Principal Microsoft Solutions & Platform Architect

Kalpita Technologies, Inc.
Seattle, WA, United States
3 days ago
Apply on www.dice.com
Prepare application

Role details

Contract type
Temporary contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours
Job source

Tech stack

Microsoft Access Microsoft Windows Active Directory Active Directory Federation Services Application Programming Interfaces (APIs) User Authentication Microsoft Azure Microsoft Online Services Cloud Computing Cyber Security Identity and Access Management Kerberos (Protocol)
+13 more
Lightweight Directory Access Protocols (LDAP) Microsoft Windows SDK Windows PowerShell Azure Active Directory Phishing Zero Trust Network Access User Provisioning Software Azure Automation Microsoft InTune HR Software Deployment Automation CIS Benchmarks Restful APIs

Job description

The Principal Microsoft Identity & Platform Engineer serves as the organization’s technical authority for Microsoft Identity, Security, Endpoint Management, and Zero Trust architecture. This role will lead the design, engineering, deployment, and operational maturity of Microsoft Entra ID, Identity Governance, Policies, Intune, Windows Autopilot, Defender, Global Secure Access, and Microsoft 365 security/E5 capabilities.

The ideal candidate combines deep hands-on engineering expertise with enterprise architecture capabilities and has successfully delivered complex identity transformations including Active Directory modernization, password less authentication, cloud-first endpoint management, and Zero Trust initiatives. This individual will partner closely with Technology Operations, Information Security, Infrastructure, Compliance, Service Desk, and business stakeholders to develop and execute client Microsoft platform roadmap.

This position is open to candidates in the Seattle area. You will have a hybrid remote/in-office schedule where you will work from our casual, pet-friendly office at least 3 days a week. Remote for right candidate, Identity Modernization

  • Lead enterprise-wide initiatives to reduce dependency on traditional Active Directory, identify legacy dependencies, and establish a phased roadmap toward a modern, cloud-first identity environment.
  • Develop and execute an Entra-first identity architecture strategy, defining the target-state architecture, migration approach, security controls, governance model, and operational standards.
  • Develop and execute strategies to eliminate, remediate, or modernize legacy authentication dependencies, including applications relying on traditional AD, LDAP, Kerberos, or other legacy authentication mechanisms.
  • Lead ADFS retirement planning and execution, including dependency discovery, application remediation, authentication modernization, testing, phased migration, and final decommissioning.
  • Define standards for identity synchronization, provisioning, deprovisioning, directory architecture, and identity lifecycle management.
  • Develop migration roadmaps for transitioning from Hybrid Entra Join to Entra Join, while addressing dependencies that require continued on-premises identity services.

Authentication & Access Management

  • Define and execute the organization’s password-less authentication strategy
  • Design and implement Windows Hello for Business and Cloud Kerberos Trust architecture.
  • Establish phishing-resistant authentication standards aligned with Zero Trust and modern identity security practices.
  • Define authentication lifecycle standards covering enrollment, authentication, recovery, credential management, and deprovisioning.

Endpoint Modernization

  • Lead Microsoft Intune transformationinitiatives and define cloud-first endpoint management standards.
  • Drive GPO-to-Intune migration programs, including policy assessment, redesign, testing, and phased deployment.
  • Implement CIS benchmark and security baseline controls through Intuneto strengthen endpoint security and compliance.
  • Modernize Windows deployment, provisioning, and device lifecycle management, including enrollment, configuration, maintenance, and retirement standards.

Entra Join & Autopilot Transformation

  • Lead the transition from Hybrid AD Join to Entra Join, developing migration strategies that minimize business disruption and legacy dependencies.
  • Architect and implement Windows Autopilot modernization initiativesto enable scalable, automated, and cloud-first device provisioning.
  • Design standardized device deployment, enrollment, and provisioning processesacross Intune, Entra ID, and Autopilot.
  • Implement Cloud Kerberos Trustand eliminate legacy dependencies that prevent modern Entra Join and cloud-based endpoint deployments.

Secure Access Architecture

  • Lead evaluation of Microsoft Global Secure Access.
  • Design Entra Private Access architecture.
  • Design Entra Internet Access architecture.
  • Develop coexistence and migration strategies from Zscaler.
  • Conduct proof-of-concept testing.
  • Create migration roadmaps and operational support models.

Identity Governance

  • Evaluate and implement Entra Identity Governance capabilities.
  • Design Joiner-Mover-Leaver workflows.
  • Develop automated access certification processes.
  • Integrate identity lifecycle management with HR systems.
  • Improve role-based access governance and compliance.

Automation & Engineering

  • Develop PowerShell automation solutions.
  • Utilize Microsoft Graph APIs.
  • Automate provisioning and reporting.
  • Reduce operational overhead through engineering practices.
  • Build self-service capabilities for users and support teams.

Requirements

  • 8+ yearsof Microsoft infrastructure engineering experience, including 5+ years in Microsoft Identity and 5+ years in Microsoft 365 administration and architecture.
  • 5+ years of hands-on Intune and endpoint engineering, with demonstrated experience leading enterprise transformation programsand designing Zero Trust architectures.
  • Experience working in regulated or compliance-driven environments, with strong understanding of security, governance, and risk management requirements.
  • Proven ability to lead complex Microsoft modernization initiatives, with strong cross-functional collaboration and technical leadership skills.
  • Preferred Microsoft Certifications:
  • Microsoft Certified: Identity and Access Administrator Associate
  • Microsoft Certified: Cybersecurity Architect Expert
  • Microsoft Certified: Endpoint Administrator Associate
  • Microsoft Certified: Azure Solutions Architect Expert (AZ-305)

Skills

  • Microsoft Entra ID, Conditional Access, Identity governance, PIM, Cloud sync, Entra connect, ADFS, SSO, MFA, Authentication flow.
  • Microsoft Intune, Autopilot, Entra join, hybrid join, Windows update for business, CIS benchmarks, GPO migration
  • GSA, Entra Private Access, Entra Internet Access, Private Application Access
  • Powershell, Microsoft Graph, REST APIs, Azure Automation
  • Independent technical ownership, mentoring, cross-functional collaboration, and clear communication with technical and non-technical audiences

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:34 min

Pivoting careers into specialized platform engineering roles

Xavier Portilla Edo · LIVE

1:29 min

Evaluating phishing emails that leverage artificial time constraints

Mauro Verderosa · LIVE

2:47 min

Designing benefit programs with high activation and low administration

Rudi Bauer Rudi Bauer +1 · Cappuccino with HR

2:59 min

The danger of adopting default REST APIs

Stefan Priebsch · World Congress 2021

2:42 min

Introduction to modern Microsoft Teams development

Markus Möller · World Congress 2021

2:39 min

Exposing stored XSS and phishing attacks via markdown

Ramona Schwering Ramona Schwering · World Congress 2026 Europe

Videos

See all

Related articles

See all