远程工作雷达

解决方案与平台架构师 - 微软

Solutions & Platform Architect - Microsoft

开发工程限定地区(需当地身份)
公司Trupanion
薪资$145,000 - $165,000/年
工作地点United States
地域资格限定地区(需当地身份)
时区要求日间重叠约 9 小时,基本正常作息
用工类型Full Time
发布时间今天
数据来源Himalayas
前往 Himalayas 查看并投递 →
注意地域限制:该职位明确限定在 United States 招聘。如果你是位于中国大陆的求职者,通常需要当地工作身份才能投递,或需与雇主确认是否接受独立合同(Contractor)形式合作。

美国-远程:此职位为远程岗位,面向美国任何地区的候选人。远程候选人必须能够按照太平洋时区时间工作。位于西雅图大区的候选人需每周至少三天(星期二、星期三和星期四)在我们轻松友好的、允许宠物进入的办公室进行混合远程/现场办公。
解决方案与平台架构师 – 微软负责组织在微软身份、安全、端点管理及零信任架构方面的技术权威。该职位将领导 Microsoft Entra ID、身份治理、策略、Intune、Windows Autopilot、Defender、全球安全访问以及 Microsoft 365 安全/E5 功能的设计、工程、部署和运营成熟度。
理想的候选人具备深厚的实际工程经验与企业架构能力,并成功完成过复杂的身份转型项目,包括 Active Directory 现代化、无密码认证、以云为中心的端点管理及零信任计划。该人员将与技术运营、信息安全、基础设施、合规、服务台及业务利益相关者紧密合作,制定并执行 Trupanion 的 Microsoft 平台路线图。
职责:
身份现代化

  • 领导减少对 Active Directory 依赖的举措。
  • 制定并执行以 Entra 为核心的 Identity 架构策略。
  • 设计并实施 Microsoft Entra Cloud Sync。
  • 在适当情况下领导从 Entra Connect 架构迁移。
  • 评估并减少身份验证依赖。
  • 推动 ADFS 退役计划与执行。
  • 建立身份权威治理标准。

身份验证与访问管理

  • 领导微软的无密码身份验证策略。
  • 实施 Microsoft Authenticator 和 Passkeys。
  • 设计 Windows Hello for Business 部署。
  • 实施 Cloud Kerberos Trust 架构。
  • 开发防钓鱼的身份验证标准。
  • 建立身份验证生命周期标准。

端点现代化

  • 领导 Intune 转型举措。
  • 设计以云为中心的端点管理标准。
  • 推动 GPO 到 Intune 的迁移计划。
  • 通过 Intune 实现 CIS 基准控制。
  • 现代化 Windows 部署和配置服务。
  • 建立设备生命周期标准。

Entra Join 与 Autopilot 转型

  • 领导从混合 AD 到 Entra Join 的转换策略。
  • 架构自动化部署方案。
查看英文原文

US – Remote: This is a remote position open to candidates anywhere in the United States. Remote candidates must be available to work Pacific Time Zone hours. Candidates based in the greater Seattle area will work a hybrid remote/in-office schedule from our casual, pet-friendly office at least 3 days a week (Tuesday, Wednesday, and Thursday).
The Solutions & Platform Architect – Microsoft serves as the organization's technical authority for Microsoft Identity, Security, Endpoint Management, and Zero Trust architecture. This role will lead the design, engineering, deployment, and operational maturity of Microsoft Entra ID, Identity Governance, Policies, Intune, Windows Autopilot, Defender, Global Secure Access, and Microsoft 365 security/E5 capabilities.
The ideal candidate combines deep hands-on engineering expertise with enterprise architecture capabilities and has successfully delivered complex identity transformations including Active Directory modernization, password less authentication, cloud-first endpoint management, and Zero Trust initiatives. This individual will partner closely with Technology Operations, Information Security, Infrastructure, Compliance, Service Desk, and business stakeholders to develop and execute Trupanion's Microsoft platform roadmap.
Responsibilities:
Identity Modernization

  • Lead Active Directory dependency reduction initiatives.
  • Develop and execute Entra-first identity architecture strategy.
  • Design and implement Microsoft Entra Cloud Sync.
  • Lead migration from Entra Connect architecture where appropriate.
  • Assess and reduce authentication dependencies.
  • Drive ADFS retirement planning and execution.
  • Establish identity source-of-authority governance

Authentication & Access Management

  • Lead Microsoft's passwordless authentication strategy.
  • Implement Microsoft Authenticator and Passkeys.
  • Design Windows Hello for Business deployment.
  • Implement Cloud Kerberos Trust architecture.
  • Develop phishing-resistant authentication standards.
  • Establish authentication lifecycle standards.

Endpoint Modernization

  • Lead Intune transformation initiatives.
  • Design cloud-first endpoint management standards.
  • Drive GPO-to-Intune migration programs.
  • Implement CIS benchmark controls through Intune.
  • Modernize Windows deployment and provisioning services.
  • Establish device lifecycle standards.

Entra Join & Autopilot Transformation

  • Lead Hybrid AD to Entra Join transition strategies.
  • Architect Autopilot modernization initiatives.
  • Implement Cloud Kerberos Trust integrations.
  • Design deployment and enrollment standards.
  • Remove legacy dependencies impacting modern deployments.

Secure Access Architecture

  • Lead evaluation of Microsoft Global Secure Access.
  • Design Entra Private Access architecture.
  • Design Entra Internet Access architecture.
  • Develop coexistence and migration strategies from Zscaler.
  • Conduct proof-of-concept testing.
  • Create migration roadmaps and operational support models.

Identity Governance

  • Evaluate and implement Entra Identity Governance capabilities.
  • Design Joiner-Mover-Leaver workflows.
  • Develop automated access certification processes.
  • Integrate identity lifecycle management with HR systems.
  • Improve role-based access governance and compliance.

Automation & Engineering

  • Develop PowerShell automation solutions.
  • Utilize Microsoft Graph APIs.
  • Automate provisioning and reporting.
  • Reduce operational overhead through engineering practices.
  • Build self-service capabilities for users and support teams.

Skills

  • Microsoft Entra ID, Conditional Access, Identity governance, PIM, Cloud sync, Entra connect, ADFS, SSO, MFA, Authentication flow.
  • Microsoft Intune, SCCM, Autopilot, Entra join, hybrid join, Windows update for business, CIS benchmarks, GPO migration
  • GSA, Entra Private Access, Entra Internet Access, Private Application Access
  • Powershell, Microsoft Graph, REST APIs, Azure Automation
  • Independent technical ownership, mentoring, cross-functional collaboration, and clear communication with technical and non-technical audiences

Required Qualifications

  • 8+ years Microsoft infrastructure engineering
  • 5+ years Microsoft identity engineering
  • 5+ years Microsoft 365 administration and architecture
  • 5+ years Intune and endpoint engineering
  • Experience leading enterprise transformation programs
  • Experience designing Zero Trust architecture
  • Experience supporting regulated or compliance-driven environments

Compensation:

  • The base salary range for this position is $145,000 - $165,000 on a full-time schedule.
  • Along with base compensation, Trupanion employees are currently eligible for monthly bonuses.
  • We want all employees to be invested in Trupanion’s success, so we grant Restricted Stock Units to all new team members. Our new hire grants vest over 4 years.

Benefits and Perks:

  • Full medical, dental, and vision benefits at no cost to the employee
  • Four weeks of paid time off and 9 paid float holidays (you can decide which days are most important to you!)
  • Five-week sabbatical after five years of employment
  • Open, casual, pet-friendly, and fun office environment
  • Free medical health insurance for your pet (1 dog or cat)
  • Paid time off to volunteer at nonprofit organizations
  • Seattle Office Amenities: Free on-site gym, free dog walking services for office pets during business hours, free parking, and paid ORCA cards.

For more information about Trupanion, visit
Learn more about how Trupanion has revolutionized our industry and the reimbursement model:
Trupanion is an equal-opportunity employer and embraces diversity. We are committed to building a team that represents a variety of backgrounds, abilities, perspectives, and skills.
We will ensure that individuals are provided reasonable accommodation to participate in the job application or interview process, perform essential job functions, and receive other benefits and privileges of employment. Please contact us to request accommodations.
Applicants must be authorized to work for any employer in the U.S. We are unable to sponsor or take over sponsorship of an employment visa at this time.
Trupanion is a leading provider of medical insurance for cats and dogs in North America. Our mission is to help loving, responsible pet owners budget and care for their pets. At Trupanion, we offer a collaborative, casual, and pet-friendly environment where everyone is encouraged to be themselves.
Originally posted on Himalayas

本页面信息整理自 Himalayas,版权归原发布方所有。职位可能随时关闭,投递请以原始页面为准。 本站只做信息聚合展示,不参与招聘流程,也不向求职者收取任何费用。

该公司其他在招职位

← 返回全部职位