Architect and oversee end-to-end security solutions across hybrid and cloud environments, particularly within the Microsoft ecosystem (M365, Azure, Entra ID).
Develop and execute consolidation strategies for redundant or overlapping security technologies, reducing complexity and improving manageability.
Lead engagements including risk assessments, architectural reviews, and strategic planning sessions
Optimize Microsoft 365 and Azure security configurations, including conditional access, MFA, PIM, Defender Suite, Intune, Purview, and data loss prevention.
Translate business requirements into secure, scalable, and cost-effective technical solutions aligned with industry frameworks (NIST CSF, ISO 27001, Etc.)
Serve as a trusted advisor for internal teams and clients on emerging threats, security best practices, and roadmap planning.
Provide mentorship to junior security team members and contribute to the development of internal standards, documentation, and reusable frameworks.
Requirements
Minimum of 7–10 years in Information Security, with at least 3+ years in architecture or advisory roles focused on M365/Azure environments.
Demonstrated success in client-facing roles, preferably within a managed services or consulting environment.
Excellent communication skills with the ability to influence and guide both technical and non-technical stakeholders.
Strong project management and documentation practices with an ability to prioritize and deliver in fast-paced environments.
Professional certifications are preferred (e.g., CISSP, CCSP, CSA, CSSA, etc.)
Proven expertise with Microsoft 365 Security & Compliance Center and Azure AD / Entra ID (Conditional Access, Identity Protection, Role-Based Access Control, etc.).
Strong experience with cloud-native security tools, including Microsoft Sentinel, Defender for Endpoint, and Azure Security Center.
Deep understanding of identity and access management, data protection, and endpoint security in modern enterprise environments.
Familiarity with SIEM, EDR, SSPM, and MDM technologies (Intune preferred).