Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

M365 Identity, Security & Compliance Architect

Group Nine LLC

M365 Identity, Security & Compliance Architect (Architecture & Deployment)

The Microsoft 365 Security & Compliance Architect is a senior, hands-on technical role responsible for architecting, designing, and deploying Microsoft security and compliance solutions across customer environments. This role is accountable for taking engagements from discovery and presales through implementation and operational readiness, not just producing designs. The Architect serves as both:

  • The technical authority during presales and solution definition, and
  • The hands-on lead during deployment, configuration, and validation of Microsoft 365 security and compliance controls.

This role operates in a consulting environment and requires comfort switching between customer-facing advisory work and deep technical execution.

Core Responsibilities

Presales, Discovery & Solution Definition

  • Lead security and compliance discovery workshops and technical assessments.
  • Translate business drivers, risk tolerance, and regulatory requirements into deployable Microsoft architectures, not theoretical designs.
  • Support Sales and Presales by:
  • Defining scope and assumptions
  • Identifying technical risks and dependencies
  • Contributing directly to SOWs, implementation plans, and phased roadmaps
  • Clearly articulate what will be configured, how, and why in customer-facing documentation.

Architecture & Design (Practical, Deployable Designs)

  • Design end-to-end Microsoft 365 security and compliance solutions aligned to:
  • Zero Trust principles
  • Microsoft best practices
  • Customer operational maturity
  • Produce architecture and design artifacts that are intended to be implemented, including:
    • Identity and access models
    • Endpoint security baselines
    • Data protection and DLP strategies
    • Threat protection and incident response workflows
  • Define phased deployment approaches that balance speed, risk, and organizational readiness.

Hands-On Deployment & Configuration

The Architect is expected to personally deploy and configure solutions:

Identity & Access

  • Implement and tune Microsoft Entra ID configurations:
  • Conditional Access policies
  • MFA and passwordless authentication (WHfB, Passkey/FIDO2, TAP)
  • Single Sign-On (OIDC/SAML)
  • Identity Protection policies
  • Privileged Identity Management (PIM)
  • Lifecycle Workflows for joiner/mover/leaver scenarios
  • Configure hybrid identity integrations where required.

Identity Governance

  • Deploy and operationalize Microsoft Entra ID Governance capabilities:
  • Entitlement Management – access packages, catalogs, and connected organizations for external/B2B access
  • Access Reviews for groups, applications, and privileged roles
  • Lifecycle Workflows automating joiner / mover / leaver processes
  • Separation of duties and access certification controls
  • Terms of Use policies and approval/governance workflows
  • Experience migrating from SailPoint to Entra ID Governance is highly desirable.

Endpoint & Device Security

  • Onboard and operationalize Microsoft Defender for Endpoint:
  • Attack surface reduction rules
  • Device groups and policy targeting
  • Integration with Defender XDR

Threat Protection & XDR

  • Deploy and configure Microsoft Defender XDR, including:
  • Defender for Office 365
  • Defender for Identity
  • Defender for Cloud Apps
  • Validate telemetry, alerts, and investigation workflows.
  • Ensure integrations across Defender components function as designed.

Information Protection & Compliance

  • Implement Microsoft Purview capabilities:
  • Sensitivity labels and label policies
  • Data Loss Prevention (Endpoint, M365, Cloud Apps)
  • Data lifecycle and retention policies

Validation, Handoff & Enablement

  • Validate deployed configurations against design intent.
  • Perform policy testing and non-disruptive validation where required.
  • Deliver operational handoff documentation and knowledge transfer.
  • Advise customers on ongoing tuning, operational ownership, and future roadmap phases.

Required Technical Skills & Experience

Microsoft Security & Compliance (Hands-On)

  • Microsoft Entra ID – advanced configuration experience
  • Microsoft Entra ID Governance – hands-on experience with entitlement management, access reviews, and lifecycle workflows
  • Microsoft Defender XDR – cross-solution deployment and integration
  • Microsoft Purview – real-world labeling, DLP, and retention deployments

Architecture & Consulting Skills

  • Ability to design solutions that are deployable in real customer tenants
  • Strong documentation skills for:
  • Architecture diagrams
  • Design documents
  • Implementation guides
  • Comfortable leading customer discussions while also executing technical work.

Experience & Background

  • 7+ years in security, identity, or Microsoft cloud roles
  • 3+ years delivering Microsoft 365 security solutions end-to-end
  • Experience in consulting, MSP, or professional services environments
  • Proven ability to own projects from discovery through deployment
  • Hands-on experience designing and deploying identity governance controls (access reviews, entitlement management, access certification)

Certifications (Preferred)

  • Microsoft Certified: Security Solutions Architect Expert (SC‐100)
  • Microsoft Certified: Identity and Access Administrator (SC‐300)
  • Microsoft Certified: Information Protection Administrator (SC‐400)
  • CISSP / CCSP (nice-to-have, not required)

What This Role Is Not

  • Not a whiteboard-only or advisory-only architect
  • Not a ticket-driven operations role
  • Not a junior engineering position

What Success Looks Like

  • Architected solutions are successfully deployed, not shelved
  • SOWs accurately reflect technical reality
  • Customers trust you to both design and build
  • Security controls work as intended and survive real-world usage
  • Engagements scale into repeatable service offerings
Vacancy posted 2 days ago
Similar jobs that could be interesting for youBased on the M365 Identity, Security & Compliance Architect in Chicago, IL vacancy
  •  ...Cloud Security Architect – Azure Focus Hybrid WFH in Chicago or Austin – 3 days onsite, 2 days WFH Summary This is a Cloud Security...  ...with our GRC teams to ensure SOC 2 Type II and ISO 27001 compliance is maintained with the cloud security architecture. This role... 
    Suggested
    Work from home

    1872 Consulting

    Chicago, IL
    3 days ago
  •  ...fully remote contract opportunity.As their Architect you will provide subject matter...  ...Design, implement, and troubleshoot network security solutions using Palo Alto, FortiGate, ClearPass...  ...in Zero Trust architecture and PCI 4.0 compliance.Act as a 3rd-level support resource for... 
    Suggested
    Contract work
    Remote work

    Motion Recruitment

    Chicago, IL
    16 hours ago
  • $240k - $280k

    twentysix is looking for an experienced Security Engineer to create and drive the security roadmap while managing compliance automation programs like SOC 2 and ISO 27001. The ideal candidate should have over 7 years of security engineering experience and demonstrated leadership... 
    Suggested
    Home office

    twentysix

    Chicago, IL
    3 days ago
  • $65.52 - $101.56 per hour

     ...Highlights: Position: Enterprise Security Architect Location: Skokie, IL Full Time...  ...threat landscapes and regulatory compliance. Expert at securing IT platforms according...  .../Color/Sex/Sexual Orientation/ Gender Identity/Religion/National Origin/Disability/... 
    Suggested
    Hourly pay
    Full time
    Part time
    For contractors
    Local area
    Monday to Friday

    Endeavor Health Services

    Skokie, IL
    1 day ago
  • $122.68k - $200.74k

     ...support critical data protection initiatives. This role entails providing engineering design for security tools, assisting in project management, and ensuring compliance with standards. Ideal candidates will have at least 5 years of relevant experience and familiarity... 
    Suggested

    Elevance Health

    Chicago, IL
    2 days ago
  •  ...Title: Senior Security Architect - SaaS / Cloud Platforms Location: Chicago, IL or Phoenix,...  ...findings across multiple domains (ex: identity + data + access) Key Focus Areas...  ...posture evaluation Frameworks & Compliance Candidates must be familiar with:... 
    Work experience placement
    Work at office

    Spectraforce Technologies

    Chicago, IL
    7 days ago
  • $160k - $200k

     ...teams to enable them to build and enhance security in EWS products and Services in line...  ...are in line with security policy and are compliance to the required frameworks (ISO, PCI, OWASP...  ..., genetic information, gender, gender identity, gender expression, age, national origin... 
    Hourly pay
    Work at office
    Immediate start
    Visa sponsorship
    Work visa
    Flexible hours

    Early Warning Services

    Chicago, IL
    2 days ago
  • $130k - $150k

     ...Security Risk Architect Location Atlanta, Boston, Chicago, Houston, Los Angeles, New...  ...configurations Vulnerability & Compliance Management Oversee vulnerability management...  ..., sex, sexual orientation, gender identity or expression, national origin, age,... 
    Permanent employment
    H1b
    Work at office
    Local area
    Worldwide
    Home office

    L.E.K. Consulting

    Chicago, IL
    16 hours ago
  • $184.87k - $324.19k

     ...currently seeking a Director, SAP Enterprise Architect - Finance for our Consulting practice....  ..., age, sex, sexual orientation, gender identity, national origin, citizenship status,...  ...contains further information regarding KPMG's compliance with federal, state and local... 
    H1b
    Local area

    KPMG

    Chicago, IL
    4 days ago
  •  ...Technology at Swoon Swoon is actively seeking a Sr. Cyber Security Engineer/Architect to join the team! US Citizen or Permanent Resident/Green Card...  ...about new Cyber Security Architect jobs in Chicago, IL . Identity Security Practice - Director, Professional Services -... 
    Permanent employment
    Contract work
    Remote work

    Swoon

    Chicago, IL
    10 days ago
  •  ...Sr. Information Security Architect – AI & Cloud Security Washington, District of Columbia;Chicago, Illinois; Denver, Colorado To proceed...  ...AI RMF). • Broad experience across cloud platforms (AWS), identity, key management, secrets management, networking, containers,... 
    Work at office
    Shift work
    Day shift

    Bank of America

    Chicago, IL
    1 day ago
  • $52 - $74 per hour

     ...Financial Services client is seeking a Lead Security Architect to join their enterprise security team...  ...SaaS platforms, cloud environments, identity management, and enterprise...  ...vendors from a cybersecurity, risk, and compliance perspective Support enterprise identity... 
    Work at office
    Local area
    3 days per week

    KellyMitchell Group

    Chicago, IL
    1 day ago
  • $120k - $175k

     ...Technology Cyber Security Architect Cooley is seeking a Cyber Security Architect to join the technology team. Position summary: Cooley...  ...experience. ~ Strong knowledge of network security, identity and access management (IAM), encryption, and endpoint security... 
    Full time
    Temporary work
    Work at office
    Flexible hours
    Weekend work

    Cooley

    Chicago, IL
    1 day ago
  • $46.64 - $72.29 per hour

     ...other factors. Position Highlights: Position: IT Security Engineer II- Identity Access and Management Location: 4901 Searle Pkwy...  ...as experience with healthcare-specific applications and compliance frameworks such as HIPAA, HITRUST, and NIST. The IAM Security... 
    Hourly pay
    Full time
    Part time
    For contractors
    Remote work
    Monday to Friday

    NorthShore University HealthSystem

    Skokie, IL
    3 days ago
  • $46.64 - $72.29 per hour

     ...IT Security Engineer II- Identity Access and Management Hourly Pay Range: $46.64 - $72.29 - The hourly pay rate offered is determined by a candidate...  ...as experience with healthcare-specific applications and compliance frameworks such as HIPAA, HITRUST, and NIST. The IAM... 
    Hourly pay
    Full time
    For contractors
    Remote work
    Monday to Friday

    Endeavor Health Services

    Skokie, IL
    2 days ago
  • $140k - $165k

     ...individualized care, a culture focused on compliance and ethics, supportive user-centric...  ...to hear from you. The Role As a Senior Security Engineer, you'll harden the security posture...  ...controls across infrastructure, identity, and CI/CD. The work is hands-on: configuring... 
    Full time

    Beyond Finance, Inc.

    Chicago, IL
    3 days ago
  •  ...Security Engineer Location: Chicago, IL or New York, NY (Hybrid) Overview...  ...engineering, cloud infrastructure security, identity management, and threat monitoring . The...  ...implementing security controls, and supporting compliance initiatives in a highly regulated... 

    Artius Solutions

    Chicago, IL
    1 day ago
  •  ...Senior Enterprise Security Architect Consultant Halo Group is a premier provider of IT talent. We place technology experts within the teams...  ...expertise in one or many security technologies – such as identity management, protective monitoring, encryption, cloud security... 
    Permanent employment
    Full time

    Sonoma Consulting

    Oak Brook, IL
    2 days ago
  • Hiring a senior level AppSec Architect for the expansion of security organization and formal buildout of Application Security program of a 200 person company. Company offers a platform that simplifies running cloud-based desktops and IT infrastructure (Azure VD, M365, Win... 
    Remote work

    Vaco Recruiter Services

    Chicago, IL
    4 days ago
  •  ...Data Security Architect (DLP / Microsoft Purview) Position: Data Security Architect (DLP / Microsoft Purview): Client: Gallagher Type:...  ...governance: playbooks, SOPs, risk assessments, exceptions. - Compliance frameworks: TOGAF, NIST CSF, ISO 27001, CSA CCM, PCI-DSS, GDPR... 
    Contract work

    Argyle Infotech

    Chicago, IL
    2 days ago
  • $184.87k - $324.19k

     ...currently seeking a Director, SAP Enterprise Architect - Supply Chain for our Consulting...  ...religion, age, sex, sexual orientation, gender identity, national origin, citizenship status,...  ...further information regarding KPMG's compliance with federal, state and local recruitment... 
    H1b
    Local area

    KPMG

    Chicago, IL
    4 days ago
  • $150k - $195k

     ...are seeking an experienced Director of Identity & Access Management (IAM Lead) to establish...  ...leadership role within our Information Security function, responsible for evaluating our...  ...You will partner closely with security, compliance, and business stakeholders to ensure our... 
    Full time
    Temporary work
    Work at office
    Local area

    Cresset Capital

    Chicago, IL
    3 days ago
  • $184k - $230k

     ...Security Architecture Consultant At Early Warning, we've powered and protected the U....  ...are in line with security policy and are compliance to the required frameworks (ISO, PCI, NIST...  ..., genetic information, gender, gender identity, gender expression, age, national origin... 
    Hourly pay
    Work at office
    Immediate start
    Visa sponsorship
    Work visa
    Flexible hours

    Early Warning Services

    Chicago, IL
    1 day ago
  •  ...Application Security Solution Architect Denver, Colorado;Washington, District of Columbia; Chicago...  ...methodology which support automated security compliance integration within different pipeline...  ...genetic information, gender, gender identity, gender expression, age, national... 
    Work at office
    Shift work
    Day shift

    Bank of America

    Chicago, IL
    1 day ago
  • $172k - $225.7k

     ...platform, Snowflake requires a secure-by-design foundation to drive...  .... As a Senior Security Architect on the Applied Field Engineering...  ...robust foundations across Identity, Data, and Infrastructure for...  ...deployments. Resilience & Compliance: Guide customers through end... 
    Flexible hours

    Snowflake Computing

    Chicago, IL
    16 hours ago
  • $175k - $195k

     ...need to own their future. We are seeking a senior-level AI Security Architect to help clients design, secure, and scale enterprise AI and...  ...AWS, or GCP) and cloud security capabilities. Expertise in identity and access management (IAM), data protection, API security,... 

    Huron Consulting Group Inc.

    Chicago, IL
    16 hours ago
  • $130k - $170k

     ...Please visit our employer awards page: As a Cloud Security Architect within Credera's Security and Privacy capability group, you...  ...clients identify and remediate cloud security exposures across identity, access, and workload configurations. This role focuses... 
    H1b
    Remote work
    Worldwide
    Flexible hours
    2 days per week

    Credera Experienced Hiring Job Board

    Chicago, IL
    2 days ago
  • $150k - $185k

     ...Cloud Security Architect (DevSecOps) A growing technology organization is seeking a Cloud Security...  ...workflows Evaluate and improve identity and access management practices...  ...encryption, and monitoring Support compliance and regulatory requirements Collaborate... 

    The LaSalle Network Inc

    Chicago, IL
    1 day ago
  • $122.4k - $228k

     ...design and maturity of end-to-end cloud security across multi-cloud environments (AWS, Azure...  ...(All Cloud Security Pillars) Identity & Access Management (IAM / CIEM) - least...  ...Posture (CSPM/CNAPP) - misconfigurations, compliance, risk visibility CSPM / CNAPP Define... 
    Contract work
    Part time
    Local area
    Immediate start

    BMO Financial Group

    Chicago, IL
    5 days ago
  •  ...nature of their businessCloud Security ArchitectWe are seeking an experienced Cloud Security Architect to design and drive security...  ...Cloud environments — including identity & access management,...  ...automation tooling.Familiarity with compliance frameworks (NIST, ISO, CIS Benchmarks... 
    Remote work

    Staffing Science

    Chicago, IL
    16 hours ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to M365 Identity, Security & Compliance Architect. Be the first to apply!