Tech Stack
AWSAzureCloudCyber SecurityGoogle Cloud PlatformIoTPythonSplunk
About the role
- Senior Security Consultant is a client-focused position that works with ProArch customers to maintain a comprehensive security program.
- Role focuses on Data Security, governance, protection, and compliance, leveraging Microsoft Purview and related Microsoft 365 security tools; secondary focus includes securing cloud workloads in Azure.
- Responsibilities include design, advisement, implementation, and configuration management.
- Lead comprehensive security assessments to identify vulnerabilities and remediation strategies across client environments.
- Data Security: Lead workshops and assessments to identify gaps in data governance; design and implement scalable Microsoft Purview architectures tailored to client needs; provide strategic recommendations for improving data lifecycle management; collaborate with GTM and leadership to evolve service offerings around Purview.
- Leadership and Engagement: Provide mentorship and leadership to senior cybersecurity resources, fostering their development and guiding strategic projects; work closely with cross-functional teams to ensure alignment of cybersecurity initiatives with overall business objectives; ensure day-to-day operations of Security Consulting team are handled smoothly, issues are addressed; escalate issues deemed appropriate.
- Consulting, Advising, and Client Engagement: Act as a trusted adviser to clients and internal teams, offering strategic guidance to address specific security challenges and objectives; Lead consultative engagements, including requirements gathering, security workshops, assessments, and proofs-of-concept; Work closely with strategic clients to enhance solution adoption, ensuring solutions align with their needs and maximizing client satisfaction.
- Overcoming Obstacles and Driving Successful Delivery: Identify obstacles and potential issues in security solution delivery, proactively addressing these challenges with management; Ensure smooth project execution and client satisfaction through effective leadership and problem-solving; Develop and implement best practices and methodologies to ensure the successful delivery of cybersecurity solutions.
- Security Delivery: Lead implementation and optimization of Microsoft Purview solutions including DLP, Information Protection, Insider Risk Management, and eDiscovery; Design and deliver data classification, labeling, and retention strategies aligned with regulatory and compliance frameworks; Provide guidance on secure data lifecycle management across Microsoft 365 and Azure; Security strategy development; Security executive report delivery; Escalation for solution implementation and program onboarding; Escalation for solution maintenance & health management; Escalation for security assessments, awareness training, vulnerability management, web content security management; Escalation for SIEM and XDR architecture tasks; Mentor junior security consultants; Serve as a trusted advisor to clients; Conduct security awareness training; Stay updated with trends; Collaborate with cross-functional teams.
- Program Management: Lead solution configuration management initiatives; Lead account & permission management, provisioning, governance for security solutions within our programs; Presales meetings, proof-of-value/proof-of-concepts, security program cost & scope modeling; Solution research & design, emerging technology evaluation; Program improvement; automation & security engineering, as appropriate.
- Technical skills: Microsoft Purview, Defender, SIEM, XDR, Entra ID, Azure, etc.
Requirements
- BS or MS in Computer Science / Engineering or significant demonstratable experience in Microsoft Cloud Security.
Must have Certifications such as CISSP, SC-401, AZ-305. Certifications such as CCSP, CISA, CISM, SC-100, SC-200 or others are highly desirable.
Minimum 5 years of experience in security consulting or similar roles.
Deep knowledge of Microsoft security solutions including Defender for Endpoint, Defender for Office 365, Defender for Identity, Defender for Cloud, Defender XDR; Defender suite.
Experience with vulnerability management and remediation strategies.
Proficient in security assessments and audit methodologies.
Experience with regulatory compliance requirements (e.g. PCI DSS, HIPAA, NIST).
Willingness to travel as needed for client engagements.