Solutions & Platform Architect - Microsoft
- Full-time
- Department: Information Technology
- Compensation: USD 145000 - USD 165000 - yearly
Company Description
Trupanion is a leading provider of medical insurance for cats and dogs in North America. Our mission is to help loving, responsible pet owners budget and care for their pets. At Trupanion, we offer a collaborative, casual, and pet-friendly environment where everyone is encouraged to be themselves.
Job Description
US – Seattle only: This position is open to candidates in the Seattle, WA area. You will have a hybrid remote/in-office schedule where you will work from our casual, pet-friendly office at least 3 days a week (Tuesday, Wednesday, and Thursday). Remote candidate may be considered based on experience.
The Solutions & Platform Architect – Microsoft serves as the organization's technical authority for Microsoft Identity, Security, Endpoint Management, and Zero Trust architecture. This role will lead the design, engineering, deployment, and operational maturity of Microsoft Entra ID, Identity Governance, Policies, Intune, Windows Autopilot, Defender, Global Secure Access, and Microsoft 365 security/E5 capabilities.
The ideal candidate combines deep hands-on engineering expertise with enterprise architecture capabilities and has successfully delivered complex identity transformations including Active Directory modernization, password less authentication, cloud-first endpoint management, and Zero Trust initiatives. This individual will partner closely with Technology Operations, Information Security, Infrastructure, Compliance, Service Desk, and business stakeholders to develop and execute Trupanion's Microsoft platform roadmap.
Responsibilities:
Identity Modernization
- Lead Active Directory dependency reduction initiatives.
- Develop and execute Entra-first identity architecture strategy.
- Design and implement Microsoft Entra Cloud Sync.
- Lead migration from Entra Connect architecture where appropriate.
- Assess and reduce authentication dependencies.
- Drive ADFS retirement planning and execution.
- Establish identity source-of-authority governance
Authentication & Access Management
- Lead Microsoft's passwordless authentication strategy.
- Implement Microsoft Authenticator and Passkeys.
- Design Windows Hello for Business deployment.
- Implement Cloud Kerberos Trust architecture.
- Develop phishing-resistant authentication standards.
- Establish authentication lifecycle standards.
Endpoint Modernization
- Lead Intune transformation initiatives.
- Design cloud-first endpoint management standards.
- Drive GPO-to-Intune migration programs.
- Implement CIS benchmark controls through Intune.
- Modernize Windows deployment and provisioning services.
- Establish device lifecycle standards.
Entra Join & Autopilot Transformation
- Lead Hybrid AD to Entra Join transition strategies.
- Architect Autopilot modernization initiatives.
- Implement Cloud Kerberos Trust integrations.
- Design deployment and enrollment standards.
- Remove legacy dependencies impacting modern deployments.
Secure Access Architecture
- Lead evaluation of Microsoft Global Secure Access.
- Design Entra Private Access architecture.
- Design Entra Internet Access architecture.
- Develop coexistence and migration strategies from Zscaler.
- Conduct proof-of-concept testing.
- Create migration roadmaps and operational support models.
Identity Governance
- Evaluate and implement Entra Identity Governance capabilities.
- Design Joiner-Mover-Leaver workflows.
- Develop automated access certification processes.
- Integrate identity lifecycle management with HR systems.
- Improve role-based access governance and compliance.
Automation & Engineering
- Develop PowerShell automation solutions.
- Utilize Microsoft Graph APIs.
- Automate provisioning and reporting.
- Reduce operational overhead through engineering practices.
- Build self-service capabilities for users and support teams.
Skills
- Microsoft Entra ID, Conditional Access, Identity governance, PIM, Cloud sync, Entra connect, ADFS, SSO, MFA, Authentication flow.
- Microsoft Intune, SCCM, Autopilot, Entra join, hybrid join, Windows update for business, CIS benchmarks, GPO migration
- GSA, Entra Private Access, Entra Internet Access, Private Application Access
- Powershell, Microsoft Graph, REST APIs, Azure Automation
- Independent technical ownership, mentoring, cross-functional collaboration, and clear communication with technical and non-technical audiences
Qualifications
Required Qualifications
- 8+ years Microsoft infrastructure engineering
- 5+ years Microsoft identity engineering
- 5+ years Microsoft 365 administration and architecture
- 5+ years Intune and endpoint engineering
- Experience leading enterprise transformation programs
- Experience designing Zero Trust architecture
- Experience supporting regulated or compliance-driven environments
Additional Information
Compensation:
- The base salary range for this position is $145,000 - $165,000 on a full-time schedule.
- Along with base compensation, Trupanion employees are currently eligible for monthly bonuses.
- We want all employees to be invested in Trupanion’s success, so we grant Restricted Stock Units to all new team members. Our new hire grants vest over 4 years.
Benefits and Perks:
- Full medical, dental, and vision benefits at no cost to the employee
- Four weeks of paid time off and 9 paid float holidays (you can decide which days are most important to you!)
- Five-week sabbatical after five years of employment
- Open, casual, pet-friendly, and fun office environment
- Free medical health insurance for your pet (1 dog or cat)
- Paid time off to volunteer at nonprofit organizations
- Seattle Office Amenities: Free on-site gym, free dog walking services for office pets during business hours, free parking, and paid ORCA cards.
For more information about Trupanion, visit https://trupanion.com/about
Learn more about how Trupanion has revolutionized our industry and the reimbursement model: https://www.youtube.com/watch?v=vdWZ4KHiPTQ
Trupanion is an equal-opportunity employer and embraces diversity. We are committed to building a team that represents a variety of backgrounds, abilities, perspectives, and skills.
We will ensure that individuals are provided reasonable accommodation to participate in the job application or interview process, perform essential job functions, and receive other benefits and privileges of employment. Please contact us to request accommodations.
Applicants must be authorized to work for any employer in the U.S. We are unable to sponsor or take over sponsorship of an employment visa at this time.
By clicking the link above or any third-party link within this posting, you are leaving this site and going to a third-party website where the third-party website's terms and privacy policy apply