
- 15+ years of cybersecurity experience.
- 8+ years in Enterprise Security Architecture roles.
- Proven experience leading large-scale enterprise security transformation programs.
- Strong hands-on expertise in Microsoft E5 Security and Microsoft Purview.
- Experience architecting and delivering implementations for 10,000+ endpoints/servers in multi-region environments.
- Experience managing leadership-level stakeholders, including CISOs, CIOs, Steering Committees, and Board Members.
- Ability to operate both at executive and hands-on technical levels.
Key Technical Requirements:
Hands-On Architecture Leadership & Delivery:
- Own end-to-end target security architecture across:
1. Microsoft Entra ID
2. Microsoft Defender for Endpoint (MDE)
3. Microsoft Defender for Office 365 (MDO)
4. Microsoft Defender for Cloud Apps (MDCA)
5. Microsoft Defender for Identity (MDI)
6. Microsoft 365 Defender XDR
7. Microsoft Purview
- Hands-on experience configuring, validating, troubleshooting and optimizing:
1. Conditional Access Policies
2. Identity Protection
3. RBAC
4. Attack Surface Reduction (ASR) Rules
5. Data Loss Prevention (DLP) Policies
6. Sensitivity Labels
7. Insider Risk Management
8. eDiscovery
9. Compliance Manager
- Define enterprise-wide standards for:
1. RBAC Architecture
2. Zero Trust Security Architecture
3. XDR Correlation Models
4. Security Governance Frameworks
5. Data Classification and Protection Standards
Security Platform Consolidation Experience:
- Must have experience leading migrations/consolidations from legacy security tools such as:
1. CrowdStrike
2. Checkpoint EDR
3. Symantec DLP
4. Sophos
- into Microsoft-native security platforms.
Data Protection & Governance:
- Must have strong experience designing:
1. Enterprise Sensitivity Label Taxonomy
2. Data Governance Frameworks
3. Information Protection Strategy
4. DLP Control Frameworks
5. Regulatory Compliance Controls
6. Adaptive Protection Models
7. Insider Risk Controls
Escalation & Troubleshooting Expertise:
- Should be capable of personally:
1. Troubleshooting critical production issues
2. Resolving security configuration challenges
3. Supporting stabilization and hypercare phases
4. Acting as technical escalation point during complex deployments
Leadership & Stakeholder Management:
- Candidate should have proven experience in:
1. Acting as trusted advisor to CISOs and executive leadership.
2. Leading board-level and steering committee discussions.
3. Presenting architecture decisions and risk trade-offs.
4. Managing scope, risk acceptance, escalations, and delivery challenges.
5. Conducting workshops with Business Units and Compliance teams.
6. Translating security architecture into business risk language.
Delivery Governance Experience:
- Strong experience required in:
1. Wave-based deployment methodologies.
2. Enterprise rollout governance.
3. Hypercare and stabilization models.
4. Stage-gate assessments.
5. Architecture compliance reviews.
6. Testing and validation sign-offs.
7. Knowledge Transfer governance.
Team Leadership Responsibilities:
- Lead security architects, consultants, engineers, and project managers.
- Guide Identity, Endpoint Security, Cloud Security, and Data Protection workstreams.
- Review and approve:
1. Configuration Baselines
2. SOPs
3. Runbooks
4. Health Check Reports
5. Optimization Reports
6. KPI Dashboards
- Lead architecture-focused knowledge transfer sessions.
- Develop reusable architecture assets and best practices.
Didn’t find the job appropriate? Report this Job