- Location
- ZA
- Workplace
- Hybrid
- Type
- Full-time
- Department
- IT
- Seniority
- Senior
- Education
- Master
- Closing date
- Today
- Source
- Vincere
Description
We are seeking a Senior Microsoft Security Engineer – Architecture on behalf of a client to act as the internal subject matter expert and architectural authority across Microsoft 365, Azure and hybrid environments. This senior specialist role is suited to someone with deep, hands-on Microsoft security experience who can translate security risks and business requirements into robust technical standards, validate implementations and continuously strengthen enterprise security posture.
Responsibilities:
- Own and continuously develop Microsoft security architecture across M365, Azure and hybrid environments.
- Define Zero Trust, identity-first security standards, configuration baselines and design patterns.
- Set and validate security standards across Microsoft Defender, Entra ID, Purview, Defender for Cloud Apps and M365 collaboration platforms.
- Lead Microsoft identity security architecture covering Conditional Access, MFA, PIM, identity governance, passwordless authentication and external identities.
- Define and validate email security controls including Defender for Office 365, SPF, DKIM, DMARC, Safe Links and Safe Attachments.
- Establish endpoint and cloud security standards across Defender for Endpoint, Intune and Defender for Cloud.
- Define data classification, sensitivity labelling, DLP and Insider Risk Management requirements through Microsoft Purview.
- Govern security across Teams, SharePoint, OneDrive and external collaboration environments.
- Define telemetry and logging requirements for integration with managed SOC and SIEM environments.
- Design or review PowerShell and Logic Apps automation for compliance, configuration management and reporting.
- Monitor configuration drift, security exceptions, Secure Score performance and remediation requirements.
- Maintain technical standards, runbooks, configuration guides and governance documentation.
- Advise on Microsoft licensing, emerging security capabilities and the Microsoft security product roadmap.
- Act as the escalation point and trusted advisor to infrastructure, cloud, application, risk and governance teams.
Requirements:
- Bachelor’s degree in Information Technology, Computer Science, Information Security or equivalent practical experience.
- 8+ years of hands-on production experience with the Microsoft security stack, including personally building and operating enterprise-scale Microsoft security platforms.
- Strong experience across Microsoft Defender, Entra ID, Microsoft Purview, Azure security and Microsoft 365 security.
- Proven experience designing Microsoft security architecture within complex or regulated enterprise environments.
- Enterprise hybrid identity experience across on-premises Active Directory, Entra ID and Entra Connect.
- Strong knowledge of Conditional Access, MFA, PIM, identity governance and non-human identity security.
- Hands-on experience with email security architecture, including SPF, DKIM, DMARC and Defender for Office 365.
- Experience governing B2B collaboration, guest access and external identities.
- Knowledge of POPIA, ISO 27001 or NIST CSF requirements would be advantageous.
- Exposure to FMCG, manufacturing or IT/OT environments would be advantageous.
Required Certifications:
- SC-100 – Cybersecurity Architect Expert
- SC-300 – Identity & Access Administrator
- SC-400 – Information Protection Administrator
- AZ-500 – Azure Security Engineer Associate
- Advantageous: AZ-305 – Azure Solutions Architect and/or CISSP.
EE Disclaimer:
All positions will be filled in accordance with the company's Employment Equity plan. We encourage people with disabilities to apply.
Application Unsuccessful Disclaimer:
If you do not receive feedback within two weeks of your application, please consider it unsuccessful. Keep an eye on our website and other career sites for future opportunities.
REF: PG01