
Responsibilities:
- Own end-to-end target security architecture across Microsoft Entra ID, Microsoft Defender, Microsoft 365 Defender XDR, and Purview.
- Define enterprise-wide standards for architecture.
- Lead security architects, consultants, engineers, and project managers.
- Guide Identity, Endpoint Security, Cloud Security, and Data Protection workstreams.
- Review and approve configuration baselines, SOPs, runbooks, health, optimization reports, and KPI dashboards.
- Lead architecture-focused knowledge transfer sessions.
- Develop reusable architecture assets and best practices.
Requirements:
- 15+ years of cybersecurity experience.
- 8+ years in Enterprise Security Architecture roles.
- Proven experience leading large-scale enterprise security transformation programs.
- Strong hands-on expertise in Microsoft E5 Security and Microsoft Purview.
- Experience architecting and delivering implementations for 10,000+ endpoints/servers in multi-region environments.
- Experience managing leadership-level stakeholders, including CISOs, CIOs, Steering Committees, and Board Members.
- Ability to operate both at executive and hands-on technical levels.
- Expertise in RBAC, Zero Trust, XDR Correlation Models, Data, and Security.
- Must have experience leading migrations/consolidations from legacy security tools such as CrowdStrike, Checkpoint EDR, Symantec DLP, and Sophos into Microsoft-native security platforms.
- Must have strong experience designing Enterprise Sensitivity Label Taxonomy, Data Governance Frameworks, Information Protection Strategy, DLP Control Frameworks, Regulatory Compliance Controls, Adaptive Protection Models, and Insider Risk Controls.
- Troubleshooting critical production issues.
- Resolving security configuration challenges.
- Supporting stabilization and hypercare phases.
- Acting as technical escalation point during complex deployments.
Candidate Profile:
- Acting as trusted advisor to CISOs and executive leadership.
- Leading board-level and steering committee discussions.
- Presenting architecture decisions and risk trade-offs.
- Managing scope, risk acceptance, escalations, and delivery challenges.
- Conducting workshops with Business Units and Compliance teams.
- Translating security architecture into business risk language.
- Wave-based deployment methodologies.
- Enterprise rollout governance.
- Hypercare and stabilization models.
- Stage-gate assessments.
- Architecture compliance reviews.
- Testing and validation sign-offs.
- Knowledge Transfer governance.
- Identity Security: Entra.
- Endpoint Security: Microsoft Defender for Endpoint (MDE).
- Email Security: Microsoft Defender for Office 365 (MDO).
- Cloud App Security: MDCA / MCAS.
- Identity Threat Detection: MDI Extended Detection & Response.
- Microsoft 365 Defender XDR.
- Microsoft Certified: Cybersecurity Architect Expert (SC-100), SC-200, SC-300, SC-400, CISSP, CISM, TOGAF.
- Experience within the Logistics environments and Critical OT/IT.
Didn’t find the job appropriate? Report this Job