M365 Identity, Security & Compliance Architect
Group Nine LLC
M365 Identity, Security & Compliance Architect (Architecture & Deployment)
The Microsoft 365 Security & Compliance Architect is a senior, hands-on technical role responsible for architecting, designing, and deploying Microsoft security and compliance solutions across customer environments. This role is accountable for taking engagements from discovery and presales through implementation and operational readiness, not just producing designs. The Architect serves as both:
- The technical authority during presales and solution definition, and
- The hands-on lead during deployment, configuration, and validation of Microsoft 365 security and compliance controls.
This role operates in a consulting environment and requires comfort switching between customer-facing advisory work and deep technical execution.
Core Responsibilities
Presales, Discovery & Solution Definition
- Lead security and compliance discovery workshops and technical assessments.
- Translate business drivers, risk tolerance, and regulatory requirements into deployable Microsoft architectures, not theoretical designs.
- Support Sales and Presales by:
- Defining scope and assumptions
- Identifying technical risks and dependencies
- Contributing directly to SOWs, implementation plans, and phased roadmaps
- Clearly articulate what will be configured, how, and why in customer-facing documentation.
Architecture & Design (Practical, Deployable Designs)
- Design end-to-end Microsoft 365 security and compliance solutions aligned to:
- Zero Trust principles
- Microsoft best practices
- Customer operational maturity
- Produce architecture and design artifacts that are intended to be implemented, including:
- Identity and access models
- Endpoint security baselines
- Data protection and DLP strategies
- Threat protection and incident response workflows
- Define phased deployment approaches that balance speed, risk, and organizational readiness.
Hands-On Deployment & Configuration
The Architect is expected to personally deploy and configure solutions:
Identity & Access
- Implement and tune Microsoft Entra ID configurations:
- Conditional Access policies
- MFA and passwordless authentication (WHfB, Passkey/FIDO2, TAP)
- Single Sign-On (OIDC/SAML)
- Identity Protection policies
- Privileged Identity Management (PIM)
- Lifecycle Workflows for joiner/mover/leaver scenarios
- Configure hybrid identity integrations where required.
Identity Governance
- Deploy and operationalize Microsoft Entra ID Governance capabilities:
- Entitlement Management – access packages, catalogs, and connected organizations for external/B2B access
- Access Reviews for groups, applications, and privileged roles
- Lifecycle Workflows automating joiner / mover / leaver processes
- Separation of duties and access certification controls
- Terms of Use policies and approval/governance workflows
- Experience migrating from SailPoint to Entra ID Governance is highly desirable.
Endpoint & Device Security
- Onboard and operationalize Microsoft Defender for Endpoint:
- Attack surface reduction rules
- Device groups and policy targeting
- Integration with Defender XDR
Threat Protection & XDR
- Deploy and configure Microsoft Defender XDR, including:
- Defender for Office 365
- Defender for Identity
- Defender for Cloud Apps
- Validate telemetry, alerts, and investigation workflows.
- Ensure integrations across Defender components function as designed.
Information Protection & Compliance
- Implement Microsoft Purview capabilities:
- Sensitivity labels and label policies
- Data Loss Prevention (Endpoint, M365, Cloud Apps)
- Data lifecycle and retention policies
Validation, Handoff & Enablement
- Validate deployed configurations against design intent.
- Perform policy testing and non-disruptive validation where required.
- Deliver operational handoff documentation and knowledge transfer.
- Advise customers on ongoing tuning, operational ownership, and future roadmap phases.
Required Technical Skills & Experience
Microsoft Security & Compliance (Hands-On)
- Microsoft Entra ID – advanced configuration experience
- Microsoft Entra ID Governance – hands-on experience with entitlement management, access reviews, and lifecycle workflows
- Microsoft Defender XDR – cross-solution deployment and integration
- Microsoft Purview – real-world labeling, DLP, and retention deployments
Architecture & Consulting Skills
- Ability to design solutions that are deployable in real customer tenants
- Strong documentation skills for:
- Architecture diagrams
- Design documents
- Implementation guides
- Comfortable leading customer discussions while also executing technical work.
Experience & Background
- 7+ years in security, identity, or Microsoft cloud roles
- 3+ years delivering Microsoft 365 security solutions end-to-end
- Experience in consulting, MSP, or professional services environments
- Proven ability to own projects from discovery through deployment
- Hands-on experience designing and deploying identity governance controls (access reviews, entitlement management, access certification)
Certifications (Preferred)
- Microsoft Certified: Security Solutions Architect Expert (SC‐100)
- Microsoft Certified: Identity and Access Administrator (SC‐300)
- Microsoft Certified: Information Protection Administrator (SC‐400)
- CISSP / CCSP (nice-to-have, not required)
What This Role Is Not
- Not a whiteboard-only or advisory-only architect
- Not a ticket-driven operations role
- Not a junior engineering position
What Success Looks Like
- Architected solutions are successfully deployed, not shelved
- SOWs accurately reflect technical reality
- Customers trust you to both design and build
- Security controls work as intended and survive real-world usage
- Engagements scale into repeatable service offerings
- ...Cloud Security Architect – Azure Focus Hybrid WFH in Chicago or Austin – 3 days onsite, 2 days WFH Summary This is a Cloud Security... ...with our GRC teams to ensure SOC 2 Type II and ISO 27001 compliance is maintained with the cloud security architecture. This role...SuggestedWork from home
- ...fully remote contract opportunity.As their Architect you will provide subject matter... ...Design, implement, and troubleshoot network security solutions using Palo Alto, FortiGate, ClearPass... ...in Zero Trust architecture and PCI 4.0 compliance.Act as a 3rd-level support resource for...SuggestedContract workRemote work
$240k - $280k
twentysix is looking for an experienced Security Engineer to create and drive the security roadmap while managing compliance automation programs like SOC 2 and ISO 27001. The ideal candidate should have over 7 years of security engineering experience and demonstrated leadership...SuggestedHome office$65.52 - $101.56 per hour
...Highlights: Position: Enterprise Security Architect Location: Skokie, IL Full Time... ...threat landscapes and regulatory compliance. Expert at securing IT platforms according... .../Color/Sex/Sexual Orientation/ Gender Identity/Religion/National Origin/Disability/...SuggestedHourly payFull timePart timeFor contractorsLocal areaMonday to Friday$122.68k - $200.74k
...support critical data protection initiatives. This role entails providing engineering design for security tools, assisting in project management, and ensuring compliance with standards. Ideal candidates will have at least 5 years of relevant experience and familiarity...Suggested- ...Title: Senior Security Architect - SaaS / Cloud Platforms Location: Chicago, IL or Phoenix,... ...findings across multiple domains (ex: identity + data + access) Key Focus Areas... ...posture evaluation Frameworks & Compliance Candidates must be familiar with:...Work experience placementWork at office
$160k - $200k
...teams to enable them to build and enhance security in EWS products and Services in line... ...are in line with security policy and are compliance to the required frameworks (ISO, PCI, OWASP... ..., genetic information, gender, gender identity, gender expression, age, national origin...Hourly payWork at officeImmediate startVisa sponsorshipWork visaFlexible hours$130k - $150k
...Security Risk Architect Location Atlanta, Boston, Chicago, Houston, Los Angeles, New... ...configurations Vulnerability & Compliance Management Oversee vulnerability management... ..., sex, sexual orientation, gender identity or expression, national origin, age,...Permanent employmentH1bWork at officeLocal areaWorldwideHome office$184.87k - $324.19k
...currently seeking a Director, SAP Enterprise Architect - Finance for our Consulting practice.... ..., age, sex, sexual orientation, gender identity, national origin, citizenship status,... ...contains further information regarding KPMG's compliance with federal, state and local...H1bLocal area- ...Technology at Swoon Swoon is actively seeking a Sr. Cyber Security Engineer/Architect to join the team! US Citizen or Permanent Resident/Green Card... ...about new Cyber Security Architect jobs in Chicago, IL . Identity Security Practice - Director, Professional Services -...Permanent employmentContract workRemote work
- ...Sr. Information Security Architect – AI & Cloud Security Washington, District of Columbia;Chicago, Illinois; Denver, Colorado To proceed... ...AI RMF). • Broad experience across cloud platforms (AWS), identity, key management, secrets management, networking, containers,...Work at officeShift workDay shift
$52 - $74 per hour
...Financial Services client is seeking a Lead Security Architect to join their enterprise security team... ...SaaS platforms, cloud environments, identity management, and enterprise... ...vendors from a cybersecurity, risk, and compliance perspective Support enterprise identity...Work at officeLocal area3 days per week$120k - $175k
...Technology Cyber Security Architect Cooley is seeking a Cyber Security Architect to join the technology team. Position summary: Cooley... ...experience. ~ Strong knowledge of network security, identity and access management (IAM), encryption, and endpoint security...Full timeTemporary workWork at officeFlexible hoursWeekend work$46.64 - $72.29 per hour
...other factors. Position Highlights: Position: IT Security Engineer II- Identity Access and Management Location: 4901 Searle Pkwy... ...as experience with healthcare-specific applications and compliance frameworks such as HIPAA, HITRUST, and NIST. The IAM Security...Hourly payFull timePart timeFor contractorsRemote workMonday to Friday$46.64 - $72.29 per hour
...IT Security Engineer II- Identity Access and Management Hourly Pay Range: $46.64 - $72.29 - The hourly pay rate offered is determined by a candidate... ...as experience with healthcare-specific applications and compliance frameworks such as HIPAA, HITRUST, and NIST. The IAM...Hourly payFull timeFor contractorsRemote workMonday to Friday$140k - $165k
...individualized care, a culture focused on compliance and ethics, supportive user-centric... ...to hear from you. The Role As a Senior Security Engineer, you'll harden the security posture... ...controls across infrastructure, identity, and CI/CD. The work is hands-on: configuring...Full time- ...Security Engineer Location: Chicago, IL or New York, NY (Hybrid) Overview... ...engineering, cloud infrastructure security, identity management, and threat monitoring . The... ...implementing security controls, and supporting compliance initiatives in a highly regulated...
- ...Senior Enterprise Security Architect Consultant Halo Group is a premier provider of IT talent. We place technology experts within the teams... ...expertise in one or many security technologies – such as identity management, protective monitoring, encryption, cloud security...Permanent employmentFull time
- Hiring a senior level AppSec Architect for the expansion of security organization and formal buildout of Application Security program of a 200 person company. Company offers a platform that simplifies running cloud-based desktops and IT infrastructure (Azure VD, M365, Win...Remote work
- ...Data Security Architect (DLP / Microsoft Purview) Position: Data Security Architect (DLP / Microsoft Purview): Client: Gallagher Type:... ...governance: playbooks, SOPs, risk assessments, exceptions. - Compliance frameworks: TOGAF, NIST CSF, ISO 27001, CSA CCM, PCI-DSS, GDPR...Contract work
$184.87k - $324.19k
...currently seeking a Director, SAP Enterprise Architect - Supply Chain for our Consulting... ...religion, age, sex, sexual orientation, gender identity, national origin, citizenship status,... ...further information regarding KPMG's compliance with federal, state and local recruitment...H1bLocal area$150k - $195k
...are seeking an experienced Director of Identity & Access Management (IAM Lead) to establish... ...leadership role within our Information Security function, responsible for evaluating our... ...You will partner closely with security, compliance, and business stakeholders to ensure our...Full timeTemporary workWork at officeLocal area$184k - $230k
...Security Architecture Consultant At Early Warning, we've powered and protected the U.... ...are in line with security policy and are compliance to the required frameworks (ISO, PCI, NIST... ..., genetic information, gender, gender identity, gender expression, age, national origin...Hourly payWork at officeImmediate startVisa sponsorshipWork visaFlexible hours- ...Application Security Solution Architect Denver, Colorado;Washington, District of Columbia; Chicago... ...methodology which support automated security compliance integration within different pipeline... ...genetic information, gender, gender identity, gender expression, age, national...Work at officeShift workDay shift
$172k - $225.7k
...platform, Snowflake requires a secure-by-design foundation to drive... .... As a Senior Security Architect on the Applied Field Engineering... ...robust foundations across Identity, Data, and Infrastructure for... ...deployments. Resilience & Compliance: Guide customers through end...Flexible hours$175k - $195k
...need to own their future. We are seeking a senior-level AI Security Architect to help clients design, secure, and scale enterprise AI and... ...AWS, or GCP) and cloud security capabilities. Expertise in identity and access management (IAM), data protection, API security,...$130k - $170k
...Please visit our employer awards page: As a Cloud Security Architect within Credera's Security and Privacy capability group, you... ...clients identify and remediate cloud security exposures across identity, access, and workload configurations. This role focuses...H1bRemote workWorldwideFlexible hours2 days per week$150k - $185k
...Cloud Security Architect (DevSecOps) A growing technology organization is seeking a Cloud Security... ...workflows Evaluate and improve identity and access management practices... ...encryption, and monitoring Support compliance and regulatory requirements Collaborate...$122.4k - $228k
...design and maturity of end-to-end cloud security across multi-cloud environments (AWS, Azure... ...(All Cloud Security Pillars) Identity & Access Management (IAM / CIEM) - least... ...Posture (CSPM/CNAPP) - misconfigurations, compliance, risk visibility CSPM / CNAPP Define...Contract workPart timeLocal areaImmediate start- ...nature of their businessCloud Security ArchitectWe are seeking an experienced Cloud Security Architect to design and drive security... ...Cloud environments — including identity & access management,... ...automation tooling.Familiarity with compliance frameworks (NIST, ISO, CIS Benchmarks...Remote work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to M365 Identity, Security & Compliance Architect. Be the first to apply!
- cloud security architect Chicago, IL
- cyber security architect Chicago, IL
- aws security architect Chicago, IL
- security architect Chicago, IL
- assistant vice president compliance Chicago, IL
- mortgage compliance Chicago, IL
- regulatory compliance associate Chicago, IL
- regulatory compliance analyst Chicago, IL
- vendor compliance Chicago, IL
- ethics compliance Chicago, IL

