the application process.

    If you are based in California we encourage you to read West Monroes Notice at Collection for California residents provided pursuant to the California Consumer Privacy Act (CCPA) and linked here .

    Required Experience :

    Senior IC

    Key Skills

    Apache Hive,S3,Redshift,Spark,AWS,Solr,NoSQL,Data Warehouse,Internet Of Things,Kafka,DynamoDB,ZooKeeper

    Employment Type : Full Time

    Experience : years

    Vacancy : 1

    Create a job alert for this search

    Senior Security Architect • Chicago, Illinois, USA

    Related jobs
    Senior Cyber Security Architect II (IL, WA or VA)

    Senior Cyber Security Architect II (IL, WA or VA)

    Walgreens • Deerfield, IL, United States
    Full-time
    The Security Architect will design and oversee implementation of secure information technology architectures under direct supervision. Helps to identify and define the organizations cyber security r...Show more
    Last updated: 30+ days ago • Promoted
    Senior Application Security Architect

    Senior Application Security Architect

    Morningstar, Inc. • Chicago, IL, United States
    Full-time
    The Information Security department is responsible for setting enterprise security policies and standards to protect the confidentiality, integrity, and availability of Morningstar information.The ...Show more
    Last updated: 30+ days ago • Promoted
    Senior Solution Architect

    Senior Solution Architect

    Spectraforce Technologies • Chicago, IL, United States
    Full-time
    Title : Senior Solution Architect.Location : Chicago, IL (Hybrid 3Days Onsite in every Week).The Risk Controls Enhancements (RCE) enterprise initiative is a modernization and consolidation effort of...Show more
    Last updated: 1 day ago • Promoted
    Sr. Manager, Solution Architect

    Sr. Manager, Solution Architect

    Capital One • K-Town, IL, US
    Full-time +1
    Manager, Solution Architect Capital One is hiring a skilled Solutions Architect to join our exceptional team of talented technologists in the Card Partnerships segment of Card Tech.The Card Tech te...Show more
    Last updated: 1 day ago • Promoted
    Senior Cyber Security Architect - IAM & Enterprise Security

    Senior Cyber Security Architect - IAM & Enterprise Security

    Northern Trust • Chicago, IL, United States
    Full-time
    A leading global financial institution in Chicago is seeking a Cyber Security Principal Architect to provide architectural oversight for technology solutions. Responsibilities include ensuring the a...Show more
    Last updated: 22 hours ago • Promoted • New!
    Senior Application Security Architect

    Senior Application Security Architect

    Morningstar Credit Ratings, LLC • Chicago, IL, United States
    Full-time
    The Team : • •The Information Security department is responsible for setting enterprise security policies and standards that are designed to protect the confidentiality, integrity, and availability of...Show more
    Last updated: 30+ days ago • Promoted
    Senior Solution Architect

    Senior Solution Architect

    TransUnion • Chicago, Illinois, USA
    Full-time
    TransUnions Job Applicant Privacy Notice.Personal Information We Collect.At TransUnion we strive to build an environment where our associates are in the drivers seat of their professional developme...Show more
    Last updated: 3 hours ago • Promoted • New!
    Senior Director, Information Security Engineering & Architecture

    Senior Director, Information Security Engineering & Architecture

    Walgreens • Deerfield, IL, United States
    Full-time
    Senior Director, Information Security Engineering & Architecture.Senior Director, Information Security Engineering & Architecture. Get AI-powered advice on this job and more exclusive features.This ...Show more
    Last updated: 30+ days ago • Promoted
    Senior Solution Architect

    Senior Solution Architect

    CVS Health • Buffalo Grove, IL, United States
    Full-time
    At CVS Health, we're building a world of health around every consumer and surrounding ourselves with dedicated colleagues who are passionate about transforming health care.As the nation's leading h...Show more
    Last updated: 5 days ago • Promoted
    Senior Technical Consultant - Microsoft Security Architect (Purview)

    Senior Technical Consultant - Microsoft Security Architect (Purview)

    AHEAD • Chicago, IL, United States
    Full-time
    AHEAD builds platforms for digital business.By weaving together advances in cloud infrastructure, automation and analytics, and software delivery, we help enterprises deliver on the promise of digi...Show more
    Last updated: 1 day ago • Promoted
    Senior Solutions Architect

    Senior Solutions Architect

    Blue Cross Blue Shield Association • Chicago, IL, United States
    Full-time
    The hiring range for this role is : .This is the lowest to highest salary we.A candidate's position within the.Note : No amount of pay is considered to be wages or compensation until such amount is ea...Show more
    Last updated: 30+ days ago • Promoted
    Senior AI Security Architect — Enterprise Threat & Governance

    Senior AI Security Architect — Enterprise Threat & Governance

    Northern Trust • Chicago, IL, United States
    Full-time
    A renowned financial institution in Chicago is seeking a Principal AI Security Architect to define and drive AI security strategies and architecture. This role requires extensive experience in enter...Show more
    Last updated: 22 hours ago • Promoted • New!
    FedNow Senior Cyber Security Architect

    FedNow Senior Cyber Security Architect

    Federal Reserve • Chicago, IL, United States
    Full-time +1
    Federal Reserve Bank of Boston Federal Reserve Financial Services (FRFS) delivers a suite of payments services to financial institutions via FedLine Solutions, FedNowSM, Fedwire, National Settlemen...Show more
    Last updated: 4 days ago • Promoted
    Cyber Defense Architect - Zero Trust & Transformation Lead

    Cyber Defense Architect - Zero Trust & Transformation Lead

    KPMG US • Chicago, IL, United States
    Full-time
    A leading consulting firm is seeking a Cyber Defense, Solution Architect to lead technology risk initiatives.This role requires at least ten years of relevant experience in consulting, with a focus...Show more
    Last updated: 4 days ago • Promoted
    Senior Manager, Solutions Architecture, Data Security Pre-sales- Capital One Software (Remote)

    Senior Manager, Solutions Architecture, Data Security Pre-sales- Capital One Software (Remote)

    Capital One • Chicago, IL, US
    Remote
    Full-time +1
    Senior Manager, Solutions Architecture, Data Security Pre-sales- Capital One Software (Remote).Ever since our first credit card customer in 1994, Capital One has recognized that technology and data...Show more
    Last updated: 30+ days ago • Promoted
    Global Security Architect III — Multi-Cloud Threat Defense

    Global Security Architect III — Multi-Cloud Threat Defense

    Google • Chicago, IL, United States
    Full-time
    A leading technology firm is seeking a Global Solutions Security Architect III to develop and document security solution architectures. This role involves cross-functional collaboration, driving sol...Show more
    Last updated: 4 days ago • Promoted
    Global Cybersecurity Solution Architect—Secure-by-Design

    Global Cybersecurity Solution Architect—Secure-by-Design

    McDonald's • Chicago, IL, United States
    Full-time
    A global fast-food corporation is seeking a Senior Cyber Security Solution Architect to develop and implement advanced cybersecurity strategies, conducting architecture reviews and collaborating wi...Show more
    Last updated: 4 days ago • Promoted
    Senior Solution Architect

    Senior Solution Architect

    Compunnel, Inc. • Chicago, IL, United States
    Full-time
    The Senior Solution Architect will support the Risk Controls Enhancements (RCE) program, a large-scale enterprise initiative aimed at modernizing and consolidating Governance, Risk, and Controls (G...Show more
    Last updated: 3 days ago • Promoted