- Location
- Johannesburg
- Workplace
- Hybrid
- Type
- Full-time
- Department
- Security
- Seniority
- Senior
- Experience
- 5+ years
- Education
- Master
- Closing date
- Today
- Source
- CareersPage
Description
Senior Microsoft Security Specialist – 6-Month Contract
Location: Johannesburg / Gauteng
Workplace: Hybrid
Contract: 6 Months
Industry: Technology / Cybersecurity
An exciting 6-month contract opportunity is available for an experienced Senior Microsoft Security Specialist to join a leading technology environment.
We are looking for a senior security professional with extensive hands-on experience across the Microsoft security ecosystem, including Microsoft 365, Azure, Microsoft Defender, Sentinel, Entra ID, Intune and hybrid infrastructure environments.
The successful candidate will act as a senior technical authority, driving security posture improvements, cyber resilience, governance and technical security initiatives while serving as a high-level escalation point for complex Microsoft security matters.
Key Responsibilities
- Own and manage the organisation's overall Microsoft security posture.
- Lead the design, implementation, optimisation and governance of the Microsoft E5 Security stack.
- Establish security standards, baselines, policies and operational procedures for Microsoft platforms.
- Develop strategic roadmaps to improve Microsoft security capability maturity.
- Lead the administration and optimisation of the Microsoft Defender ecosystem, including Defender for Endpoint, Office 365, Identity, Cloud Apps, Cloud and XDR.
- Implement advanced threat protection controls and drive proactive threat hunting and detection improvements.
- Own and manage the Microsoft Sentinel platform, including detection rules, analytics, workbooks, automation playbooks and threat-hunting capabilities.
- Integrate Microsoft and third-party security data sources into Sentinel and improve security monitoring maturity.
- Manage and secure Microsoft 365 services including Exchange Online, SharePoint Online, OneDrive, Teams and Power Platform.
- Implement and maintain DLP, Information Protection, Sensitivity Labels, Retention Policies and Insider Risk Management controls.
- Lead administration and security of Microsoft Entra ID (Azure AD).
- Design and implement Conditional Access, PIM, Identity Protection, MFA, Passwordless Authentication, SSO and RBAC.
- Conduct access reviews and privileged account governance while implementing Zero Trust security principles.
- Design and implement security controls across Azure environments.
- Manage Azure security governance, including Azure Policy, Landing Zones, subscription governance and resource governance.
- Secure cloud workloads, networking, storage and platform services.
- Own the organisation's Microsoft Intune and SCCM/MECM co-management environment.
- Manage endpoint security policies, MDM, MAM, device compliance and configuration management.
- Lead endpoint patch management and vulnerability remediation activities.
- Drive continuous improvement of Microsoft Secure Score and overall cyber maturity.
- Conduct security assessments, reviews, gap analyses, control effectiveness assessments and vulnerability reviews.
- Develop and execute remediation plans for identified security weaknesses.
- Act as an L3/L4 escalation point for critical and complex security incidents.
- Lead technical investigations involving Microsoft 365, Azure, identity, endpoint compromises, insider threats and advanced persistent threats.
- Coordinate containment, eradication, forensic investigation and recovery activities during major cyber incidents.
- Produce root cause analyses and post-incident recommendations.
- Review and approve security designs for projects impacting Microsoft cloud and hybrid platforms.
- Provide security sign-off for platform-related changes and initiatives.
- Maintain architecture decision records and security control documentation.
- Provide technical leadership, coaching and mentorship to junior security specialists and operational teams.
- Promote security best practices and a security-first culture across technology teams.
What We Are Looking For
The ideal candidate will have:
- A Bachelor's Degree in Information Technology, Computer Science, Cybersecurity, Engineering or a related field.
- Relevant Microsoft security certifications.
- Minimum 8–10 years of IT infrastructure and security experience.
- Minimum 5 years of hands-on Microsoft Security experience.
- Proven experience managing Microsoft E5 Security environments within large enterprise organisations.
- Extensive experience with Microsoft Sentinel and Microsoft Defender technologies.
- Strong experience securing hybrid cloud environments.
- Hands-on experience with Intune and SCCM/MECM co-management environments.
- Experience leading major incident response and forensic investigations.
- Proven experience developing security standards, governance frameworks and operating models.
- Experience mentoring technical teams and operating as a senior escalation point.
- Strong analytical, problem-solving and decision-making abilities.
- Excellent stakeholder management, communication and presentation skills.
Technical Skills
- Microsoft Defender XDR
- Defender for Endpoint
- Defender for Office 365
- Defender for Identity
- Defender for Cloud Apps
- Defender for Cloud
- Microsoft Sentinel
- Microsoft Purview
- Microsoft Secure Score
- Microsoft Entra ID
- Conditional Access
- MFA and SSO
- Privileged Identity Management (PIM)
- Identity Protection
- RBAC
- Microsoft Intune
- SCCM / MECM
- Windows Autopilot
- Patch Management
- Application Packaging and Deployment
- Azure Security
- Azure Policy
- Azure Landing Zones
- Cloud Governance and Compliance
- Cloud Workload Protection
- Security Architecture
- Incident Response
- Threat Hunting
- SIEM and SOAR
- Vulnerability Management
- Security Monitoring
- Digital Forensics
Preferred Certifications
- Microsoft Certified: Cybersecurity Architect Expert (SC-100)
- Microsoft Certified: Security Operations Analyst Associate (SC-200)
- Microsoft Certified: Identity and Access Administrator Associate (SC-300)
- Microsoft Certified: Information Protection Administrator Associate (SC-400)
- Microsoft Certified: Azure Security Engineer Associate (AZ-500)
- Microsoft Certified: Azure Administrator Associate (AZ-104)
- CISSP
- CISM
- CCSP
- CompTIA Security+
Key Competencies
- Strategic security leadership
- Advanced problem-solving
- Security architecture and design
- Incident management
- Risk assessment
- Stakeholder management
- Decision-making
- Communication and presentation
- Coaching and mentorship
- Governance and compliance management
- Continuous improvement
- Strong analytical skills
Success Measures
Success in this role will be measured through:
- Improvement of Microsoft Secure Score.
- Reduction in security vulnerabilities and exposure risks.
- Improved Microsoft Sentinel detection and incident response capabilities.
- Successful implementation of Microsoft security roadmap initiatives.
- Improved endpoint compliance and patch management effectiveness.
- Effective incident response and resolution outcomes.
- Increased adoption of security governance standards.
- Overall improvement in the organisation's Microsoft cloud security maturity.
Contract Details
This is a 6-month hybrid contract position based in Johannesburg, with an opportunity to work across a dynamic enterprise technology and cybersecurity environment.
If you are a senior Microsoft security professional with strong hands-on technical expertise, enterprise security experience and the ability to lead complex security initiatives, we would like to hear from you.
Apply now to be considered for this opportunity.