Senior Microsoft Cloud & Platform Security Lead
JMR Software (Pty) Ltd · Gauteng
Posted 29 July 2026
Stop applying one at a time.
JobAlertsZA auto-applies to South African jobs like this one for you, overnight. Upload your CV once — we do the applying.
Start free — we apply for you →Introduction
Lead and own the overall Microsoft cloud and platform security posture across the Client’s M365, Azure and hybrid environment. Set security standards, drive Secure Score improvement, own Sentinel and Defender effectiveness, and act as the senior technical authority and escalation point for platform security decisions and complex incidents.
Duties & Responsibilities
Design, implement and continuously improve security controls across M365
and Azure, including Defender suite, Sentinel, Entra ID, and Azure
governance and policy frameworks.
- Define and maintain technical security standards, baselines and patterns for
platform, cloud and M365 services aligned to CIS, NIST, ISO 27001 and
company standards.
- Monitor and improve Microsoft Secure Score and other posture KPIs;
conduct security assessments and gap analyses across the Microsoft estate.
- Act as L3/L4 escalation for complex or major incidents involving M365, Azure
and platform security; guide containment, forensics and recovery in
collaboration with the SOC.
- Review and approve security designs for initiatives impacting Microsoft or
cloud platforms; maintain architecture decision records and control
rationale.
- Govern PKI, Azure Key Vault, DevSecOps controls, GitHub Advanced Security
and AI/Copilot security guardrails in collaboration with the
Platform/DevSecOps engineer.
- Provide escalation support and technical mentorship to all security
engineers; uplift team capability across Microsoft security technologies.
- Represent platform security in architecture, project and Group forums;
ensure local controls align to company cyber standards and audit
expectations.
- Coordinate with infrastructure, EUC, cloud platform, risk, audit and project
delivery stakeholders to ensure security is embedded across delivery
initiatives.
Desired Experience & Qualification
Scope Boundaries
- Does not own day-to-day EUC/endpoint operations (Intune/MECM) or IAM
lifecycle administration; provides technical standards, challenge authority
and escalation support to those roles.
- Infrastructure, cloud and application teams retain operational ownership of
their platforms; this role provides security leadership, guidance and
escalation.
- Policy approval, budget authority and formal risk acceptance remain with
cyber leadership and governance forums.