Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Senior Principal/Architect (Identity & Security)

$225k - $304k

West Monroe

Are you ready to make an impact?

Senior Principal/Architect (Identity & Security) 

Overview

West Monroe is seeking a Senior Principal/Architect (Identity & Security) to lead cross-functional teams in the design, remediation, and modernization of complex identity and cloud infrastructure solutions. This role focuses on securing and transforming critical IT environments for a diverse portfolio of clients, helping them navigate complex Active Directory modernizations, cloud identity migrations, and security hardening initiatives. This opportunity provides technical leadership in transforming complex IT environments across key industry verticals, including Healthcare, Financial Services, Private Equity, and High Tech. While the scope spans hybrid and cloud identity, the work is particularly grounded in Active Directory as a core Tier 0 platform, with strong Microsoft Entra ID expertise to design and operate modern hybrid identity patterns. 

Responsibilities

  • Partner with consultants and client leadership to  architect, build, and deploy secure and modern Active Directory and Microsoft Entra ID solutions. 

  • Assess current-state identity environments and processes, interview stakeholders, define critical requirements, and present practical solution strategies and roadmaps to client executives. 

  • Lead the technical design of future-state Active Directory (AD DS) and Entra ID architectures, including privileged access management (PAM) design, tiered administrative access models (e.g., Microsoft’s Enterprise Access Model (EAM)), and identity consolidation strategies. 

  • Establish and enforce identity architecture standards, best practices, and governance to deliver secure, compliant, and consistent solutions aligned with industry benchmarks (e.g., CIS and** Microsoft baselines)**. 

  • Lead security assessment and remediation planning, including  consolidating findings from tools (e.g., Purple Knight, Maester, CIS Benchmark-based configuration assessments (e.g., CIS-CAT)) to create and manage prioritized, risk-based remediation backlogs. 

  • Provide  expert technical oversight for security remediation initiatives, such as hardening domain controllers, remediating privileged access, resolving Entra Connect sync issues, and restricting legacy protocols. 

  • Develop detailed implementation plans, migration strategies, and  remediation backlogs (e.g., in Smartsheet or similar project management tools) for AD restructuring, AD consolidation, identity synchronization, and legacy decommissioning. 

  • Establish and manage engagement-level  governance, quality, and risk , including defining quantitative success criteria, RACI, and clear communications to both technical and executive stakeholders. 

  • Support key decision-making on project direction, including technology selections, team workstreams, and delivery methodologies. 

  • Mentor junior consultants on technical best practices, solution design, and client engagement. 

  • Assist business development efforts through proposals, pre-sales technical discovery, and client presentations. 

Qualifications

  • Bachelor’s degree in a relevant field preferred, or equivalent experience required. 

  • Prior experience in consulting preferred. 

  • 8–12+ years of experience in IT architecture, engineering, and/or security with a deep focus on identity solutions. 

  • Expert-level knowledge of  Active Directory Domain Services (AD DS)design, security, and administration, including: domain/forest architecture,  sites/replication, DNS, Group Policy (GPO) management, DC virtualization safeguards, and forest recovery principles. 

  • Strong experience with  Microsoft Entra ID (formerly Azure AD), including Entra Connect, Conditional Access, modern authentication methods, and Privileged Identity Management (PIM). 

  • Proven experience leading identity migrations (including on-premises to cloud, cross-forest restructurings, and Tenant-to-Tenant (cross-tenant) consolidations), AD remediations, and/or consolidation projects. 

  • Experience designing and implementing hybrid authentication patterns between AD DS and Microsoft Entra ID, including pass-through authentication (PTA), Seamless SSO, Cloud Kerberos Trust, and phishing-resistant authentication methods. 

  • Proficiency in designing and implementing enterprise  Privileged Access Management (PAM)solutions (including typical platforms like CyberArk, Delinea, or similar) and  tiered administrative access models (e.g., Tier 0/1/2, Microsoft’s Enterprise Access Model (EAM)). 

  • Hands-on experience with Active Directory and Microsoft Entra ID security assessment and testing tools (e.g., Purple Knight, PingCastle, Maester, Microsoft Defender for Identity or similar AD threat detection platforms) and hardening methodologies (e.g., CIS Benchmarks and Microsoft security baselines). 

  • Proficiency with AD security hardening techniques such as KRBTGT password rotations, restricting NTLM, Group Policy object (GPO) cleanup, Local Administrator Password Solution (LAPS), implementing resource-based Kerberos constrained delegation (RBKCD), and configuring LDAP signing. 

  • Familiarity with migration and directory protection tools (e.g., Quest On-Demand Migration) and identity-driven application dependencies. 

  • Strong communication (written and verbal), presentation, client management, and team leadership skills. 

  • Willingness to travel for out-of-town client engagements. 

  • Bonus skills:

  • Familiarity with compliance standards (e.g., NIST, HIPAA, ISO). 

  • Advanced scripting for automation and analysis (e.g.,  PowerShell ). 

  • Knowledge of  Infrastructure as Code (Terraform)and  DevSecOps practices. 

  • Familiarity with application dependency and network flow mapping tools (e.g., Device42, Faddom) used to discover AD-integrated application dependencies and support migration planning or microsegmentation boundaries. 

  • Familiarity with Active Directory resilience and recovery tooling (e.g., Semperis, ADEngine) is a plus. 

  • Experience migrating from on-premises Active Directory Certificate Services (AD CS) to cloud-native PKI solutions is a plus. 

  • Familiarity with enterprise  Identity Governance and Administration (IGA)platforms (e.g., SailPoint, Saviynt) to manage and improve periodic access certifications (e.g., moving from spreadsheets to a tool) and run detective Segregation of Duties (SoD) reports. 

  • Experience  automating identity lifecycles by replacing nightly batch files from a Human Resources Information System (HRIS) with Application Programming Interface (API)-driven syncs or establishing governance for non-employee/contractor identities. 

  • Understanding of System for Cross-domain Identity Management** (SCIM)** or API-based provisioning to automate Joiner-Mover-Leaver (JML) workflows for  Software as a Service (SaaS)apps, expanding beyond just core directories and email. 

  • Experience with Tier-0 threat monitoring and detection strategies, including security event logging and SIEM integration with Active Directory and other Tier 0 assets. 

  • Professional certifications (e.g., Microsoft Identity/SC series, CISSP, CyberArk/Delinea). 

  • Occasional exposure to CIAM platforms (e.g., Microsoft Entra External ID, Okta, Auth0) and associated migration/implementation patterns is a plus but not a core requirement. 

What to Expect

  • A collaborative, flexible, and outcomes-driven consulting environment. 

  • A culture that values inclusion, diverse perspectives, and teamwork. 

  • A business-focused and industry-specific approach to deploying technology that helps clients tackle their most significant challenges and deliver tangible results, free from rigid hierarchies. 

  • While the role spans a broad range of identity technologies and tools,  no candidate is expected to be an expert in every item listed . We are seeking deep strength in Tier-0 Active Directory security and modernization, paired with strong Microsoft Entra ID knowledge and the curiosity to rapidly master adjacent areas. 

Ready to get started? Join the team and make an impact. 

Based on pay transparency guidelines, the salary range for this role can vary based on your proximity to one of our West Monroe offices (see table below). Information on our competitive total rewards package, including our bonus structure and benefits is  here . Individual salaries are determined by evaluating a variety of factors including geography, experience, skills, education, and internal equity.

Employees (and their families) are covered by medical, dental, vision, and basic life insurance. Employees are able to enroll in our company’s 401k plan, purchase shares from our employee stock ownership program and be eligible to receive annual bonuses. Employees will also receive unlimited flexible time off and ten paid holidays throughout the calendar year. Eligibility for ten weeks of paid parental leave will also be available upon hire date. 

Seattle or Washington, D.C.

$236,300—$277,700 USD

Los Angeles

$247,500—$291,000 USD

New York City or San Francisco

$258,800—$304,200 USD

A location not listed above

$225,000—$264,500 USD

Other consultancies talk at you.

At West Monroe, we work with you.

We’re a global business and technology consulting firm passionate about creating measurable value for our clients, delivering real-world solutions.

The combination of business and technology is not new, but how we bring them together is unique. We’re fluent in both. We know that technology alone is not the answer, but how we apply it is. We rely on data to constantly adapt and solve new challenges. Actions that work today with outcomes that generate value for years to come.

At West Monroe, we zero in on the heart of the opportunity, getting to results faster and preparing people for what’s next.

You’ll feel the difference in how we work. We show up personally. We’re right there in the room with you, co-creating through the challenges. With West Monroe, collaboration isn’t a lofty promise, but a daily action. We work together with you to turn vision into clear action with lasting impact.

West Monroe **   ****is an Equal Employment Opportunity Employer **  
We believe in treating each employee and applicant for employment fairly and with dignity. We base our employment decisions on merit, experience, and potential, without regard to race, color, national origin, sex, sexual orientation, gender identity, marital status, age, religion, disability, veteran status, or any other characteristic prohibited by federal, state or local law. To learn more about diversity, equity and inclusion at West Monroe, visit  . If you require a reasonable accommodation to participate in our recruiting process, please inquire by sending an email to View email address on swooped.co .

Please review our current policy regarding use of generative artificial intelligence during the application process .

If you are based in California, we encourage you to read West Monroe’s Notice at Collection for California residents, provided pursuant to the California Consumer Privacy Act (CCPA) and linked  here .  

Vacancy posted more than 2 months ago
Similar jobs that could be interesting for youBased on the Senior Principal/Architect (Identity & Security) in San Francisco, CA vacancy
  • $257.5k

     ...you are the future of Salesforce. Principal Architect, Platform Identity The Mission We are seeking...  ...elegant architectural patterns that secure billions of global transactions....  ...the primary technical bridge between senior leadership and cross-functional engineering... 
    Principal
    Immediate start
    Shift work
    Day shift

    Salesforce

    San Francisco, CA
    3 days ago
  • $144k - $329.1k

     ...clients to leverage the newest technologies securely and at scale. We leverage best...  ...The opportunity We are looking for a Principal AI Architect to join our team and lead our AI initiatives...  ...age, sex, sexual orientation, gender identity/expression, pregnancy, genetic... 
    Principal
    Senior
    Summer holiday
    Flexible hours

    EY

    San Francisco, CA
    4 days ago
  • SoFi in San Francisco seeks a Technical Leader for Digital Identity, responsible for the technical strategy, architecture of Tier-0 platforms, and building an effective engineering culture. Your role involves complex authorization systems and ensuring operational excellence... 
    Senior

    Israelvcforum

    San Francisco, CA
    2 days ago
  • $100k

     ...Enterprise Identity Security Implementation Engineer Oleria provides adaptive and autonomous identity security solutions to protect and...  ...testing, and go-live. You work directly with CISOs, identity architects, and IT operations teams to translate their access... 
    Senior
    Temporary work
    Worldwide
    Flexible hours

    Oleria Security

    San Francisco, CA
    4 days ago
  • $160k - $200k

    Senior Principal Architect Engineer, Power Generation Senior Principal Power Generation Architect Engineer...  ...effectively, build consensus, and secure favorable agreements without...  ...national origin, sexual orientation, gender identity, disability, or veteran status. #J-1... 
    Principal
    Senior
    Work at office
    Flexible hours

    Tract Capital

    San Francisco, CA
    1 day ago
  • A leading consulting firm in San Francisco seeks a Digital Identity SME with a focus on Microsoft Entra and Saviynt. The role involves assessing current states, designing IAM strategies, and leading implementations. Candidates should possess hands-on experience with identity... 
    Senior
    Flexible hours

    EY

    San Francisco, CA
    5 days ago
  • $170k - $277k

    Palo Alto Networks, Inc. is seeking a Senior Principal Backend Engineer to lead backend development for cybersecurity solutions in San Francisco. The ideal candidate will have 14+ years of software engineering experience, expert skills in Python and Go, and a strong background... 
    Principal
    Senior

    Palo Alto Networks, Inc.

    San Francisco, CA
    4 days ago
  • $170k - $277k

     ...everyday lives that are only enabled by a secure digital environment. Job Summary The Layer 7 security team is seeking a Senior Principal Software Engineer to lead the design...  ..., family or medical care leave, gender identity or expression, genetic information, marital... 
    Principal
    Senior
    Full time
    Work at office
    Worldwide

    Palo Alto Networks

    San Francisco, CA
    5 days ago
  • $260k - $275k

    Saviynt, located in San Francisco, is hiring a Senior Principal Software Engineer to lead the development of our AI security products. You will design and implement secure and scalable workflows, work across various cloud platforms, and contribute to product direction and... 
    Principal
    Senior

    Jobleads-US

    San Francisco, CA
    2 days ago
  •  ...Anchorage Lending CA, LLC is seeking a seasoned backend engineer to enhance our digital asset platform. With a focus on robust security and innovative solutions, you will collaborate with teams to build high quality software for our Atlas business while ensuring efficient... 
    Senior

    Anchorage Lending CA, LLC

    San Francisco, CA
    3 days ago
  • $280k - $385k

    A leading data and AI company seeks senior leaders to define the strategy for its security platform, focusing on Authentication. Candidates should have extensive experience in Data Security, leadership skills, and a strong communication background. The role offers a competitive... 
    Principal
    Senior
    Remote job

    Databricks Inc.

    San Francisco, CA
    1 day ago
  • $260k - $275k

    Medium is seeking a Senior Principal Software Engineer in San Francisco to lead the design and implementation of AI security solutions. This role requires over 15 years in software engineering, with expert skills in Java, Spring, and cloud platforms such as AWS and Azure... 
    Principal
    Senior

    Jobleads-US

    San Francisco, CA
    4 days ago
  •  ...A leading identity security platform provider in San Francisco is seeking a Product Manager to define success metrics and collaborate with various teams. An ideal candidate thrives in fast-paced environments, focuses on customer success, and is aligned with the company... 
    Senior

    C-1 Inc

    San Francisco, CA
    3 days ago
  • $221k - $260k

    ArtOfBlockchain is seeking an experienced engineer to architect and build mobile systems for secure management of identity credentials like eIDs and ePassports. The role involves deep engagement with NFC systems, cryptographic security measures, and collaboration across... 
    Senior
    Flexible hours

    ArtOfBlockchain

    San Francisco, CA
    2 days ago
  • $150k - $185k

     ...implementations for enterprise customers. You will own the process from discovery to deployment and work closely with CISOs to deliver identity security solutions. Ideal candidates have 5-8 years of experience in B2B SaaS implementations, with deep knowledge of identity... 
    Senior

    Medium

    San Francisco, CA
    4 days ago
  • A leading cybersecurity firm is seeking a B2B Product Marketing role focused on identity security. You will create competitive strategies, write sales enablement content, and develop customer case studies using AI tools for rapid production. The ideal candidate should have... 
    Senior

    Medium

    San Francisco, CA
    1 day ago
  • $150k - $185k

    Oleria Security is looking for an Implementation Engineer to lead technical deployments for enterprise customers. This role involves managing...  ...from discovery to go-live, ensuring smooth integrations across identity ecosystems like Okta and AWS IAM. The ideal candidate will have... 
    Senior

    Oleria Security

    San Francisco, CA
    4 days ago
  • OpenAI is seeking a Senior Staff Software Engineer to lead the design and development of the identity infrastructure in San Francisco. You will oversee the architecture and...  ...of systems across cloud platforms, ensuring security and reliability. Ideal candidates have over... 
    Senior
    Relocation package

    OpenAI

    San Francisco, CA
    1 day ago
  • $181.1k - $318.4k

     ...by millions of Apple customers!As a Senior Wireless MAC Standards Architect, you will be at the forefront of...  ...saving, low latency, coexistence, security, and privacy. Experience with modeling...  ..., sex, sexual orientation, gender identity, national origin, disability,... 
    Senior
    Relocation

    Apple Inc.

    San Francisco, CA
    2 days ago
  • $162.7k - $263.18k

     ...everyday lives that are only enabled by a secure digital environment. Job Summary Join...  ...and identifying applications. As a Sr. Principal Security Researcher, you will shape detection...  ..., family or medical care leave, gender identity or expression, genetic information,... 
    Principal
    Senior
    Full time
    Work at office
    Worldwide

    Palo Alto Networks

    San Francisco, CA
    3 days ago
  • $130.7k - $200k

     ...Keurig Dr Pepper is seeking a Sr. Principal Product Owner to lead the...  ...systems — spanning secure file transfer (SFTP), middleware...  ...approaches. Partner with Solution Architects to define non‑functional requirements...  ..., sexual orientation, gender identity, gender expression, age,... 
    Principal
    Senior
    For contractors
    Work experience placement
    Shift work

    Keurig Dr Pepper Inc.

    San Francisco, CA
    3 days ago
  • $257.5k

     ...The Experience: We are seeking a Principal Architect to serve as the visionary anchor for our...  ...on large, complex codebases. Agentic identity, trust, compliance and governance must...  ...behavioral monitoring to guarantee the safety, security, and deterministic correctness of... 
    Principal
    Casual work
    Remote work

    Salesforce.Com Inc

    San Francisco, CA
    2 days ago
  • $170k - $277k

     ...Sr. Principal Software Engineer At Palo Alto Networks®, we're united...  ...own and shape the future of secure cloud environments using an...  ...networking and security expert to architect innovative software solutions...  ...medical care leave, gender identity or expression, genetic... 
    Principal
    Senior
    Full time
    Work at office

    Palo Alto Networks

    San Francisco, CA
    3 days ago
  •  ...Handshake is looking for a Senior Security Engineer in San Francisco to lead the architecture and implementation of enterprise identity solutions. This role requires proficiency in IAM engineering, automation, and strong scripting skills in Python. The ideal candidate... 
    Senior
    Flexible hours

    Handshake

    San Francisco, CA
    4 days ago
  •  ...of SmithGroup is looking for a Project Architect to join our team. Working with us, you...  ...documents for projects of complex nature (senior living, mixed-use, multi-family)....  ...religion, sex, sexual orientation, gender identity, national origin, or protected veteran status... 
    Senior
    For contractors
    Start working today
    Work at office

    SmithGroup

    San Francisco, CA
    4 days ago
  • $130k - $155k

     ...Licensed Architect Overall Responsibilities: As a licensed Architect, responsible for...  ...education opportunities for staff. Assist Principal-in-Charge, Project Manager, and Project...  ...religion, sex, sexual orientation, gender identity, national origin, or protected veteran... 
    Senior
    Temporary work
    Work at office
    Local area

    Steinberg

    San Francisco, CA
    16 days ago
  • $200k - $250k

     ...Architect The Architect is a core member of Fluidstack's Data Center Design and Engineering...  ...positioning, setbacks, service access, security zoning, and phasing logic across multi-...  ...origin, sexual orientation, gender identity, disability and protected veterans' status... 
    Senior
    For contractors
    Local area

    Fluidstack

    San Francisco, CA
    1 day ago
  • $134.9k - $202.5k

     ...to become the world’s leading integrated design practice. Our architects, engineers, interior designers, sustainability specialists, and...  ..., genetic information, disability, sexual orientation, gender identity or gender expression. We prohibit discrimination in decisions... 
    Senior
    Full time
    Temporary work
    Part time
    For contractors
    Casual work
    Work at office
    Local area
    Flexible hours

    Stantec

    San Francisco, CA
    6 days ago
  • $160k - $230k

     ...Description Arcadis is seeking a high-caliber Principal Architect to join our Transit Group practice in...  ...an NCARB file or be able/eligible to secure one within 45 days of hire Strategic...  ...marital status, sexual orientation, gender identity, citizenship status, veteran status or... 
    Principal
    Work at office
    Local area

    Poutrix

    San Francisco, CA
    4 days ago
  • A leading tech organization is seeking a Product Security Engineer to lead security initiatives and safeguard its innovative products. This hands-on role involves embedding security throughout the development lifecycle, performing in-depth code reviews, and managing vulnerability... 
    Senior

    Tools for Humanity

    San Francisco, CA
    4 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Senior Principal/Architect (Identity & Security). Be the first to apply!