Senior Zero Trust Security Architect (Pomerium / Microsoft Entra ID / Intune / AWS)

Posted 3 days ago

Worldwide

Summary

# Senior Zero Trust Security Architect / Security Consulting Agency (Microsoft Entra ID, Intune, AWS, Pomerium) ## About Us We are a technology company with approximately 100–150 employees operating in a hybrid work environment. Our infrastructure includes Microsoft 365, AWS-hosted applications, Fortinet firewall, and an existing Web Application Firewall (WAF). As our organization grows, we want to replace our traditional VPN-based access model with a modern, identity-first Zero Trust Architecture. We are looking for a highly experienced **Zero Trust Security Architect or Security Consulting Agency** who has successfully designed and implemented similar environments for real organizations. This is **not** a simple infrastructure deployment. We are looking for professionals who can challenge assumptions, recommend the right architecture, and execute it end-to-end. --- # Project Objective Design and implement a complete Zero Trust Architecture that: * Eliminates broad VPN access * Provides identity-first authentication * Grants least-privilege access * Allows only compliant corporate devices * Protects internal applications * Improves auditability and governance * Scales with future business growth Our current proposal recommends a solution based on Microsoft Entra ID, Microsoft Intune, Microsoft Defender, AWS, Fortinet, and Pomerium, but **this is not mandatory**. We are open to better architectural approaches if they are technically justified. --- # Existing Environment Our current environment consists of: * 100–150 hybrid employees * Microsoft 365 * Microsoft Entra ID * AWS-hosted applications * HRMS * CRM * Internal production web applications * Existing Fortinet Firewall * Existing WAF * Windows laptops * Shared desktops * Mobile devices --- # Scope of Work The selected freelancer/agency will be responsible for the complete architecture, implementation, testing, documentation, knowledge transfer, and production rollout. ## Phase 1 – Discovery & Assessment * Review current infrastructure * Review AWS environment * Review Microsoft 365 configuration * Review Fortinet configuration * Review existing security architecture * Asset inventory * User inventory * Endpoint inventory * Risk assessment * Gap analysis * Security recommendations Deliverables * Environment Assessment Report * Gap Assessment Report * Risk Register --- ## Phase 2 – Solution Architecture Design a complete Zero Trust Architecture including: * High Level Design (HLD) * Low Level Design (LLD) * Identity architecture * Authentication flow * Authorization model * RBAC design * Policy framework * Access Matrix * Network architecture * Application onboarding strategy * Device Trust architecture * Disaster Recovery considerations --- ## Phase 3 – Identity & Access Foundation Configure: * Microsoft Entra ID * Single Sign-On * Multi-Factor Authentication * Conditional Access Policies * RBAC * Group Mapping * Identity Federation --- ## Phase 4 – Device Trust & Compliance Implement: * Microsoft Intune (preferred) * Device Enrollment * Device Compliance Policies * Device Whitelisting * Endpoint Health Validation * Certificate-based trust * Corporate device validation --- ## Phase 5 – Zero Trust Gateway Deploy and configure a Zero Trust Access solution. The proposal recommends **Pomerium**, however we are open to better alternatives if properly justified. Responsibilities include: * Gateway deployment * Identity integration * AWS integration * Secure application publishing * Policy configuration * Secure tunnels * Reverse proxy configuration * Certificate management --- ## Phase 6 – Application Onboarding Secure applications including: * HRMS * CRM * Internal applications * APIs * Production web applications Configure: * URL policies * Authorization rules * Group Mapping * Access Policies --- ## Phase 7 – Security Validation Perform: * Functional testing * Security validation * UAT * Penetration verification * Issue resolution --- ## Phase 8 – Production Rollout * Production deployment * Documentation * Admin Training * Knowledge Transfer * Operational Handover --- ## Phase 9 – Hypercare Support Provide post go-live support including: * Troubleshooting * Policy tuning * Access reviews * Bug fixes * Operational support --- # Expected Deliverables At the end of the engagement we expect: * High Level Design (HLD) * Low Level Design (LLD) * Architecture Diagrams * Identity & Access Matrix * RBAC Documentation * Conditional Access Policies * Device Compliance Policies * Device Whitelisting Policies * Configuration Guides * Administrator Guide * Operations Manual * Security Testing Report * UAT Report * Knowledge Transfer Session * Complete implementation documentation * One month of post go-live support --- # Required Experience You should have demonstrable experience with most of the following: * Zero Trust Architecture * Microsoft Entra ID * Microsoft Intune * Microsoft Defender * AWS * Identity & Access Management * Conditional Access * SSO * MFA * RBAC * OIDC * OAuth * SAML * Pomerium * Cloudflare Zero Trust * Zscaler * Tailscale * Fortinet * Security Architecture --- # We Want Architects, Not Just Implementers We already have a proposal prepared by another security consulting firm. It recommends a solution built around **Microsoft Entra ID, Microsoft Intune, Microsoft Defender, Fortinet, AWS, and Pomerium**. **This proposal is intended as a starting point—not a fixed implementation plan.** If you believe there is a better architecture, we encourage you to challenge our assumptions and explain why. We are looking for experts who can make informed architectural decisions rather than simply deploying the technologies mentioned in the proposal. Your recommendation should consider: * Security * Scalability * Operational complexity * Ease of management * Long-term maintenance * Vendor lock-in * Licensing costs * High availability * Future expansion * Total Cost of Ownership (TCO) If you recommend replacing any component, please explain: * What you would replace * Why * Benefits * Drawbacks * Licensing implications * Long-term maintenance implications For example, if you believe Pomerium should be replaced by Cloudflare Zero Trust, Zscaler, Twingate, Tailscale, OpenZiti, or another solution, explain your reasoning with real-world implementation experience—not marketing claims. We value architectural thinking over product preferences. --- # Your Proposal MUST Include Please answer **all** of the following: ### 1. Relevant Experience Describe your three most relevant Zero Trust implementations. Include: * Organization size * Industry * Technologies used * Number of users * Your exact role --- ### 2. Architecture Recommendation Would you implement the proposed architecture? If not, * What would you change? * Why? * What would you recommend instead? --- ### 3. Technology Stack Which technologies would you use for: * Identity * MFA * Device Management * Device Trust * Gateway * Application Proxy * Endpoint Security * Logging * Monitoring Explain why. --- ### 4. Migration Strategy Describe your rollout plan. How would you migrate users with minimal business disruption? --- ### 5. Device Trust Strategy Explain how you would ensure that only trusted devices can access corporate resources. --- ### 6. Shared Devices How would you securely manage: * Shared desktops * Contractor devices * BYOD * Mobile devices --- ### 7. Least Privilege Explain your RBAC strategy. --- ### 8. Conditional Access Describe your Conditional Access strategy. --- ### 9. High Availability How will you design the solution to avoid downtime? --- ### 10. Future Scalability How will your design support future growth? --- ### 11. Security Risks Based on the project description, what are the top five security risks you see today? --- ### 12. Deliverables List every document and artifact you will provide. --- ### 13. Timeline Provide a realistic implementation schedule with milestones. --- ### 14. Past Work Please provide evidence of relevant experience such as: * Case studies * Architecture diagrams (sanitized if required) * Technical blogs * Whitepapers * GitHub repositories * Documentation samples * Conference talks * Customer references (if possible) Simply stating "we have done this before" will not be considered sufficient. --- # Proposal Screening Generic AI-generated proposals will be rejected. We will prioritize candidates who: * Demonstrate deep architectural knowledge. * Explain the reasoning behind their recommendations. * Share relevant implementation experience. * Identify risks proactively. * Can defend their design decisions during technical discussions. We're looking for a long-term technology partner—not just someone to complete a one-time implementation.

  • $1,500.00

    Fixed-price
  • Expert
    Experience Level
  • Remote Job
  • Ongoing project
    Project Type
Skills and Expertise
Mandatory skills
Network Security
Zero Trust Architecture
Activity on this job
  • Proposals:5 to 10
  • Last viewed by client:2 days ago
  • Interviewing:
    6
  • Invites sent:
    0
  • Unanswered invites:
    0
About the client
Member since Sep 6, 2018
  • India
    Raipur8:47 AM
  • $20K total spent
    67 hires, 6 active
  • 42 hours
  • Large company (100-1,000 people)

Explore similar jobs on Upwork

Network and Cloud EngineerHourly‐ Posted 4 weeks ago
Network Security
Virtual LAN
Firewall
HackedHourly‐ Posted 2 weeks ago
Malware Removal
WordPress Website Design
Information Security
Penetration Testing
Vulnerability Assessment
Network Security
CMS Development
WordPress Malware Removal
Virus Removal
Cloudflare
SSL
Ethical Hacking
cPanel
WordPress Bug Fix
WordPress Security

How it works

  • Post a job icon
    Create your free profile
    Highlight your skills and experience, show your portfolio, and set your ideal pay rate.
  • Talent comes to you icon
    Work the way you want
    Apply for jobs, create easy-to-by projects, or access exclusive opportunities that come to you.
  • Payment simplified icon
    Get paid securely
    From contract to payment, we help you work safely and get paid securely.
Want to get started? Create a profile

About Upwork

  • Rating is 4.9 out of 5.
    4.9/5
    (Average rating of clients by professionals)
  • G2 2021
    #1 freelance platform
  • 49,000+
    Signed contract every week
  • $2.3B
    Freelancers earned on Upwork in 2020

Find the best freelance jobs

Growing your career is as easy as creating a free profile and finding work like this that fits your skills.

Trusted by

  • Microsoft Logo
  • Airbnb Logo
  • Bissell Logo
  • GoDaddy Logo