Solutions & Platform Architect - Microsoft

TrupanionSeattle, WA
$145,000 - $165,000Hybrid

About The Position

The Solutions & Platform Architect – Microsoft serves as the organization's technical authority for Microsoft Identity, Security, Endpoint Management, and Zero Trust architecture. This role will lead the design, engineering, deployment, and operational maturity of Microsoft Entra ID, Identity Governance, Policies, Intune, Windows Autopilot, Defender, Global Secure Access, and Microsoft 365 security/E5 capabilities. The ideal candidate combines deep hands-on engineering expertise with enterprise architecture capabilities and has successfully delivered complex identity transformations including Active Directory modernization, password less authentication, cloud-first endpoint management, and Zero Trust initiatives. This individual will partner closely with Technology Operations, Information Security, Infrastructure, Compliance, Service Desk, and business stakeholders to develop and execute Trupanion's Microsoft platform roadmap.

Requirements

  • 8+ years Microsoft infrastructure engineering
  • 5+ years Microsoft identity engineering
  • 5+ years Microsoft 365 administration and architecture
  • 5+ years Intune and endpoint engineering
  • Experience leading enterprise transformation programs
  • Experience designing Zero Trust architecture
  • Experience supporting regulated or compliance-driven environments
  • Microsoft Entra ID, Conditional Access, Identity governance, PIM, Cloud sync, Entra connect, ADFS, SSO, MFA, Authentication flow.
  • Microsoft Intune, SCCM, Autopilot, Entra join, hybrid join, Windows update for business, CIS benchmarks, GPO migration
  • GSA, Entra Private Access, Entra Internet Access, Private Application Access
  • Powershell, Microsoft Graph, REST APIs, Azure Automation
  • Independent technical ownership, mentoring, cross-functional collaboration, and clear communication with technical and non-technical audiences

Responsibilities

  • Lead Active Directory dependency reduction initiatives.
  • Develop and execute Entra-first identity architecture strategy.
  • Design and implement Microsoft Entra Cloud Sync.
  • Lead migration from Entra Connect architecture where appropriate.
  • Assess and reduce authentication dependencies.
  • Drive ADFS retirement planning and execution.
  • Establish identity source-of-authority governance
  • Lead Microsoft's passwordless authentication strategy.
  • Implement Microsoft Authenticator and Passkeys.
  • Design Windows Hello for Business deployment.
  • Implement Cloud Kerberos Trust architecture.
  • Develop phishing-resistant authentication standards.
  • Establish authentication lifecycle standards.
  • Lead Intune transformation initiatives.
  • Design cloud-first endpoint management standards.
  • Drive GPO-to-Intune migration programs.
  • Implement CIS benchmark controls through Intune.
  • Modernize Windows deployment and provisioning services.
  • Establish device lifecycle standards.
  • Lead Hybrid AD to Entra Join transition strategies.
  • Architect Autopilot modernization initiatives.
  • Implement Cloud Kerberos Trust integrations.
  • Design deployment and enrollment standards.
  • Remove legacy dependencies impacting modern deployments.
  • Lead evaluation of Microsoft Global Secure Access.
  • Design Entra Private Access architecture.
  • Design Entra Internet Access architecture.
  • Develop coexistence and migration strategies from Zscaler.
  • Conduct proof-of-concept testing.
  • Create migration roadmaps and operational support models.
  • Evaluate and implement Entra Identity Governance capabilities.
  • Design Joiner-Mover-Leaver workflows.
  • Develop automated access certification processes.
  • Integrate identity lifecycle management with HR systems.
  • Improve role-based access governance and compliance.
  • Develop PowerShell automation solutions.
  • Utilize Microsoft Graph APIs.
  • Automate provisioning and reporting.
  • Reduce operational overhead through engineering practices.
  • Build self-service capabilities for users and support teams.

Benefits

  • Full medical, dental, and vision benefits at no cost to the employee
  • Four weeks of paid time off
  • 9 paid float holidays
  • Five-week sabbatical after five years of employment
  • Free medical health insurance for your pet (1 dog or cat)
  • Paid time off to volunteer at nonprofit organizations
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service