Senior Microsoft Security Specialist
Swan iT Recruitment Ltd · Johannesburg, Gauteng · Negotiable
Stop applying one at a time.
JobAlertsZA auto-applies to South African jobs like this one for you, overnight. Upload your CV once — we do the applying.
Start free — we apply for you →Introduction
We are looking for a Senior Microsoft Security Specialist to take ownership of and continuously improve the organisation’s Microsoft security ecosystem across Microsoft 365, Azure, Intune, Microsoft Defender, Microsoft Sentinel, Entra ID and hybrid infrastructure environments.
The successful candidate will act as the senior technical authority for Microsoft platform security, driving security standards, cyber resilience, security posture improvements and the protection of critical systems, identities, data and endpoints. The role will lead strategic Microsoft security initiatives, provide expert guidance during major incidents, drive improvements in Microsoft Secure Score and act as the highest-level escalation point for complex Microsoft security matters.
The incumbent will also provide technical leadership, mentorship and guidance to junior security specialists while collaborating closely with architecture, infrastructure, governance, risk, compliance and Security Operations Centre (SOC) teams.
Duties & Responsibilities
- Own and manage the overall Microsoft security posture across the organisation.
- Lead the design, implementation, optimisation and governance of the Microsoft E5 Security stack.
- Establish security standards, baselines, policies and operational procedures for Microsoft platforms.
- Develop strategic roadmaps for Microsoft security capability maturity and adoption.
- Lead the administration and optimisation of the Microsoft Defender ecosystem, including Defender for Endpoint, Defender for Office 365, Defender for Identity, Defender for Cloud Apps, Defender for Cloud and Defender XDR.
- Implement advanced threat protection controls and recommendations, drive proactive threat hunting and improve threat detection capabilities.
- Review, tune and optimise security policies while maintaining business productivity.
- Analyse threat intelligence and implement mitigations against emerging threats.
- Own the Microsoft Sentinel platform, ensuring effective detection, investigation and response to security incidents.
- Develop and maintain Sentinel use cases, detection rules, analytics, workbooks, automation playbooks and threat-hunting capabilities.
- Work closely with SOC teams to improve incident detection, response effectiveness and overall security monitoring maturity.
- Ensure effective integration of Microsoft and third-party security data sources into Sentinel and drive the reduction of false positives.
- Manage and secure Microsoft 365 services including Exchange Online, SharePoint Online, OneDrive for Business, Microsoft Teams and Power Platform.
- Implement and maintain Data Loss Prevention (DLP), Information Protection, Sensitivity Labels, Retention Policies and Insider Risk Management controls.
- Lead the administration and security of Microsoft Entra ID and implement Conditional Access, Privileged Identity Management (PIM), Identity Protection, MFA, passwordless authentication, SSO and RBAC.
- Conduct access reviews and privileged account governance while implementing Zero Trust security principles across identity environments.
- Design and implement security controls across Azure environments, including Azure Policy, Azure Blueprints, Azure Landing Zones, subscription governance and resource governance.
- Secure cloud workloads, networking, storage and platform services, and conduct cloud security assessments with appropriate remediation recommendations.
- Review cloud architectures and approve security controls prior to implementation.
- Own the organisation’s Intune and SCCM/MECM co-management environment, including endpoint security policies, MDM, MAM, device compliance and configuration management.
- Lead endpoint patch management and vulnerability remediation activities.
- Oversee software packaging, deployment, updates and lifecycle management through Intune and SCCM/MECM.
- Drive continuous improvement initiatives aimed at increasing Microsoft Secure Score and overall cyber maturity.
- Establish and track security metrics and performance indicators, including security assessments, reviews, gap analyses, control effectiveness assessments and vulnerability reviews.
- Present security posture reports and recommendations to management and stakeholders, and develop remediation plans for identified security weaknesses.
- Act as an L3/L4 escalation point for critical and complex security incidents.
- Lead technical investigations involving Microsoft 365, Azure, identity compromises, endpoint compromises, insider threats and advanced persistent threats.
- Coordinate containment, eradication, forensic investigation and recovery activities during major cyber events.
- Produce root cause analyses and post-incident recommendations.
- Review, evaluate and approve security designs for projects impacting Microsoft cloud and hybrid platforms.
- Act as the Microsoft security subject matter expert during project delivery initiatives and provide security sign-off for platform-related changes and initiatives.
- Maintain architecture decision records and security control rationale documentation.
- Provide technical leadership and mentorship to junior Microsoft Security Specialists and operational teams.
- Establish best practices, standards and operational procedures, while supporting capability uplift, knowledge sharing and skills development within the security team.
- Promote a security-first culture across technology teams.
Desired Experience & Qualification
- Bachelor’s Degree in Information Technology, Computer Science, Cybersecurity, Engineering or a related field.
- Relevant Microsoft security certifications are essential.
- Minimum 8–10 years’ experience in IT infrastructure and security , including at least 5 years of hands-on Microsoft Security experience .
- Proven experience managing Microsoft E5 Security environments within large enterprise organisations.
- Extensive hands-on experience with Microsoft Sentinel and Microsoft Defender technologies.
- Strong experience securing hybrid cloud environments.
- Hands-on experience with Intune and SCCM/MECM co-management environments.
- Experience leading major incident response and forensic investigations.
- Demonstrated experience developing security standards, governance frameworks and operating models.
- Experience mentoring technical teams and acting as a senior escalation point.
- Strong technical experience across Microsoft Defender XDR, Defender for Endpoint, Defender for Office 365, Defender for Identity, Defender for Cloud Apps, Defender for Cloud, Microsoft Sentinel, Microsoft Purview and Microsoft Secure Score.
- Strong experience with Microsoft Entra ID, Conditional Access, MFA, SSO, PIM, Identity Protection and RBAC.
- Experience with Intune, SCCM/MECM, Autopilot, patch management and application packaging and deployment.
- Strong knowledge of Azure Security, Azure Policy, Azure Landing Zones, cloud governance and compliance, cloud workload protection and security architecture.
- Strong knowledge of incident response, threat hunting, SIEM/SOAR, vulnerability management, security monitoring and digital forensics.
- Strong strategic security leadership, analytical, problem-solving and decision-making skills.
- Excellent stakeholder management, communication and presentation skills.
- Strong coaching and mentorship capabilities.
- Microsoft Certified: Cybersecurity Architect Expert (SC-100) preferred.
- Microsoft Certified: Security Operations Analyst Associate (SC-200) preferred.
- Microsoft Certified: Identity and Access Administrator Associate (SC-300) preferred.
- Microsoft Certified: Information Protection Administrator Associate (SC-400) preferred.
- Microsoft Certified: Azure Security Engineer Associate (AZ-500) preferred.
- Microsoft Certified: Azure Administrator Associate (AZ-104) preferred.
- CISSP, CISM, CCSP or CompTIA Security+ advantageous.