Senior Security Engineer Architect

Outsource SA Solutions (Pty) Ltd · Standon · TBD

Posted 11 August 2026

Stop applying one at a time.

JobAlertsZA auto-applies to South African jobs like this one for you, overnight. Upload your CV once — we do the applying.

Start free — we apply for you →

Introduction

We are hiring a Senior Microsoft Security Architect / Engineer to serve as the ultimate technical authority on our Microsoft security ecosystem. If you bring 8+ years of deep hands-on expertise across Defender, Entra ID, and Purview, this is your opportunity to shape enterprise Zero Trust standards, steer our licensing strategy, and evaluate cutting-edge tools like Copilot for Security in a complex enterprise environment.

Duties & Responsibilities

1. Platform Architecture, Verification & Standards

Architecture Ownership: Own the Microsoft security architecture across M365, Azure, and hybrid environments using Zero Trust and identity-first security principles.

Baseline & Documentation: Produce and maintain architectural designs, configuration baselines, and standards across the Defender Suite, Entra ID, Purview, Defender for Cloud Apps, and M365 collaboration tools.

Design Validation: Validate all Microsoft security platform implementations against approved designs, translating security requirements into clear technical specifications for operational execution.

Drift Control & Remediation: Identify deviations or gaps in active configurations, issue formal remediation requirements, and maintain continuous drift detection mechanisms.

Resilience & Governance: Define fallback standards for control resilience during outages, maintain a validation register, exercise formal change gate authority for platform modifications, and manage the security baseline exception process.

2. Email Security Architecture & Controls

Email Defense Strategy: Own the end-to-end email security architecture using Microsoft Defender for Office 365.

Authentication Standards: Maintain standards for anti-phishing/spoofing policies, Safe Links, Safe Attachments, email authentication ( SPF, DKIM, DMARC across all sending domains), and mail flow/quarantine rules.

Workforce Phishing Resilience: Design and define the enterprise Attack Simulation Training program—specifying scenario targets, templates, and training logic to measurably improve user awareness.

3. Microsoft Identity Security Architecture

Identity Blueprint: Define standards for Conditional Access, MFA, Privileged Identity Management (PIM), and Identity Governance (executed by the IAM engineering function).

Non-Human Identities: Enforce security standards for service principals, managed identities, and app registrations across Azure and Entra ID (naming, secret/certificate lifecycle, and access reviews).

Privileged & Advanced Access: Establish standards for Privileged Access Workstations (PAWs), define passwordless adoption roadmaps ( Windows Hello for Business / FIDO2 ), and govern External Identities (B2B guests, suppliers, contractors).

4. Endpoint, Cloud & Application Security

Endpoint Protection: Define Defender for Endpoint and Intune/Endpoint Manager standards covering EDR policies, device compliance, and hardening baselines.

Cloud Security Posture: Own Azure security posture requirements (Defender for Cloud policies, regulatory compliance standards, CIS Benchmarks , and Secure Score targets).

CASB & Application Security: Direct cloud application security using Defender for Cloud Apps—specifying shadow IT discovery standards, conditional access app controls, and session monitoring.

5. Data Protection & Collaboration Security

Information Protection: Define the data classification framework, sensitivity labelling taxonomy, and DLP rules in Microsoft Purview aligned with privacy regulations (e.g., POPIA, GDPR) and risk appetite.

Insider Risk: Configure and validate Insider Risk Management policy rules, alert thresholds, and investigation workflows.

Collaboration Hardening: Secure high-risk data-sharing surfaces (Teams, SharePoint, OneDrive) by governing external sharing, guest access, sync restrictions, and app integrations.

6. Security Telemetry, Automation & Stewardship

SOC Integration: Define log collection and telemetry standards across all platforms to ensure complete ingestion into the managed SOC/SIEM with zero coverage gaps.

Automation & Scripting: Design PowerShell and Logic Apps for compliance reporting and platform automation, reviewing operational automation scripts prior to production deployment.

Roadmap & Vendor Management: Advise on Microsoft licensing optimization (E3/E5 tiers, Defender plans), track the Microsoft product roadmap (evaluating new capabilities like Copilot for Security ), and enforce security controls for third-party integrations (GDAP, Graph API).

Desired Experience & Qualification

Required Certifications

SC-100 – Cybersecurity Architect Expert

SC-300 – Identity & Access Administrator

SC-400 – Information Protection Administrator

AZ-500 – Azure Security Engineer Associate

Education

Bachelor’s Degree in Information Technology, Computer Science, Information Security, or equivalent practical experience.

Advantageous Certifications

AZ-305 – Azure Solutions Architect Expert

CISSP – Certified Information Systems Security Professional

Experience Requirements

8+ Years of Production Experience (Hard Requirement): Hands-on experience engineering, building, and operating the Microsoft security stack at enterprise scale.

Enterprise Identity & Hybrid Access: Proven expertise with on-premises Active Directory, Entra ID, Entra Connect, Conditional Access, and Privileged Identity Management (PIM).

Deep Microsoft Security Stack Mastery: Extensive architectural and practical experience across the full Defender Suite (Office 365, Endpoint, Cloud Apps, Identity) and Microsoft Purview .

Email Security Architecture: Deep expertise in configuring and enforcing email protection controls, including SPF, DKIM, DMARC, Safe Links, and Safe Attachments across complex sending domains.

Identity Governance & Third-Party Management: Experience governing non-human identities (service principals, app registrations), B2B external identities, and third-party integrations (GDAP, Graph API).

Advantageous Industry & Compliance Exposure

Experience in FMCG, Manufacturing, or IT/OT hybrid environments .

Practical working knowledge of data privacy and cybersecurity frameworks/regulations ( POPIA, GDPR, ISO 27001, or NIST CSF ).

Experience conducting architectural reviews, managing security drift, and acting as a formal technical change gate within structured IT governance models.

Package & Remuneration

TBD

Interested?

Apply through Pnet

Auto-apply to this jobView original posting ↗