Avanade logo
AvanadePosted 1 month ago

Lead Security Architect (MDE, Entra ID, MDCA)

On-siteKuala Lumpur, Kuala Lumpur, Malaysia

Full TimeSenior LevelEnterprise

Job Summary

Lead discovery and architecture activities across Microsoft Defender XDR, Defender for Endpoint, Defender for Cloud Apps, and Microsoft Entra ID for large enterprise environments. Assess endpoint configurations, identity controls, user synchronization, MFA, Conditional Access, and integration dependencies. Define Defender for Endpoint baselines, antivirus policies, Attack Surface Reduction rules, and Intune deployment strategies. Design Defender for Cloud Apps connectors and policies for M365 applications, cloud discovery, and threat detection. Produce technical designs, configuration guidance, and risk inputs for go-live and hypercare support. Manage stakeholder discussions and knowledge-transfer sessions while maintaining alignment between approved architecture and delivery outcomes.

Required Qualifications

  • Min 10+ years of experience in cybersecurity architecture, Microsoft security consulting, enterprise security delivery, or related technology roles
  • Strong architecture experience with Microsoft Defender XDR, Microsoft Defender for Endpoint, and Microsoft Defender for Cloud Apps
  • Strong knowledge of Microsoft Entra ID, Active Directory integration, identity synchronization, MFA, Conditional Access, RBAC, and Privileged Identity Management
  • Able to lead architecture workshops and explain security decisions, risks, prerequisites, and implementation guidance to technical and senior stakeholders
  • Strong ownership of design quality and scope boundaries
  • Experience designing EDR baselines, antivirus policies, ASR rules, endpoint onboarding, security-policy deployment, and legacy security-tool coexistence approaches
  • Knowledge of MDCA connectors, cloud discovery, threat-detection, file, session, and Conditional Access App Control policies
  • Understanding of Microsoft security licensing, access prerequisites, policy dependencies, and enterprise security governance
  • Comfortable coordinating across security, identity, endpoint, Intune, SOC, engineering, delivery, and client IT teams throughout solution design and delivery

Desired Qualifications

  • Desirable Microsoft certifications include SC-200, MD-102, SC-900, AZ-500, SC-300, SC-401

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce