Posting DetailsPosting Details
Job # 043135
Department Code 20703-6031
Department Information Technology Services
Job Title IT Architect
Location Syracuse, NY
Campus Syracuse, NY
Pay Range $94,000- $100,000
Pay Determination Pay rates at Syracuse University are based on a combination of factors including, but not limited to, the job responsibilities; the candidate's education, training, work experience and key competencies; the university's strategic priorities; internal peer equity; applicable federal, state, local laws, grant funding and contractual requisites; and external market analyses.
Staff Level S6
FLSA Status Exempt
Hours Standard University business hours
8:30am - 5:00pm (academic year)
8:00am - 4:30pm (summer)
Hours may vary based on operational needs.
Job Type Full-time
Unionized Position Code Not Applicable
Job Description The incumbent of the role is expected to design, develop, and maintain enterprise identity and infrastructure management platforms serving distributed IT administrators across global campuses. Serves as technical architect for hybrid and cloud-first identity, authentication, and device lifecycle systems, bridging legacy on-premises infrastructure with modern cloud services. Architects integrations between on-premises Active Directory, Entra ID, and Microsoft Graph API to support centralized administration of identity, access control, and endpoint management at enterprise scale. Translates complex operational requirements into scalable, maintainable tooling and automation. Evaluates cost and implementation timelines for new infrastructure solutions and thoroughly documents changes, architectural decisions, and system functionality. Responds to security incidents affecting infrastructure systems and mitigates vulnerabilities across identity and authentication services.
Education and Experience - Bachelor's degree or 4 years of experience in computing technology or equivalent combination of experience and education.
- Experience in integration of on-premises and cloud-based computing infrastructures.
Skills and Knowledge - Experience architecting enterprise management platforms and automation tooling
- Proficiency in PowerShell and C#/.NET for systems development and integration
- Experience with DevOps practices: version control, CI/CD, and infrastructure as code
- Deep knowledge of Entra ID, Conditional Access, and Microsoft Graph API
- Experience with smartcard/PIV, FIDO2/passkeys, and certificate-based authentication
- Experience with PKI, certificate lifecycle management, and trust chain administration
- Experience with Intune and Autopilot endpoint management
- ETL experience with logging formats and reporting tools including Splunk
- Experience with cybersecurity best practices including access control, least privilege, and incident response
- Microsoft 365 administration and cloud service integration
- Ability to convey complex technical information to technical and non-technical audiences, orally and in writing
- Working knowledge of AI-driven decision support tools and their potential to streamline and improve business processes. Ability to identify opportunities where AI solutions can reduce manual effort and support data-driven decision making. Familiarity with AI assistants (such as Anthropic's Claude, Microsoft Copilot, ChatGPT, or similar tools) and a willingness to apply them in functional analysis and documentation activities
Responsibilities - Platform Architecture and Development. Design, develop, and maintain enterprise CLI tooling and automation platforms for identity and infrastructure management operations using C#/.NET and PowerShell. Architect and implement integrations with Microsoft Graph API and related cloud service APIs. Define and maintain platform architecture including module structure, authentication flows, permission models, and extensibility patterns. Manage full software development lifecycle including version control, testing, deployment, and documentation for tools used by distributed IT administrators across multiple campuses.
- Identity and Access Management Architecture. Architect and administer Entra ID tenant infrastructure including device lifecycle management, Conditional Access policies, access packages, and hybrid identity synchronization. Design and implement tiered permission models supporting principle of least privilege across distributed administrative teams. Plan and execute migration strategies for transitioning on-premises Active Directory services to cloud-native identity solutions while maintaining operational continuity.
- Authentication Infrastructure. Design and maintain enterprise authentication systems including smartcard/PIV enrollment and lifecycle, FIDO2/passkey deployment, and certificate-based authentication. Manage PKI trust chains and certificate lifecycle processes for enterprise authentication services. Troubleshoot complex multi-layer authentication flows spanning network, certificate, and identity provider components.
- Device Lifecycle and Endpoint Management. Architect and support Autopilot and Intune-based device provisioning and management pipelines. Design and implement automated device lifecycle operations including enrollment, compliance monitoring, baseline configuration, and decommissioning at scale. Develop and maintain fleet-wide remediation and hygiene automation for endpoint and device object management.
- Security and Incident Response. Evaluate security risks to infrastructure systems including identity, authentication, and endpoint management services, and recommend architectural mitigations. Participate in incident response for infrastructure-layer security events. Assess vendor and third-party access requests for appropriate scope, delegation model, and compliance with security standards.
Physical Requirements Not Applicable
Tools/Equipment Not Applicable
Application Instructions In addition to completing an online application, please attach a resume and cover letter.
Quick Link https://www.sujobopps.com/postings/114665
Job Posting Date 09/28/2026
Application DeadlineFull Consideration ByJob Category Staff
Message to Applicants