Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Senior Principal/Architect (Identity & Security)

$203.2k - $239.1k

West Monroe

Are you ready to make an impact?

Senior Principal/Architect (Identity & Security)


Overview


West Monroe is seeking a Senior Principal/Architect (Identity & Security) to lead cross-functional teams in the design, remediation, and modernization of complex identity and cloud infrastructure solutions. This role focuses on securing and transforming critical IT environments for a diverse portfolio of clients, helping them navigate complex Active Directory modernizations, cloud identity migrations, and security hardening initiatives. This opportunity provides technical leadership in transforming complex IT environments across key industry verticals, including Healthcare, Financial Services, Private Equity, and High Tech. While the scope spans hybrid and cloud identity, the work is particularly grounded in Active Directory as a core Tier 0 platform, with strong Microsoft Entra ID expertise to design and operate modern hybrid identity patterns.


Responsibilities

  • Partner with consultants and client leadership to architect, build, and deploy secure and modern Active Directory and Microsoft Entra ID solutions.
  • Assess current-state identity environments and processes, interview stakeholders, define critical requirements, and present practical solution strategies and roadmaps to client executives.
  • Lead the technical design of future-state Active Directory (AD DS) and Entra ID architectures, including privileged access management (PAM) design, tiered administrative access models (e.g., Microsoft's Enterprise Access Model (EAM)), and identity consolidation strategies.
  • Establish and enforce identity architecture standards, best practices, and governance to deliver secure, compliant, and consistent solutions aligned with industry benchmarks (e.g., CIS and Microsoft baselines) .
  • Lead security assessment and remediation planning, including consolidating findings from tools (e.g., Purple Knight, Maester, CIS Benchmark-based configuration assessments (e.g., CIS-CAT)) to create and manage prioritized, risk-based remediation backlogs.
  • Provide expert technical oversight for security remediation initiatives, such as hardening domain controllers, remediating privileged access, resolving Entra Connect sync issues, and restricting legacy protocols.
  • Develop detailed implementation plans, migration strategies, and remediation backlogs (e.g., in Smartsheet or similar project management tools) for AD restructuring, AD consolidation, identity synchronization, and legacy decommissioning.
  • Establish and manage engagement-level governance, quality, and risk , including defining quantitative success criteria, RACI, and clear communications to both technical and executive stakeholders.
  • Support key decision-making on project direction, including technology selections, team workstreams, and delivery methodologies.
  • Mentor junior consultants on technical best practices, solution design, and client engagement.
  • Assist business development efforts through proposals, pre-sales technical discovery, and client presentations.
  • Leverage AI tools to accelerate analysis, synthesize complex information, and support data-driven recommendations for clients, exercising sound judgment in evaluating outputs.
  • Apply AI technologies (e.g., generative AI, automation tools, data models) to enhance insights, improve delivery efficiency, and elevate the quality of client outcomes.
Qualifications
  • Bachelor's degree in a relevant field preferred, or equivalent experience required.
  • Prior experience in consulting preferred.
  • 8-12+ years of experience in IT architecture, engineering, and/or security with a deep focus on identity solutions.
  • Expert-level knowledge of Active Directory Domain Services (AD DS) design, security, and administration, including: domain/forest architecture, sites/replication, DNS, Group Policy (GPO) management, DC virtualization safeguards, and forest recovery principles.
  • Strong experience with Microsoft Entra ID (formerly Azure AD), including Entra Connect, Conditional Access, modern authentication methods, and Privileged Identity Management (PIM).
  • Proven experience leading identity migrations (including on-premises to cloud, cross-forest restructurings, and Tenant-to-Tenant (cross-tenant) consolidations), AD remediations, and/or consolidation projects.
  • Experience designing and implementing hybrid authentication patterns between AD DS and Microsoft Entra ID, including pass-through authentication (PTA), Seamless SSO, Cloud Kerberos Trust, and phishing-resistant authentication methods.
  • Proficiency in designing and implementing enterprise Privileged Access Management (PAM) solutions (including typical platforms like CyberArk, Delinea, or similar) and tiered administrative access models (e.g., Tier 0/1/2, Microsoft's Enterprise Access Model (EAM)).
  • Hands-on experience with Active Directory and Microsoft Entra ID security assessment and testing tools (e.g., Purple Knight, PingCastle, Maester, Microsoft Defender for Identity or similar AD threat detection platforms) and hardening methodologies (e.g., CIS Benchmarks and Microsoft security baselines).
  • Proficiency with AD security hardening techniques such as KRBTGT password rotations, restricting NTLM, Group Policy object (GPO) cleanup, Local Administrator Password Solution (LAPS), implementing resource-based Kerberos constrained delegation (RBKCD), and configuring LDAP signing.
  • Familiarity with migration and directory protection tools (e.g., Quest On-Demand Migration) and identity-driven application dependencies.
  • Strong communication (written and verbal), presentation, client management, and team leadership skills.
  • Willingness to travel for out-of-town client engagements.
  • Experience integrating AI tools (e.g., ChatGPT) into day-to-day workflows to enhance productivity and insight generation, coupled with strong critical thinking to assess accuracy, mitigate bias, and ensure high-quality outputs.
  • Bonus skills:
  • Familiarity with compliance standards (e.g., NIST, HIPAA, ISO).
  • Advanced scripting for automation and analysis (e.g., PowerShell ).
  • Knowledge of Infrastructure as Code (Terraform) and DevSecOps practices.
  • Familiarity with application dependency and network flow mapping tools (e.g., Device42, Faddom) used to discover AD-integrated application dependencies and support migration planning or microsegmentation boundaries.
  • Familiarity with Active Directory resilience and recovery tooling (e.g., Semperis, ADEngine) is a plus.
  • Experience migrating from on-premises Active Directory Certificate Services (AD CS) to cloud-native PKI solutions is a plus.
  • Familiarity with enterprise Identity Governance and Administration (IGA) platforms (e.g., SailPoint, Saviynt) to manage and improve periodic access certifications (e.g., moving from spreadsheets to a tool) and run detective Segregation of Duties (SoD) reports.
  • Experience automating identity lifecycles by replacing nightly batch files from a Human Resources Information System (HRIS) with Application Programming Interface (API)-driven syncs or establishing governance for non-employee/contractor identities.
  • Understanding of System for Cross-domain Identity Management (SCIM) or API-based provisioning to automate Joiner-Mover-Leaver (JML) workflows for Software as a Service (SaaS) apps, expanding beyond just core directories and email.
  • Experience with Tier-0 threat monitoring and detection strategies, including security event logging and SIEM integration with Active Directory and other Tier 0 assets.
  • Professional certifications (e.g., Microsoft Identity/SC series, CISSP, CyberArk/Delinea).
  • Occasional exposure to CIAM platforms (e.g., Microsoft Entra External ID, Okta, Auth0) and associated migration/implementation patterns is a plus but not a core requirement.
What to Expect
  • A collaborative, flexible, and outcomes-driven consulting environment.
  • A culture that values inclusion, diverse perspectives, and teamwork.
  • A business-focused and industry-specific approach to deploying technology that helps clients tackle their most significant challenges and deliver tangible results, free from rigid hierarchies.
  • While the role spans a broad range of identity technologies and tools, no candidate is expected to be an expert in every item listed . We are seeking deep strength in Tier-0 Active Directory security and modernization, paired with strong Microsoft Entra ID knowledge and the curiosity to rapidly master adjacent areas.


Ready to get started? Join the team and make an impact.


Based on pay transparency guidelines, the salary range for this role can vary based on your proximity to one of our West Monroe offices (see table below). Information on our competitive total rewards package, including our bonus structure and benefits is here. Individual salaries are determined by evaluating a variety of factors including geography, experience, skills, education, and internal equity.

Employees (and their families) are covered by medical, dental, vision, and basic life insurance. Employees are able to enroll in our company's 401k plan, purchase shares from our employee stock ownership program and be eligible to receive annual bonuses. Employees will also receive unlimited flexible time off and ten paid holidays throughout the calendar year. Eligibility for ten weeks of paid parental leave will also be available upon hire date.


Seattle or Washington, D.C.

$203,200-$239,100 USD

Los Angeles

$212,900-$250,500 USD

New York City or San Francisco

$222,500-$261,900 USD

A location not listed above

$193,500-$227,700 USD

Other consultancies talk at you.
At West Monroe, we work with you.

We're a global business and technology consulting firm passionate about creating measurable value for our clients, delivering real-world solutions.

The combination of business and technology is not new, but how we bring them together is unique. We're fluent in both. We know that technology alone is not the answer, but how we apply it is. We rely on data to constantly adapt and solve new challenges. Actions that work today with outcomes that generate value for years to come.

At West Monroe, we zero in on the heart of the opportunity, getting to results faster and preparing people for what's next.

You'll feel the difference in how we work. We show up personally. We're right there in the room with you, co-creating through the challenges. With West Monroe, collaboration isn't a lofty promise, but a daily action. We work together with you to turn vision into clear action with lasting impact.

West Monroe is an Equal Employment Opportunity Employer
We believe in treating each employee and applicant for employment fairly and with dignity. We base our employment decisions on merit, experience, and potential, without regard to race, color, national origin, sex, sexual orientation, gender identity, marital status, age, religion, disability, veteran status, or any other characteristic prohibited by federal, state or local law. To learn more about diversity, equity and inclusion at West Monroe, visit If you require a reasonable accommodation to participate in our recruiting process, please inquire by sending an email to View email address on click.appcast.io.

Please review our current policy regarding use of generative artificial intelligence during the application process.

If you are based in California, we encourage you to read West Monroe's Notice at Collection for California residents, provided pursuant to the California Consumer Privacy Act (CCPA) and linked here.
Vacancy posted 2 days ago
Similar jobs that could be interesting for youBased on the Senior Principal/Architect (Identity & Security) in Chicago, IL vacancy
  • $203.2k - $239.1k

     ...you ready to make an impact? West Monroe is hiring a Security Senior Architect for our growing Cybersecurity & Enterprise Technology consulting...  ...implement security solutions that protect cloud, data, identity, and AI-enabled systems while supporting business... 
    Senior
    Local area
    Immediate start
    Flexible hours

    West Monroe

    Chicago, IL
    4 days ago
  • $104.8k - $192.2k

    EY is seeking a Digital Identity SME - Senior in Chicago to help organizations enhance user experience and reduce risk through identity solutions. Responsibilities include developing IAM strategies, implementing governance solutions using Microsoft Entra and Saviynt, and... 
    Senior
    Work experience placement
    Flexible hours

    EY

    Chicago, IL
    3 days ago
  • $204.25k - $300k

     ...and make a real difference. As a Senior Principal Cybersecurity Architect at JPMorganChase within the...  ...experience ~ Extensive experience in security assessment, threat modeling, and secure...  ...gender, sexual orientation, gender identity, gender expression, age, marital or... 
    Principal
    Senior

    JPMorgan Chase Bank, N.A.

    Chicago, IL
    5 days ago
  • Principal-level Syndigo / Riversand Architect / Senior Developer - true hands-on SME Own end-to-end architecture AND development across MDM / PIM solutions in enterprise environments Act as technical authority , bridging architecture, design, and deep hands-on coding... 
    Principal
    Senior
    Full time
    Contract work

    Myticas Consulting

    Chicago, IL
    12 hours ago
  • Slalom is seeking a Senior Consultant or Principal level Security Strategist in Chicago, Illinois, with extensive expertise in Business Continuity and Disaster Recovery, Privacy Engineering, Cybersecurity, and GRC architecture. The role involves technical ownership of privacy... 
    Senior

    Slalom

    Chicago, IL
    12 hours ago
  • $190k - $200k

    A leading recruitment firm is hiring a Senior AppSec Architect to expand their security organization and build an Application Security program for a 200-person company. This is a 100% remote role in the US. The position offers a compensation of $190,000-200,000 plus a... 
    Senior
    Remote job

    Vaco Recruiter Services

    Chicago, IL
    2 days ago
  •  ...collaborating on cloud optimizations, enhancing security, or just hanging out as a team. At...  ...place to work. What You’ll Do The Senior SAP Architect will lead the end-to-end architectural...  ...HANA and PostgreSQL data architecture Identity & Access architecture (XSUAA, IAS/IPS,... 
    Senior
    Immediate start
    Remote work
    Flexible hours

    Protera

    Chicago, IL
    3 days ago
  •  ...ensuring scalability, performance, and security. Design and implement cloud architectures...  ...Seeking a highly skilled Technical Architect with hands on expertise in the .NET technology...  ..., sex, sexual orientation, gender identity, age, disability, national origin, citizenship... 
    Senior
    Permanent employment
    Contract work
    Local area

    Robotics Prcocess Automation, LLC

    Chicago, IL
    3 days ago
  • $180k

     ...Job Description The Principal Architect - Solutions is responsible for...  ...s diverse client base. This senior role is expected to take a proactive...  ...and implementing scalable, secure, and highly efficient cloud...  ...pregnancy and gender identity), national origin, political... 
    Principal
    Temporary work
    Remote work

    Ollion

    Chicago, IL
    1 day ago
  • $140.6k - $183.11k

     ...Principal Architect Achieving our goals starts with supporting yours. Grow your career, access...  .... This includes designing scalable and secure architectures, integrating AI-assisted...  ...color, religion, national origin, gender identity, sexual orientation, disability, age, veteran... 
    Principal
    Hourly pay

    United Airlines

    Chicago, IL
    7 hours ago
  • $150k - $190k

     ...something great. Come make your mark. Principal Quality Automation Architect The Principal Quality...  ...and solutions, and raise issues to senior team members when necessary A team...  ...gender, sexual orientation, gender identity or expression, veteran status, or any... 
    Principal
    Work at office
    Local area
    Remote work
    2 days per week

    Accordion USA

    Chicago, IL
    12 hours ago
  • $140.6k - $183.11k

     ...Principal Domain Architect Achieving our goals starts with supporting yours....  ...direction across network, security, automation, and associated...  ...agent-based automation, and identity-driven policy frameworks for...  ...connectivity architecture strategy to senior leadership and technical... 
    Principal
    Hourly pay
    Work at office
    2 days per week
    3 days per week

    United Airlines

    Chicago, IL
    4 days ago
  • $195.37k - $244.21k

     ...Department Overview As a Principal Platform Engineer in...  ..., scalability, security and cost optimization...  ...The Principal Platform Architect partners with Engineering...  ...leadership. Mentor senior engineers and architects...  ..., gender, gender identity, gender expression, transgender... 
    Principal
    Local area
    Flexible hours
    Shift work

    McDonald's Corporation

    Chicago, IL
    3 days ago
  • $197k - $337k

     ...As an AI Architect within Thoughtworks' Data & AI Service Line, you...  ...strategic AI advisor to C-suite and senior technical stakeholders,...  ...explainability, privacy, and security by design Drive hands-on delivery...  ..., sexual orientation, gender identity or expression, national... 
    Principal
    Local area
    Remote work
    Shift work

    ThoughtWorks

    Chicago, IL
    2 days ago
  • $95k - $150k

     ...environments. As a team of engineers, architects, designers, scientists,...  ...your future? Be our next Senior Project Architect Your...  ...working under Project Managers and Principals from Conceptual Design...  ...Sexual Orientation and Gender Identity or Expression. Should... 
    Senior
    Full time
    Work at office

    EXP

    Chicago, IL
    3 days ago
  • $272k - $374k

     ...Secure Every Identity, from AI to Human Identity is the key to unlocking the potential of AI. Okta secures AI by building the trusted...  ...mission. If you are too, let's talk. We are looking for a Senior Architect to join our Emerging Technologies organization. This is... 
    Senior
    Local area
    Worldwide
    Flexible hours
    Shift work

    Okta, Inc.

    Chicago, IL
    1 day ago
  • $140k - $150k

     ...Virtual Infrastructure and Systems Architect, working as a member of the...  ...Azure services to support a secure, mobile workforce and agile...  ...administration acting in a senior role. Proven ability to manage...  ...and veteran status, gender identity or expression, genetic... 
    Senior
    Full time
    Local area
    Worldwide

    Seyfarth Shaw

    Chicago, IL
    8 hours ago
  • $120k - $150k

     ...environments. As a team of engineers, architects, designers, scientists,...  ...your future? Be our next Senior Architect, Science +...  ...working under Project Managers and Principals from Conceptual Design through...  ...Orientation and Gender Identity or Expression. Should... 
    Senior
    Full time
    Work at office

    EXP

    Chicago, IL
    1 day ago
  • $145k - $175k

     .... Learn more at later.com. About this position: As a Senior Security Engineer at Later, you will play a critical role in strengthening...  ...with hands-on engineering, with a particular focus on identity and access management, authentication systems, and secure-by-... 
    Senior
    Permanent employment
    Local area
    Remote work

    Later

    Chicago, IL
    1 day ago
  • $180k - $200k

     ...Senior Architect /.NET / Finance / Chicago Chicago, Illinois Hybrid Full Time $180k...  ...Architect to help design and deliver scalable, secure applications that support both internal...  ...queue systems Understanding of identity and access management (OAuth, OIDC, SSO... 
    Senior
    Full time
    Work experience placement

    Motion Recruitment

    Chicago, IL
    8 hours ago
  • $160k - $205k

     ...awards page: We are looking for an enthusiastic Senior GenAI and LLM Architect to add to Credera's Data capability group. Our ideal...  ...employment without regard to race, color, religion, gender identity, sexual orientation, national origin, age, genetic information... 
    Senior
    H1b
    Remote work
    Worldwide
    Flexible hours
    2 days per week

    Credera Experienced Hiring Job Board

    Chicago, IL
    3 days ago
  • $150.1k - $227k

     ...to deliver product innovation to our customers. As a Readiness Architect, you will be responsible for understanding the Industries...  ...national origin, sex, sexual orientation, gender expression or identity, transgender status, age, disability, veteran or marital status... 
    Senior
    Shift work

    Salesforce.Com Inc

    Chicago, IL
    3 days ago
  • VMC Soft Technologies, Inc is seeking an experienced Okta Architect in Chicago, IL. The successful candidate will provide architectural...  .... Candidates must possess strong knowledge of Okta standards, identity and access management, and have 10+ years of relevant... 
    Senior

    VMC Soft Technologies, Inc

    Chicago, IL
    3 days ago
  •  ...Description & Requirements The Senior AI Architect will serve as the Firm's senior technical...  ...between ambitious business concepts and secure, production-ready deployments within a...  ...authentication and security, including SAML, OAuth, identity management, and secure API integration... 
    Senior
    Hourly pay
    Full time
    Part time
    Work at office
    Worldwide

    Baker McKenzie

    Chicago, IL
    7 hours ago
  • $160k - $200k

     ...Please visit our employer awards page: Credera is seeking a Senior Integration Architect to deliver on our vision of Connected Work®, where we help...  ...without regard to race, color, religion, gender identity, sexual orientation, national origin, age, genetic information... 
    Senior
    H1b
    Remote work
    Worldwide
    Flexible hours
    2 days per week

    Credera Experienced Hiring Job Board

    Chicago, IL
    3 days ago
  • $179.76k - $341.52k

     ...We are seeking a hands-on Modernization Architect who combines deep expertise in agentic...  ...Serve as a trusted technical advisor to senior stakeholders, guiding both strategy and...  ...religion, sex, sexual orientation, gender identity, national origin, disability, or status... 
    Senior
    Minimum wage
    Full time
    Part time
    Local area
    Worldwide

    Kyndryl

    Chicago, IL
    1 day ago
  • $135k - $182.1k

    Senior Identity and Access Management (IAM) Specialist We are seeking a highly experienced and technically proficient Senior Identity and...  ...complex enterprise environment. This role is critical to ensuring secure, compliant, and efficient access to systems and data, with a... 
    Senior
    Shift work
    Day shift

    Koitecc Solutions

    Chicago, IL
    2 days ago
  •  ...Cities & Places business brings together architects, engineers, planners, landscape...  ...growth, Jacobs is seeking an experienced Senior Landscape Architect to help lead impactful...  ...status, sexual orientation, gender, gender identity, gender expression and transgender status... 
    Senior

    Jacobs

    Chicago, IL
    4 days ago
  • $218.4k - $365.2k

     ...Responsibilities Act as a peer to senior technical leaders, engaging C...  ...with Chief Information Security Officers and Privacy Officers...  ...actionable for enterprise‑scale architects. Bring the Well‑Architected...  ..., sexual orientation, gender identity, disability, veteran status,... 
    Principal

    salesforce.com, inc.

    Chicago, IL
    3 days ago
  • $218.4k - $365.2k

     ...dedicated to the success of architects. Architects are the trusted advisors...  ...session with a room full of senior technologists. You never stop...  ...with Chief Information Security Officers and Privacy Officers...  ...orientation, gender expression or identity, transgender status, age,... 
    Principal
    Shift work

    Salesforce

    Chicago, IL
    2 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Senior Principal/Architect (Identity & Security). Be the first to apply!