Security Architect
15 hours ago
Manchester
• The Security Architect is a senior technical leadership role responsible for defining, governing and evolving secure enterprise architectures across Advania’s Managed Services client base, • The role provides strategic and technical leadership across identity, security, cloud, infrastructure, networking, data protection and operational security domains, with a particular focus on Microsoft technologies including Entra ID, Defender, Sentinel, Purview, Azure and Microsoft 365, • Security Architecture Leadership, • Act as the lead security architecture authority across assigned Managed Services clients, • Develop enterprise security strategies, roadmaps and target-state architectures, • Produce and govern High-Level Designs (HLDs), Low-Level Designs (LLDs) and reference architectures, • Ensure architectures align with Zero Trust, Security by Design and Secure by Default principles, • Conduct architecture reviews and design assurance activities, • Identity & Access Management Architecture, • Design and govern enterprise identity strategies across cloud, hybrid and on-premises environments, • Lead architecture for:, • Microsoft Entra ID, • Active Directory, • Identity Governance, • Privileged Identity Management (PIM), • Conditional Access, • Authentication Services, • Federation, • Single Sign-On, • B2B/B2C identity models, • Define lifecycle management and access governance strategies, • Architect integrations between Microsoft identity services and third-party platforms. Managed Identities, Conditional Access, Identity Governance, Enterprise Applications and hybrid identity capabilities are core areas already recognised within Advania’s service offerings, • Microsoft Security Architecture, • Provide architectural ownership across the Microsoft security ecosystem, including:, • Microsoft Defender Suite, • Microsoft Sentinel, • Microsoft Purview, • Security Copilot, • Microsoft Intune, • Entra ID Security, • Azure Security Services, • Microsoft 365 Security & Compliance, • Develop security patterns and reference architectures for:, • Threat protection, • Identity protection, • Data protection, • Insider risk management, • Security monitoring, • Compliance, • AI security, • These technologies are explicitly identified as core security architecture domains within Advania’s security architecture practice, • Infrastructure & Platform Integration, • Design secure architectures spanning:, • Azure, • AWS, • Google Cloud, • On-premises infrastructure, • SaaS platforms, • Datacentre environments, • Lead secure integration of:, • Third-party security products, • Network infrastructure, • Business applications, • Identity providers, • Security operations tooling, • Assess technical dependencies and integration risks across complex customer estates, • Managed Services Enablement, • Support the onboarding of customer environments into managed services, • Ensure new solutions are operationally supportable, • Define service acceptance criteria and operational design requirements, • Work alongside SOC, Managed Identity, Azure and Infrastructure teams to establish support models, • Provide technical governance throughout the service lifecycle, • Client Advisory & Strategic Engagement, • Act as trusted advisor to CIO, CTO, CISO and technology leadership teams, • Facilitate architecture workshops and strategy sessions, • Develop security strategies, maturity roadmaps and investment plans, • Present architecture solutions and recommendations to executive and board-level stakeholders, • Support client security assessments, audits and transformation programmes, • Service Development, • Support the creation and evolution of Managed Security Services, • Define architecture standards, reusable patterns and technical frameworks, • Evaluate emerging technologies and services, • Drive innovation across identity, cloud security, AI security and automation, • What Success Looks Like, • Structural review of 10 clients, understand posture, contract, roadmaps and major risks, • Develop reusable patterns covering Entra ID, Purview, and Defender for Cloud, • Support at least 5 qualified opportunities, • Trusted architecture authority across assigned clients, • Infrastructure Integration, • Cloud based PKI, • Executive stakeholder management, • Microsoft Sentinel, • AZ-305 Azure Solutions Architect, • GDPR Risk Management, • Microsoft Entra ID, • Multi-cloud security architecture, • Client Engagement, • PIM SC-100 Cybersecurity Architect Expert, • MFA, • Minimum 3-5 years’ experience in enterprise security, cloud architecture or cyber security roles, • Strong understanding of: Increased adoption of Microsoft security technologies AI security and governance Networking DORA Deep expertise in: Threat Modelling Security Engineering Identity Governance Microsoft Intune Cloud Security Reusable architecture standards and patterns established across the business Directory Services Regulatory environments including: Positive client satisfaction and stakeholder feedback SSO Infrastructure Cyber Essentials Microsoft Federation Managed Services environment Microsoft Defender Suite Growth of architecture-led consultancy and managed service opportunities Extensive client-facing consultancy experience Azure Security Success Measures Architecture workshop facilitation Identity & Access Management Authentication Security architectures successfully deployed into operational managed services ISO 27001 Security Governance Azure Landing Zones SC-200 Security Operations Analyst Hybrid Identity Advanced experience across: Microsoft Purview Desirable Experience Exposure Management and Vulnerability Management platforms API Security NIST CSF Secure DevOps / DevSecOps Security Operations integration Microsoft 365 Security & Compliance FCA / PRA Security Monitoring Improved client security maturity and resilience Microsoft Expertise AZ-500 Azure Security Engineer SC-300 Identity & Access Administrator Secure Architecture Frameworks Demonstrable experience operating as a Security Architect, Enterprise Architect or Principal Consultant Technical leadership across multiple concurrent clients NIS2 Data Protection Hybrid Infrastructure Zero Trust Architecture CISSP Certifications CCSP CISMS ABSA Practitioner #J-18808-Ljbffr