Avanade logo

Lead Security Architect (MDE, Entra ID, MDCA)

Avanade

RemoteFull timeMid levelPosted today
Apply with JobAssist

About the role

Summary Join Avanade’s Security Practice to lead the architecture of integrated Microsoft security solutions for large enterprise environments. You will shape Defender and identity designs, guide implementation, manage technical stakeholders, and maintain alignment between approved architecture, security requirements, platform dependencies, and delivery outcomes.

Key Responsibilities

  • Lead discovery and architecture activities across Microsoft Defender XDR, Microsoft Defender for Endpoint, Microsoft Entra ID, and Microsoft Defender for Cloud Apps.
  • Assess endpoint security configurations, identity controls, user synchronization, MFA, Conditional Access, application connectors, policy requirements, and integration dependencies.
  • Define Defender for Endpoint architecture covering EDR baselines, antivirus policies, Attack Surface Reduction rules, onboarding requirements, coexistence considerations, and policy deployment through Intune.
  • Design Defender for Cloud Apps connectors and policies for Microsoft 365 applications, cloud discovery, threat detection, files, sessions, and Conditional Access App Control.
  • Define Microsoft Entra ID design considerations for identity synchronization, Conditional Access, MFA, RBAC, PIM, licensing, and integration with Defender capabilities.
  • Produce technical designs, configuration guidance, integration approaches, architecture decisions, assumptions, dependencies, and risk inputs.
  • Lead design reviews, implementation walkthroughs, stakeholder discussions, and knowledge-transfer sessions.
  • Provide architecture guidance during go-live, hypercare, and warranty for issues related to approved designs and configuration guidance.

Qualifications Skill and experiences

  • Min 10+ years of experience in cybersecurity architecture, Microsoft security consulting, enterprise security delivery, or related technology roles.
  • Strong architecture experience with Microsoft Defender XDR, Microsoft Defender for Endpoint, and Microsoft Defender for Cloud Apps.
  • Strong knowledge of Microsoft Entra ID, Active Directory integration, identity synchronization, MFA, Conditional Access, RBAC, and Privileged Identity Management.
  • Able to lead architecture workshops and explain security decisions, risks, prerequisites, and implementation guidance to technical and senior stakeholders
  • Strong ownership of design quality and scope boundaries
  • Experience designing EDR baselines, antivirus policies, ASR rules, endpoint onboarding, security-policy deployment, and legacy security-tool coexistence approaches.
  • Knowledge of MDCA connectors, cloud discovery, threat-detection, file, session, and Conditional Access App Control policies.
  • Understanding of Microsoft security licensing, access prerequisites, policy dependencies, and enterprise security governance
  • Comfortable coordinating across security, identity, endpoint, Intune, SOC, engineering, delivery, and client IT teams throughout solution design and delivery
  • Desirable Microsoft certifications include SC-200, MD-102, SC-900, AZ-500, SC-300, SC-401.

Millions of jobs, with real people getting hired every day

20,000+
New jobs added daily
7,000,000+
Verified job listings
500,000+
Tailored applications submitted
FAQ

Questions, answered

Click "Apply with JobAssist" – we tailor your resume and application to this role and submit it for your approval.

Yes. This role at Avanade was screened before publishing – we confirmed the employer before listing it.

The employer didn't disclose a salary range for this listing. JobAssist shows pay whenever it's available.

This position can be done from anywhere, with no in-office requirement.

Yes – every application is tailored from your profile and this job's requirements, and you can review and edit before it's sent.