M365 Architect Identity, Security & Compliance Architect
LaSalle Network · Chicago, IL · 1 mo ago
Information Technology$180k–$200k/yrContract
Core Responsibilities
Lead security and compliance discovery workshops and technical assessments.
Translate business drivers, risk tolerance, and regulatory requirements into deployable Microsoft architectures, not theoretical designs.
Support Sales and Presales by:
- Defining scope and assumptions
- Identifying technical risks and dependencies
- Contributing directly to SOWs, implementation plans, and phased roadmaps
- Clearly articulate what will be configured, how, and why in customer-facing documentation.
Architecture & Design (Practical, Deployable Designs)
Design end-to-end Microsoft 365 security and compliance solutions aligned to:
- Zero Trust principles
- Microsoft best practices
- Customer operational maturity
Hands-On Deployment & Configuration
Identity & Access
- Implement and tune Microsoft Entra ID configurations:
- Conditional Access policies
- MFA and passwordless authentication (WHfB, Passkey/FIDO2, TAP)
- Single Sign-On (OIDC/SAML)
- Identity Protection policies
- Privileged Identity Management (PIM)
- Lifecycle Workflows for joiner/mover/leaver scenarios
- Configure hybrid identity integrations where required.
- Deploy And Operationalize Microsoft Entra ID Governance Capabilities
- Entitlement Management – access packages, catalogs, and connected organizations for external/B2B access
- Access Reviews for groups, applications, and privileged roles
- Lifecycle Workflows automating joiner / mover / leaver processes
- Separation of duties and access certification controls
- Terms of Use policies and approval/governance workflows
- Onboard and operationalize Microsoft Defender for Endpoint:
- Attack surface reduction rules
- Device groups and policy targeting
- Integration with Defender XDR Threat Protection & XDR
- Deploy and configure Microsoft Defender XDR, including:
- Defender for Office 365
- Defender for Identity
- Defender for Cloud Apps
- Validate telemetry, alerts, and investigation workflows.
- Ensure integrations across Defender components function as designed.
- Implement Microsoft Purview capabilities:
- Sensitivity labels and label policies
- Data Loss Prevention (Endpoint, M365, Cloud Apps)
- Data lifecycle and retention policies
- Validate deployed configurations against design intent.
- Perform policy testing and non-disruptive validation where required.
- Deliver operational handoff documentation and knowledge transfer.
- Advise customers on ongoing tuning, operational ownership, and future roadmap phases.
- Microsoft Security & Compliance (Hands-On)
- Microsoft Entra ID – advanced configuration experience
- Microsoft Entra ID Governance – hands-on experience with entitlement management, access reviews, and lifecycle workflows
- Microsoft Defender XDR – cross-solution deployment and integration
- Microsoft Purview – real-world labeling, DLP, and retention deployments
- Architecture & Consulting Skills
- Ability to design solutions that are deployable in real customer tenants
- Strong documentation skills for: Architecture diagrams, Design documents, Implementation guides
- Comfortable leading customer discussions while also executing technical work
- Experience in consulting, MSP, or professional services environments
- Proven ability to own projects from discovery through deployment
- Hands-on experience designing and deploying identity governance controls (access reviews, entitlement management, access certification)
Identity Governance
Endpoint & Device Security
Information Protection & Compliance
Required Technical Skills & Experience
Key Details
Compensation: $180,000-200,000 annually
Benefits: Medical, Dental, and Vision insurance available