5-7 years of experience in systems architecture and engineering
Deep expertise in Microsoft 365 and Entra ID, including multi-tenant scenarios
Strong knowledge of endpoint architecture with Microsoft Intune and Apple Business Manager
Proficient in identity and access management design, including SSO and conditional access
Familiarity with Azure cloud infrastructure and integration with internal systems
Experience in designing integrations and automation across SaaS platforms
Prior experience with M&A technology due diligence and tenant migrations preferred
Responsibilities
Define and maintain the target-state architecture for internal systems
Author and enforce technical standards for configuration and security
Own the identity architecture across Entra ID and connected SaaS
Design integration architecture for internal business systems
Assess acquired companies' technology stacks and define migration plans
Evaluate emerging platforms and lead proofs of concept
Partner with IT security to embed Zero Trust principles into platform design
Maintain architecture documentation for broader team understanding
Benefits
Remote work flexibility
Opportunity to shape long-term technology strategy
Engagement in high-impact projects involving M&A
Collaboration with cross-functional teams
Access to professional development resources
Full Job Description
Systems Engineer, Architecture
Department: IS&T
Employment Type: Full Time
Location: Shield Technology Partners - Remote
Compensation: $140,000 - $165,000 / year
Description
The Systems Engineer, Architecture owns the long-term design of Shield's internal technology environment. Where day-to-day operations keep systems running, this role decides what those systems should look like in two to five years and defines the standards, roadmap, and reference designs to get there. You will own the architecture of our core platforms, including Microsoft 365, Entra ID, Intune, Azure, and our SaaS ecosystem, and ensure that every new tool, integration, and acquired environment fits a coherent, secure, and scalable design.
Key Responsibilities
Architecture Ownership: Define and maintain the target-state architecture for Shield's internal systems, including identity, endpoint, collaboration, and cloud platforms. Maintain the technology roadmap and sequence changes to get from current state to target state.
Standards and Governance: Author and enforce technical standards for configuration, security baselines, naming, tenancy, and integration patterns. Serve as the design authority for new tooling and platform changes.
Identity and Access Design: Own the identity architecture across Entra ID and connected SaaS, including SSO, SCIM provisioning, conditional access, and privileged access models. Design for scale as new entities and users are added.
Integration Architecture: Design how internal business systems connect, including HRIS-driven provisioning, PSA and ticketing platforms, and automation flows. Set the patterns that engineers implement.
M&A Integration Design: Assess acquired companies' technology stacks, define migration and consolidation plans for tenants, identity, and endpoints, and establish repeatable integration playbooks.
Platform Lifecycle Planning: Evaluate emerging platforms and plan the retirement and replacement of legacy systems. Lead proofs of concept and produce decision records with clear rationale and tradeoffs.
Security Architecture: Partner with IT security to embed Zero Trust principles, device compliance, encryption, MFA, and EDR coverage into platform design rather than bolting them on afterward.
Documentation: Maintain architecture diagrams, design standards, and decision records so the environment is understandable and supportable by the broader IS&T team.
Skills, Knowledge & Expertise
Architecture Mindset: Ability to think in systems and lifecycles, weigh tradeoffs, and design for where the organization will be rather than where it is today.
Microsoft 365 and Entra ID: Deep, design-level experience with M365 tenancy, Exchange, SharePoint, Teams, and Entra ID, including multi-tenant and tenant consolidation scenarios.
Endpoint Architecture: Expert knowledge of Microsoft Intune and Apple Business Manager, including policy design, compliance frameworks, and zero-touch provisioning for Windows and macOS.
Identity and Access Management: Strong command of IAM design, including SSO, SAML, OIDC, SCIM, conditional access, and role-based and privileged access models.
Cloud Infrastructure: Working knowledge of Azure (AWS a plus), including identity integration, networking fundamentals, and how cloud services connect to internal business systems.
Integration and Automation: Experience designing integrations and automation across SaaS platforms using APIs, iPaaS tools, PowerShell, or Graph API.
Security Fundamentals: Familiarity with security frameworks and remote-first best practices, including Zero Trust, disk encryption, MFA enforcement, and EDR.
M&A Experience: Prior exposure to technology due diligence, tenant migrations, or environment consolidation is strongly preferred.
Communication: Ability to explain architectural decisions to both technical and non-technical stakeholders and to document designs clearly.