S
Principal Solution Architect ADFS Core, PKI & Active Directory
S
Principal Solution Architect ADFS Core, PKI & Active Directory
Sonata Software- Posted 9 hours ago
- Be among the first 10 applicants
Job Description
About Sonata Software
Sonata Software, with over $1.2 Billion Revenue, is a leading AI-first Modernization Engineering company, powered by our unique PlatformationTM framework. Our 6400+ AI Engineers are helping enterprises transform from systems to intelligent business platforms leveraging partner ecosystem to drive speed, efficiency and growth. Our bouquet of Modernization Engineering Services with AI -first approach cuts across Cloud, Data, AI, Dynamics, Test Automation, and Managed Services.
Sonata's AI-led modernization is enabled by a powerful suite of proprietary tools and assets. At the core is the Harmoni.AI Enterprise Platform, which includes AgentBridge -a governance and observability framework; Agent Builder -a development toolkit for fungible agents integrated into enterprise systems; and the Agent Marketplace -an internal ecosystem for modular, reusable agents.
Headquartered in Bengaluru, India, Sonata Software has a strong global presence, including key regions US, UK, India, Malaysia, Mexico, Australia, DACH (Germany/Switzerland) & Nordics (Finland). We are a trusted partner of Fortune 500 companies in Banking, Financial Services and Insurance; Healthcare and Lifesciences; Telecom, Media, and Technology; and Retail, Manufacturing and Distribution space.
Deep collaborations with partners like Microsoft, AWS, Salesforce, and Snowflake strengthen our ability to deliver cutting-edge AI solutions. Our 30+years of partnership with Microsoft, and being part of the elite Microsoft Inner Circle, places us among the top 1% of global Microsoft partners. Sonata is now among the first companies to earn the Microsoft Frontier Partner Badge Also; Sonata Software is proud to achieve AWS Premier Tier Status in the AWS Partner Network.
Principal Solution Architect – ADFS Core, PKI & Active Directory
Role Overview : We are looking for a highly experienced Principal Solution Architect with 15+ years of expertise in Microsoft Active Directory, Active Directory Federation Services (ADFS), Public Key Infrastructure (PKI), and Microsoft Identity technologies to join the CSA Global Delivery (CSA GD) team. The successful candidate will serve as a technical authority and architecture leader for complex enterprise identity, authentication, federation, directory services, and PKI engagements. The role requires deep hands-on technical expertise combined with the ability to define enterprise architectures, lead complex implementations and transformations, troubleshoot critical environments, and provide technical direction to engineering teams and customers. The architect will work closely with Microsoft customers, CSA teams, engineering teams, program managers, and other technology stakeholders to design secure, scalable, resilient, and modern identity solutions.
Key Responsibilities
Active Directory
The Candidate Should Demonstrate The Ability To
Experience Profile The Ideal Candidate Should Have
Sonata Software is an Equal Opportunity Employer encouraging diversity in the workplace. All qualified applicants will receive consideration for employment without regard to race, national origin, gender identity, age, religion, disability, sexual orientation, veteran status, marital status, or any other characteristics protected by law .
Sonata Software, with over $1.2 Billion Revenue, is a leading AI-first Modernization Engineering company, powered by our unique PlatformationTM framework. Our 6400+ AI Engineers are helping enterprises transform from systems to intelligent business platforms leveraging partner ecosystem to drive speed, efficiency and growth. Our bouquet of Modernization Engineering Services with AI -first approach cuts across Cloud, Data, AI, Dynamics, Test Automation, and Managed Services.
Sonata's AI-led modernization is enabled by a powerful suite of proprietary tools and assets. At the core is the Harmoni.AI Enterprise Platform, which includes AgentBridge -a governance and observability framework; Agent Builder -a development toolkit for fungible agents integrated into enterprise systems; and the Agent Marketplace -an internal ecosystem for modular, reusable agents.
Headquartered in Bengaluru, India, Sonata Software has a strong global presence, including key regions US, UK, India, Malaysia, Mexico, Australia, DACH (Germany/Switzerland) & Nordics (Finland). We are a trusted partner of Fortune 500 companies in Banking, Financial Services and Insurance; Healthcare and Lifesciences; Telecom, Media, and Technology; and Retail, Manufacturing and Distribution space.
Deep collaborations with partners like Microsoft, AWS, Salesforce, and Snowflake strengthen our ability to deliver cutting-edge AI solutions. Our 30+years of partnership with Microsoft, and being part of the elite Microsoft Inner Circle, places us among the top 1% of global Microsoft partners. Sonata is now among the first companies to earn the Microsoft Frontier Partner Badge Also; Sonata Software is proud to achieve AWS Premier Tier Status in the AWS Partner Network.
Principal Solution Architect – ADFS Core, PKI & Active Directory
Role Overview : We are looking for a highly experienced Principal Solution Architect with 15+ years of expertise in Microsoft Active Directory, Active Directory Federation Services (ADFS), Public Key Infrastructure (PKI), and Microsoft Identity technologies to join the CSA Global Delivery (CSA GD) team. The successful candidate will serve as a technical authority and architecture leader for complex enterprise identity, authentication, federation, directory services, and PKI engagements. The role requires deep hands-on technical expertise combined with the ability to define enterprise architectures, lead complex implementations and transformations, troubleshoot critical environments, and provide technical direction to engineering teams and customers. The architect will work closely with Microsoft customers, CSA teams, engineering teams, program managers, and other technology stakeholders to design secure, scalable, resilient, and modern identity solutions.
Key Responsibilities
- Solution Architecture & Design
- Lead architecture and design of complex Microsoft Identity and Access Management solutions.
- Develop enterprise architectures covering: o Active Directory Domain Services (AD DS)
- Active Directory Federation Services (ADFS)
- PKI / Active Directory Certificate Services (AD CS)
- Active Directory Domain Controllers
- DNS and Group Policy
- Windows authentication and authorization o Kerberos and NTLM
- LDAP
- Federation and SSO
- Hybrid identity
- Define High-Level Design (HLD), Low-Level Design (LLD), architecture diagrams, technical standards, and implementation strategies.
- Design highly available and resilient identity infrastructures across on-premises, hybrid, and cloud environments.
- Conduct architecture assessments and identify technical, security, scalability, and operational risks.
- Provide modernization strategies for legacy AD/ADFS/PKI environments.
- Active Directory – Principal-Level Expertise
- Provide deep architectural expertise in Active Directory Domain Services (AD DS).
- Design and optimize:
- Forest and domain architecture
- Domain/forest trusts
- Sites and Services
- Replication topology
- Global Catalog
- FSMO role
- DNS integration
- Group Policy architecture
- OU and delegation models
- Authentication architecture
- Troubleshoot complex AD issues involving:
- Replication failures
- Kerberos authentication
- DNS
- SYSVOL/DFSR
- Domain controller health
- Trust relationships o Authentication failures
- GPO processing
- Lead AD forest/domain migrations, consolidations, restructures, and modernization initiatives.
- Develop AD recovery and business continuity strategies, including forest recovery.
- ADFS Core
- Provide subject-matter expertise in Active Directory Federation Services (ADFS) architecture and implementation.
- Design and troubleshoot complex:
- ADFS farms o Federation services
- Web Application Proxy (WAP)
- Claims-based authentication
- Claims rules
- Relying Party Trusts
- Claims Provider Trusts
- SAML
- WS-Federation
- OAuth/OIDC integrations where applicable
- Design highly available and secure ADFS architectures.
- Troubleshoot complex authentication and federation issues.
- Analyze ADFS event logs, authentication flows, token issuance, certificates, and claims.
- Lead ADFS migrations, upgrades, farm redesigns, and modernization programs.
- Develop strategies for transitioning legacy ADFS workloads to modern cloud-based identity platforms where appropriate.
- PKI / Active Directory Certificate Services
- Provide principal-level architecture expertise in Microsoft PKI and Active Directory Certificate Services (AD CS).
- Design enterprise PKI architectures including:
- Root CA
- Subordinate/Issuing CA
- Offline Root CA
- Enterprise CA
- Standalone CA
- Certificate templates
- CRL
- OCSP
- AIA/CDP
- Design certificate lifecycle management strategies.
- Troubleshoot complex certificate issuance, validation, revocation, and trust-chain issues.
- Architect PKI solutions for:
- Windows authentication
- Smart cards
- Device authentication
- TLS/SSL
- Wi-Fi authentication
- VPN
- Application authentication
- Code signing
- Lead PKI migrations, CA upgrades, certificate authority consolidation, and certificate infrastructure modernization.
- Define PKI security controls, key protection, CA hierarchy, backup/recovery, and disaster recovery strategies.
- Identity Security
- Design secure identity architectures following Zero Trust and least-privilege principles.
- Assess risks associated with:
- Privileged accounts
- Domain Admin access
- Service accounts
- Kerberos
- NTLM
- LDAP
- Certificate authorities
- ADFS
- Domain Controllers
- Recommend security hardening for AD, ADFS, and PKI environments.
- Develop strategies for reducing legacy authentication protocols and improving identity security.
- Support identity security assessments and remediation programs.
- Modernization & Transformation
- Lead transformation initiatives from legacy identity infrastructure toward modern Microsoft identity architectures.
- Evaluate migration paths from:
- Legacy AD → Modern AD architecture
- ADFS → Microsoft Entra ID
- Legacy PKI → Modern certificate management
- Traditional authentication → modern authentication
- Develop phased migration roadmaps while maintaining business continuity.
- Assess dependencies between legacy applications and identity infrastructure.
- Provide technical recommendations for hybrid identity and cloud adoption.
- Customer & Technical Leadership
- Act as a Principal Technical Advisor for complex customer engagements.
- Engage directly with customer architects, technical leaders, and senior stakeholders.
- Lead architecture workshops and technical deep dives.
- Translate complex technical requirements into scalable enterprise solutions.
- Present architecture recommendations and technical strategies to senior leadership.
- Serve as an escalation point for Severity 1 / critical identity incidents.
- Mentor senior engineers, architects, and technical leads.
- CSA GD / Global Delivery Responsibilities
- Collaborate with Microsoft CSA teams and Global Delivery stakeholders on complex customer engagements.
- Participate in customer workshops, architecture reviews, technical assessments, and delivery governance.
- Provide technical leadership across geographically distributed delivery teams.
- Define reusable architecture patterns, reference architectures, and technical accelerators.
- Contribute to knowledge management and technical communities within CSA GD.
- Identify opportunities for automation and standardization across identity engagements.
Active Directory
- 15+ years of Microsoft infrastructure / identity experience.
- Expert-level Active Directory Domain Services knowledge.
- AD architecture and design.
- Forest/domain design.
- AD replication.
- DNS.
- Group Policy.
- Kerberos.
- LDAP.
- Trusts.
- Domain Controller architecture and troubleshooting.
- AD migration and consolidation.
- Deep expertise in ADFS.
- ADFS farm architecture.
- Claims-based authentication.
- Claims rules.
- Relying Party Trusts.
- SAML / WS-Federation.
- WAP.
- ADFS certificate management.
- Authentication troubleshooting.
- ADFS migration and modernization.
- Expert-level Microsoft PKI / AD CS.
- Enterprise PKI architecture.
- Root and Subordinate CA.
- Certificate templates.
- CRL / OCSP.
- AIA / CDP.
- Certificate lifecycle management.
- PKI migration and recovery.
- PKI security and hardening.
- Microsoft Entra ID
- Entra Connect / Azure AD Connect
- Hybrid Identity
- Microsoft Identity Manager (MIM)
- Microsoft Intune
- Conditional Access
- MFA
- Privileged Identity Management
- Microsoft Defender for Identity
- Windows Server
- PowerShell
- Microsoft Graph
- OAuth 2.0
- OpenID Connect
- SAML 2.0
- Zero Trust architecture
- Identity Governance
- PAM/PIM solutions
- Azure architecture
- Automation and scripting
- Infrastructure-as-Code concepts
The Candidate Should Demonstrate The Ability To
- Own architecture for large-scale enterprise identity environments.
- Make architecture decisions involving security, availability, scalability, and operational complexity.
- Lead technical teams through complex transformation programs.
- Conduct architecture reviews and challenge existing technical designs.
- Provide clear technical recommendations to senior stakeholders.
- Lead customer-facing technical discussions independently.
- Mentor architects and senior engineers.
- Drive technical standards and reusable solutions.
- Manage ambiguity and provide structured technical direction.
- Operate effectively in a global delivery / customer-facing environment.
- Bachelor's degree in Computer Science, Information Technology, Engineering, or related discipline.
- Microsoft Certified: Identity and Access Administrator
- Microsoft Certified: Windows Server Hybrid Administrator
- Microsoft Certified: Azure Solutions Architect Expert
- Microsoft Certified: Cybersecurity Architect Expert
- Microsoft Certified: Azure Security Engineer Associate
- Microsoft Certified: Azure Administrator Associate
Experience Profile The Ideal Candidate Should Have
- 15+ years of overall IT experience.
- Extensive experience designing and supporting enterprise Microsoft identity infrastructure.
- Significant experience working with large Active Directory environments.
- Proven expertise in ADFS and PKI architecture.
- Experience leading complex AD/ADFS/PKI migrations and modernization programs.
- Strong customer-facing and consulting experience.
- Experience working with globally distributed teams.
- Strong technical documentation and presentation skills.
- Experience acting as a technical authority / principal architect rather than solely as an implementation engineer.
Sonata Software is an Equal Opportunity Employer encouraging diversity in the workplace. All qualified applicants will receive consideration for employment without regard to race, national origin, gender identity, age, religion, disability, sexual orientation, veteran status, marital status, or any other characteristics protected by law .
More Info
Key Skills
OpenID Connect
Microsoft Entra ID
Microsoft Identity technologies
Zero Trust architecture
Identity Governance
Microsoft Defender for Identity
Microsoft Graph
Infrastructure-as-Code concepts
Automation and scripting
Azure AD Connect
WS-Federation
