Microsoft Security Consultant (6 month Contract) x 3
Swan iT Recruitment Ltd · Johannesburg, Gauteng · Negotiable
Stop applying one at a time.
JobAlertsZA auto-applies to South African jobs like this one for you, overnight. Upload your CV once — we do the applying.
Start free — we apply for you →Introduction
The Microsoft Security Consultant will be responsible for owning, managing, and continuously
improving the organisation's Microsoft security ecosystem across Microsoft 365, Azure, Intune,
Microsoft Defender, Sentinel, Entra ID, and hybrid infrastructure environments.
This role serves as the technical authority for Microsoft platform security and is accountable
for defining security standards, strengthening cyber resilience, improving security posture, and
ensuring effective protection of critical systems, identities, data, and endpoints. The incumbent will
lead strategic security initiatives, provide expert guidance during major incidents, drive Secure Score
improvements, and act as the highest level escalation point for complex Microsoft security-related
matters.
The successful candidate will also provide leadership, mentorship, and technical guidance to junior
security specialists while working closely with architecture, infrastructure, governance, risk,
compliance, and SOC teams.
Duties & Responsibilities
Microsoft Security Platform Ownership
- Own and manage the overall Microsoft security posture across the organisation.
- Lead the design, implementation, optimisation, and governance of the Microsoft E5 Security
- stack.
- Establish security standards, baselines, policies, and operational procedures for Microsoft
- platforms.
- Ensure the effective operation and continuous improvement of Microsoft security
- technologies across the enterprise.
- Develop strategic roadmaps for Microsoft security capability maturity and adoption.
Microsoft Defender Ecosystem Management
Lead administration and optimisation of the Microsoft Defender suite, including:
- Microsoft Defender for Endpoint
- Microsoft Defender for Office 365
- Microsoft Defender for Identity
- Microsoft Defender for Cloud Apps
- Microsoft Defender for Cloud
- Microsoft Defender XDR
- Implement advanced threat protection controls and recommendations.
- Drive proactive threat hunting and detection improvements.
- Review, tune, and optimise security policies to minimise risk while maintaining business
- productivity.
- Analyse threat intelligence and implement mitigations against emerging threats.
Microsoft Sentinel Management and Security Operations
- Own the Microsoft Sentinel platform and ensure its effectiveness in detecting, investigating,
- and responding to security incidents.
- Develop and maintain use cases, detection rules, analytics, workbooks, automation
- playbooks, and threat-hunting capabilities.
- Work closely with Security Operations Centre (SOC) teams to improve incident detection and
- response effectiveness.
- Ensure proper integration of Microsoft and third-party security data sources into Sentinel.
- Drive reduction of false positives and improve overall security monitoring maturity.
Microsoft 365 Security Administration
Manage and secure Microsoft 365 services including
- Exchange Online
- SharePoint Online
- OneDrive for Business
- Microsoft Teams
- Power Platform
- Implement and maintain Data Loss Prevention (DLP), Information Protection, Sensitivity
- Labels, Retention Policies, and Insider Risk Management controls.
- Ensure secure configuration and governance across collaboration platforms.
- Manage email security controls and advanced anti-phishing protections.
Identity and Access Management
Lead the administration and security of Microsoft Entra ID (Azure AD).
Design and implement
- Conditional Access Policies
- Privileged Identity Management (PIM)
- Identity Protection
- Multi-Factor Authentication (MFA)
- Passwordless Authentication
- Single Sign-On (SSO)
- Role-Based Access Control (RBAC)
- Conduct periodic access reviews and privileged account governance.
- Implement Zero Trust security principles across identity environments.
Azure Security and Governance
Design and implement security controls across Azure environments.
Manage Azure security governance frameworks including
- Azure Policy
- Azure Blueprints
- Azure Landing Zones
- Subscription Governance
- Resource Governance
- Secure cloud workloads, networking, storage, and platform services.
- Conduct cloud security assessments and recommend remediation activities.
- Review cloud architectures and approve security controls before implementation.
Endpoint Management and Device Security
Own the organisation's Intune and SCCM co-management environment.
Manage
- Endpoint security policies
- Mobile Device Management (MDM)
- Mobile Application Management (MAM)
- Device compliance
- Configuration management
- Lead endpoint patch management and vulnerability remediation activities.
- Oversee software packaging, deployment, updates, and lifecycle management through
Intune and SCCM.
- Ensure endpoint security compliance and operational effectiveness across all managed
- devices.
Security Posture Management
- Drive continuous improvement initiatives aimed at increasing Microsoft Secure Score and
- overall cyber maturity.
- Establish and track key security metrics and performance indicators.
Conduct regular
- Security assessments
- Security reviews
- Gap analyses
- Control effectiveness assessments
- Vulnerability reviews
- Present security posture reports and recommendations to management and stakeholders.
- Develop and execute remediation plans for identified security weaknesses.
Incident Response and Technical Escalation
- Act as L3/L4 escalation point for critical and complex security incidents.
Lead technical investigations involving
- M365 environments
- Azure environments
- Identity compromises
- Endpoint compromises
- Insider threats
- Advanced persistent threats
- Coordinate containment, eradication, forensic investigation, and recovery activities.
- Work closely with the SOC and incident response teams during major cyber events.
- Produce root cause analyses and post-incident recommendations.
Security Architecture and Design Governance
- Review, evaluate, and approve security designs for projects impacting Microsoft cloud and
- hybrid platforms.
- Act as the Microsoft security subject matter expert during project delivery initiatives.
- Maintain architecture decision records and security control rationale documentation.
- Ensure solutions align with business, compliance, and security requirements.
- Provide security sign-off for platform-related changes and initiatives.
Leadership and Mentorship
- Provide technical leadership and mentoring to junior Microsoft Security Specialists and
- operational teams.
- Develop capability uplift programmes and knowledge-sharing initiatives.
- Establish best practices, standards, and operational procedures.
- Support skills development and succession planning within the security team.
- Promote a security-first culture across technology teams.
Desired Experience & Qualification
- Bachelor's Degree in Information Technology, Computer Science, Cybersecurity, Engineering for related field.
- Relevant Microsoft security certifications are essential.
Preferred Certifications
- Microsoft Certified: Cybersecurity Architect Expert (SC-100)
- Microsoft Certified: Security Operations Analyst Associate (SC-200)
- Microsoft Certified: Identity and Access Administrator Associate (SC-300)
- Microsoft Certified: Information Protection Administrator Associate (SC-400)
- Microsoft Certified: Azure Security Engineer Associate (AZ-500)
- Microsoft Certified: Azure Administrator Associate (AZ-104)
- CISSP
- CISM
- CCSP
- CompTIA Security+
Experience Required
- Minimum 8-10 years of IT infrastructure and security experience.
- Minimum 5 years of hands-on Microsoft Security experience.
- Proven experience managing Microsoft E5 Security environments in large enterprise organisations.
- Extensive experience with Microsoft Sentinel and Defender technologies.
- Strong experience securing hybrid cloud environments.
- Hands-on exper