Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Senior Principal/Architect (Identity & Security)

$225k - $304k

West Monroe

Are you ready to make an impact?

Senior Principal/Architect (Identity & Security) 

Overview

West Monroe is seeking a Senior Principal/Architect (Identity & Security) to lead cross-functional teams in the design, remediation, and modernization of complex identity and cloud infrastructure solutions. This role focuses on securing and transforming critical IT environments for a diverse portfolio of clients, helping them navigate complex Active Directory modernizations, cloud identity migrations, and security hardening initiatives. This opportunity provides technical leadership in transforming complex IT environments across key industry verticals, including Healthcare, Financial Services, Private Equity, and High Tech. While the scope spans hybrid and cloud identity, the work is particularly grounded in Active Directory as a core Tier 0 platform, with strong Microsoft Entra ID expertise to design and operate modern hybrid identity patterns. 

Responsibilities

  • Partner with consultants and client leadership to  architect, build, and deploy secure and modern Active Directory and Microsoft Entra ID solutions. 

  • Assess current-state identity environments and processes, interview stakeholders, define critical requirements, and present practical solution strategies and roadmaps to client executives. 

  • Lead the technical design of future-state Active Directory (AD DS) and Entra ID architectures, including privileged access management (PAM) design, tiered administrative access models (e.g., Microsoft’s Enterprise Access Model (EAM)), and identity consolidation strategies. 

  • Establish and enforce identity architecture standards, best practices, and governance to deliver secure, compliant, and consistent solutions aligned with industry benchmarks (e.g., CIS and** Microsoft baselines)**. 

  • Lead security assessment and remediation planning, including  consolidating findings from tools (e.g., Purple Knight, Maester, CIS Benchmark-based configuration assessments (e.g., CIS-CAT)) to create and manage prioritized, risk-based remediation backlogs. 

  • Provide  expert technical oversight for security remediation initiatives, such as hardening domain controllers, remediating privileged access, resolving Entra Connect sync issues, and restricting legacy protocols. 

  • Develop detailed implementation plans, migration strategies, and  remediation backlogs (e.g., in Smartsheet or similar project management tools) for AD restructuring, AD consolidation, identity synchronization, and legacy decommissioning. 

  • Establish and manage engagement-level  governance, quality, and risk , including defining quantitative success criteria, RACI, and clear communications to both technical and executive stakeholders. 

  • Support key decision-making on project direction, including technology selections, team workstreams, and delivery methodologies. 

  • Mentor junior consultants on technical best practices, solution design, and client engagement. 

  • Assist business development efforts through proposals, pre-sales technical discovery, and client presentations. 

Qualifications

  • Bachelor’s degree in a relevant field preferred, or equivalent experience required. 

  • Prior experience in consulting preferred. 

  • 8–12+ years of experience in IT architecture, engineering, and/or security with a deep focus on identity solutions. 

  • Expert-level knowledge of  Active Directory Domain Services (AD DS)design, security, and administration, including: domain/forest architecture,  sites/replication, DNS, Group Policy (GPO) management, DC virtualization safeguards, and forest recovery principles. 

  • Strong experience with  Microsoft Entra ID (formerly Azure AD), including Entra Connect, Conditional Access, modern authentication methods, and Privileged Identity Management (PIM). 

  • Proven experience leading identity migrations (including on-premises to cloud, cross-forest restructurings, and Tenant-to-Tenant (cross-tenant) consolidations), AD remediations, and/or consolidation projects. 

  • Experience designing and implementing hybrid authentication patterns between AD DS and Microsoft Entra ID, including pass-through authentication (PTA), Seamless SSO, Cloud Kerberos Trust, and phishing-resistant authentication methods. 

  • Proficiency in designing and implementing enterprise  Privileged Access Management (PAM)solutions (including typical platforms like CyberArk, Delinea, or similar) and  tiered administrative access models (e.g., Tier 0/1/2, Microsoft’s Enterprise Access Model (EAM)). 

  • Hands-on experience with Active Directory and Microsoft Entra ID security assessment and testing tools (e.g., Purple Knight, PingCastle, Maester, Microsoft Defender for Identity or similar AD threat detection platforms) and hardening methodologies (e.g., CIS Benchmarks and Microsoft security baselines). 

  • Proficiency with AD security hardening techniques such as KRBTGT password rotations, restricting NTLM, Group Policy object (GPO) cleanup, Local Administrator Password Solution (LAPS), implementing resource-based Kerberos constrained delegation (RBKCD), and configuring LDAP signing. 

  • Familiarity with migration and directory protection tools (e.g., Quest On-Demand Migration) and identity-driven application dependencies. 

  • Strong communication (written and verbal), presentation, client management, and team leadership skills. 

  • Willingness to travel for out-of-town client engagements. 

  • Bonus skills:

  • Familiarity with compliance standards (e.g., NIST, HIPAA, ISO). 

  • Advanced scripting for automation and analysis (e.g.,  PowerShell ). 

  • Knowledge of  Infrastructure as Code (Terraform)and  DevSecOps practices. 

  • Familiarity with application dependency and network flow mapping tools (e.g., Device42, Faddom) used to discover AD-integrated application dependencies and support migration planning or microsegmentation boundaries. 

  • Familiarity with Active Directory resilience and recovery tooling (e.g., Semperis, ADEngine) is a plus. 

  • Experience migrating from on-premises Active Directory Certificate Services (AD CS) to cloud-native PKI solutions is a plus. 

  • Familiarity with enterprise  Identity Governance and Administration (IGA)platforms (e.g., SailPoint, Saviynt) to manage and improve periodic access certifications (e.g., moving from spreadsheets to a tool) and run detective Segregation of Duties (SoD) reports. 

  • Experience  automating identity lifecycles by replacing nightly batch files from a Human Resources Information System (HRIS) with Application Programming Interface (API)-driven syncs or establishing governance for non-employee/contractor identities. 

  • Understanding of System for Cross-domain Identity Management** (SCIM)** or API-based provisioning to automate Joiner-Mover-Leaver (JML) workflows for  Software as a Service (SaaS)apps, expanding beyond just core directories and email. 

  • Experience with Tier-0 threat monitoring and detection strategies, including security event logging and SIEM integration with Active Directory and other Tier 0 assets. 

  • Professional certifications (e.g., Microsoft Identity/SC series, CISSP, CyberArk/Delinea). 

  • Occasional exposure to CIAM platforms (e.g., Microsoft Entra External ID, Okta, Auth0) and associated migration/implementation patterns is a plus but not a core requirement. 

What to Expect

  • A collaborative, flexible, and outcomes-driven consulting environment. 

  • A culture that values inclusion, diverse perspectives, and teamwork. 

  • A business-focused and industry-specific approach to deploying technology that helps clients tackle their most significant challenges and deliver tangible results, free from rigid hierarchies. 

  • While the role spans a broad range of identity technologies and tools,  no candidate is expected to be an expert in every item listed . We are seeking deep strength in Tier-0 Active Directory security and modernization, paired with strong Microsoft Entra ID knowledge and the curiosity to rapidly master adjacent areas. 

Ready to get started? Join the team and make an impact. 

Based on pay transparency guidelines, the salary range for this role can vary based on your proximity to one of our West Monroe offices (see table below). Information on our competitive total rewards package, including our bonus structure and benefits is  here . Individual salaries are determined by evaluating a variety of factors including geography, experience, skills, education, and internal equity.

Employees (and their families) are covered by medical, dental, vision, and basic life insurance. Employees are able to enroll in our company’s 401k plan, purchase shares from our employee stock ownership program and be eligible to receive annual bonuses. Employees will also receive unlimited flexible time off and ten paid holidays throughout the calendar year. Eligibility for ten weeks of paid parental leave will also be available upon hire date. 

Seattle or Washington, D.C.

$236,300—$277,700 USD

Los Angeles

$247,500—$291,000 USD

New York City or San Francisco

$258,800—$304,200 USD

A location not listed above

$225,000—$264,500 USD

Other consultancies talk at you.

At West Monroe, we work with you.

We’re a global business and technology consulting firm passionate about creating measurable value for our clients, delivering real-world solutions.

The combination of business and technology is not new, but how we bring them together is unique. We’re fluent in both. We know that technology alone is not the answer, but how we apply it is. We rely on data to constantly adapt and solve new challenges. Actions that work today with outcomes that generate value for years to come.

At West Monroe, we zero in on the heart of the opportunity, getting to results faster and preparing people for what’s next.

You’ll feel the difference in how we work. We show up personally. We’re right there in the room with you, co-creating through the challenges. With West Monroe, collaboration isn’t a lofty promise, but a daily action. We work together with you to turn vision into clear action with lasting impact.

West Monroe **   ****is an Equal Employment Opportunity Employer **  
We believe in treating each employee and applicant for employment fairly and with dignity. We base our employment decisions on merit, experience, and potential, without regard to race, color, national origin, sex, sexual orientation, gender identity, marital status, age, religion, disability, veteran status, or any other characteristic prohibited by federal, state or local law. To learn more about diversity, equity and inclusion at West Monroe, visit  . If you require a reasonable accommodation to participate in our recruiting process, please inquire by sending an email to View email address on swooped.co .

Please review our current policy regarding use of generative artificial intelligence during the application process .

If you are based in California, we encourage you to read West Monroe’s Notice at Collection for California residents, provided pursuant to the California Consumer Privacy Act (CCPA) and linked  here .  

Vacancy posted more than 2 months ago
Similar jobs that could be interesting for youBased on the Senior Principal/Architect (Identity & Security) in Los Angeles, CA vacancy
  • $142.5k - $190k

    A prominent entertainment agency is seeking a Principal Architect to lead the design of technology infrastructure spanning on-premises and cloud...  .... This role focuses on Microsoft Azure, driving zero-trust security models, and creating a multi-year infrastructure roadmap.... 
    Principal
    Senior

    IMG LIVE

    Beverly Hills, CA
    3 days ago
  • $132.4k - $251.6k

     ...transferable U.S. government issued security clearance is required prior to...  ...Systems department is seeking a Senior Principal Electrical Subsystem Architect to lead architecture development...  ..., sex, sexual orientation, gender identity, national origin, age, disability... 
    Principal
    Senior
    Temporary work
    Work experience placement
    Work at office
    Remote work
    Relocation package
    Flexible hours

    Raytheon

    Los Angeles, CA
    2 hours ago
  • $146.4k - $219.6k

    About the Role Senior Principal Integration Architect focused on Enterprise Integration, ETL & Event Streaming...  ...onboarding and certification Secure file‑based and message‑based data exchanges...  ..., sex, sexual orientation, gender identity and/or expression, genetic... 
    Principal
    Senior
    Temporary work
    Local area
    Flexible hours

    USA-Medtronic MiniMed, Inc 1017

    Los Angeles, CA
    19 hours ago
  • A leading professional services firm is seeking a Digital Identity SME to enhance user experience and reduce risk through robust identity...  ...Microsoft Entra and Saviynt with responsibilities including architecting identity governance solutions and mentoring junior staff. The... 
    Senior

    EY

    Los Angeles, CA
    1 day ago
  • $143k - $170k

     ...News Channel is searching for a Senior IAM & SaaS Engineer in Los...  .... This pivotal role involves architecting scalable IAM solutions, guiding...  ..., and enhancing the security posture across a complex digital...  ...experience along with expertise in identity & access management and... 
    Senior

    FOX News Channel

    Los Angeles, CA
    1 day ago
  • $137.4k - $206k

     ...mission-enabling solutions for global security. Our Engineering and Sciences (E&S) organization...  .... Basic Qualifications for a Senior Principal EMI/EMC Electrical Engineer:...  ...creed, sex, sexual orientation, gender identity, marital status, national origin, age,... 
    Principal
    Senior
    Full time
    Relocation package
    Monday to Thursday
    Shift work

    Northrop Grumman

    Los Angeles, CA
    2 days ago
  • Saviynt's AI-powered identity platform manages and governs human and non-human access to all of an organization's applications, data, and...  ...usage of AI. Saviynt is recognized as the leader in identity security, with solutions that protect and empower the world’s leading brands... 

    Saviynt

    El Segundo, CA
    1 day ago
  • $180k - $220k

     ...Pentera is the global leader in Automated Security Validation, helping organizations...  ...system behaviors across operating systems, identity systems, cloud platforms, and enterprise...  ...Pentera's automated validation platform Architect and implement decision-making logic that... 
    Principal
    Senior
    Work at office
    Remote work
    Worldwide

    Pentera

    Los Angeles, CA
    2 days ago
  • $114k - $171k

     ...mission-enabling solutions for global security. Our Engineering and Sciences (E&S) organization...  ...Systems are seeking a skilled Principal or Senior Principal Systems Engineer in...  ...creed, sex, sexual orientation, gender identity, marital status, national origin, age,... 
    Principal
    Senior
    Full time
    Contract work
    Relocation package
    Shift work

    Northrop Grumman

    Los Angeles, CA
    19 hours ago
  • $112.2k - $176.3k

     ...enabling solutions for global security. We have a wide portfolio of...  ...for you to join our team as a Principal Program Cost Control Analyst...  ...What You'll Get to Do The Senior Principal Program Control...  ..., sexual orientation, gender identity, marital status, national origin... 
    Principal
    Senior
    Relocation
    Shift work

    Northrop Grumman

    Los Angeles, CA
    1 day ago
  •  ...IMG LIVE is seeking a Senior Digital Workplace Engineer to enhance workplace technology across Microsoft 365 and other endpoints. This position involves significant autonomy, where the candidate will shape technology strategy and deliver large-scale enterprise solutions... 
    Senior

    IMG Live

    Beverly Hills, CA
    3 days ago
  • $141.6k - $212.4k

     ...more connected, compassionate world. About the Role The Senior Principal Cloud Security Architect is the single‑threaded owner of cloud security...  ...Establish secure‑by‑default reference architectures covering identity, network segmentation, encryption, logging, and... 
    Principal
    Senior
    Temporary work
    Local area
    Flexible hours

    USA-Medtronic MiniMed, Inc 1017

    Los Angeles, CA
    1 day ago
  • $166.4k - $249.6k

     ...analysis-based decision support to senior leaders on space...  ...missions across the national security space (NSS) enterprise. DSG is...  ...as a go-to Sr. Cybersecurity Architect working in the United States...  ...orientation, gender, gender identity or expression, color,religion... 
    Senior
    Full time
    For contractors
    Work at office
    Immediate start
    Remote work
    Relocation package
    Flexible hours

    The Aerospace Corporation

    El Segundo, CA
    19 hours ago
  • Mattel is seeking a Senior Manager of Identity & Access Management to lead IAM engineering, operations, and initiatives supporting enterprise identity security. This role will drive modernization efforts involving SSO, MFA, and Zero Trust security while collaborating closely... 
    Senior

    Mattel

    El Segundo, CA
    1 day ago
  •  ...opportunities for growth, and ensuring customer satisfaction with Saviynt's offerings. The ideal candidate will have a strong background in Identity and Access Management, with experience in SaaS environments. Saviynt offers competitive benefits including medical, 401K, and... 
    Senior

    Medium

    El Segundo, CA
    19 hours ago
  • $160k - $175k

     ...Executive to drive sales of their cloud security and access governance solutions. This professional...  ...California, focusing on enterprise identity and privileged access management...  ...landscape and established relationships at senior levels. A competitive salary range of $1... 
    Senior

    Saviynt

    Los Angeles, CA
    19 hours ago
  • Saviynt is seeking a Customer Success Manager to oversee customer loyalty and adoption of its innovative identity management products. This role is essential for driving value-based outcomes, ensuring customer happiness, and expanding the business. Ideal candidates will... 
    Senior

    Saviynt

    El Segundo, CA
    3 days ago
  • $145k - $175k

     ...respected, design-led Architecture & Design practice seeking a Senior Interior Architect to join its Los Angeles office. This firm is widely...  ...exposure to some of the most innovative architectural work in the country. Senior Interior Architect - Associate Principal... 
    Principal
    Senior
    Work at office
    Los Angeles, CA
    17 days ago
  • $114k - $171k

     ...enabling solutions for global security. Our Engineering and Sciences...  ...position may be filled as a Principal Modeling, Simulation and Analysis Systems Engineer or a Senior Principal Modeling, Simulation...  ..., sexual orientation, gender identity, marital status, national... 
    Principal
    Senior
    Full time
    Relocation package
    Shift work

    Navstar

    Los Angeles, CA
    19 hours ago
  •  ...of mission-enabling solutions for global security. Our Emerging Capabilities Development...  ...mission success. Basic Qualifications for a Principal Navigation Systems Engineer: ~5 years...  ...creed, sex, sexual orientation, gender identity, marital status, national origin, age,... 
    Principal
    Senior
    Full time
    Relocation package
    Shift work

    Northrop Grumman

    Los Angeles, CA
    4 days ago
  • $114k - $171k

     ...of mission-enabling solutions for global security. Our Emerging Capabilities Development...  ...This requisition may be filled at either a Principal Level or a Sr. Principal Level. Basic...  ...creed, sex, sexual orientation, gender identity, marital status, national origin, age,... 
    Principal
    Senior
    Full time
    Relocation package
    Shift work

    Northrop Grumman

    Los Angeles, CA
    5 days ago
  • $142.5k

     ...WME is seeking a Principal Architect, Infrastructure to lead the overall...  ...work closely across IT and security teams to rapidly iterate on...  ...infrastructure domain areas (network, identity, compute, data) and are well...  ...5 years in a principal or senior architect capacity ~... 
    Principal
    Temporary work
    Local area

    Endeavor

    Beverly Hills, CA
    2 hours ago
  • $156.4k - $234.6k

     ...enabling solutions for global security. Our Engineering and Sciences...  ...to join our team as a Sr. Principal Digital Engineer based out of...  ...our development program leads, senior scientists, engineering and manufacturing...  ..., sexual orientation, gender identity, marital status, national... 
    Principal
    Senior
    Full time
    Relocation package
    Shift work

    Northrop Grumman Corp. (JP)

    Los Angeles, CA
    3 days ago
  • $173.6k - $215k

     ...Posting Title Principal Digital Architect - Ecommerce & Enterprise AI...  ...digital touchpoint. As a senior technology leader and thought...  ...personalized, scalable, and secure customer experiences. You will...  ...religion, sex, gender, gender identity or expression, sexual orientation... 
    Principal
    Local area

    Mattel, Inc.and Subsidiaries

    El Segundo, CA
    2 days ago
  •  ...sees, trusts, and acts on data. As a Principal I, Power BI Architect , you'll design and scale enterprise...  ...teams to deliver reliable, secure, and easy-to-use analytics experiences...  ...aligned with enterprise architecture and identity patterns. Performance Optimization... 
    Principal
    Temporary work
    Flexible hours

    Herbalife

    Los Angeles, CA
    1 day ago
  • $100k - $130k

     ...we can find. The Role: We are seeking highly skilled Senior Architects and project leaders experienced in the planning, design and...  ...citizenship status, age, disability or handicap, sex, gender identity, marital status, familial status, veteran status, sexual orientation... 
    Senior
    Local area

    Grimshaw-Architects

    Los Angeles, CA
    3 days ago
  • $130k - $155k

     ...Overall Responsibilities: As a licensed Architect, responsible for guiding design teams...  ...opportunities for staff. -Assist Principal-in-Charge, Project Manager, and Project...  ...religion, sex, sexual orientation, gender identity, national origin, or protected veteran status... 
    Senior
    Temporary work
    Work at office
    Local area

    Steinberg

    Los Angeles, CA
    4 days ago
  •  ...About the Role We are seeking a Senior AI Architect - Enterprise Integrations to join our growing...  ...business requirements into scalable, secure, and maintainable AI-powered solutions...  ..., color, religion, sex, gender, gender identity or expression, sexual orientation, national... 
    Senior
    Worldwide

    IBM

    Los Angeles, CA
    4 days ago
  • $150k - $170k

    Rocket Money in Los Angeles is seeking a Brand Director to spearhead the development and execution of brand identity. Reporting to the VP of Marketing, you will lead a variety of projects in collaboration with product research teams. The ideal candidate should have 7+... 
    Senior

    Rocket Money

    Los Angeles, CA
    1 day ago
  • $119.3k - $179k

     ...integrated design practice. Our architects, engineers, interior...  ...We are actively seeking a Senior Project Architect. You are expected...  ...Collaborate with the team leadership (principal, project manager, project...  ..., sexual orientation, gender identity or gender expression. We... 
    Senior
    Full time
    Temporary work
    Part time
    For contractors
    For subcontractor
    Casual work
    Work at office
    Local area
    Flexible hours

    Stantec

    Los Angeles, CA
    3 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Senior Principal/Architect (Identity & Security). Be the first to apply!