Lead Security Architect (MDE, Entra ID, MDCA)

Avanade

Jakarta Pusat

On-site

IDR 400,000,000 - 700,000,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Avanade is seeking a senior security architect to lead the architecture of integrated Microsoft security solutions for large enterprise environments. You will shape Defender and identity designs, guide implementation, and align architecture with security requirements and delivery outcomes.

You will oversee design reviews, provide technical guidance to cross-functional teams, and ensure go-live success with strong stakeholder collaboration.

Qualifications

  • Min 10+ years of cybersecurity architecture and enterprise security delivery.
  • Deep expertise in Defender XDR, Defender for Endpoint, and Defender for Cloud Apps.
  • Strong knowledge of Entra ID, identity synchronization, MFA, and Conditional Access.
  • Able to lead architecture workshops and explain security decisions, risks, prerequisites, and implementation guidance.
  • Microsoft certifications such as SC-200, MD-102, SC-900, AZ-500, SC-300, SC-401 are desirable.

Responsibilities

  • Lead discovery and architecture activities across Defender XDR, Defender for Endpoint, Entra ID, and Cloud Apps.
  • Assess endpoint security configurations, identity controls, MFA, CA, and integration dependencies.
  • Define Defender for Endpoint architecture including onboarding and policy deployment through Intune.
  • Design Defender for Cloud Apps connectors and policies for Microsoft 365 apps and CA App Control.
  • Define Entra ID design considerations for identity synchronization and RBAC.
  • Produce technical designs, guidance, and integration approaches.
  • Lead design reviews, walkthroughs, and knowledge-transfer sessions.
  • Provide architecture support during go-live, hypercare, and warranty phases.

Skills

Cybersecurity architecture
Microsoft security
Defender XDR
Identity & access management
Stakeholder management
Architecture workshops

Tools

Intune
Azure AD
MDCA

Job description

Summary

Join Avanade's Security Practice to lead the architecture of integrated Microsoft security solutions for large enterprise environments. You will shape Defender and identity designs, guide implementation, manage technical stakeholders, and maintain alignment between approved architecture, security requirements, platform dependencies, and delivery outcomes.

Summary

Join Avanade's Security Practice to lead the architecture of integrated Microsoft security solutions for large enterprise environments. You will shape Defender and identity designs, guide implementation, manage technical stakeholders, and maintain alignment between approved architecture, security requirements, platform dependencies, and delivery outcomes.

Key Responsibilities
  • Lead discovery and architecture activities across Microsoft Defender XDR, Microsoft Defender for Endpoint, Microsoft Entra ID, and Microsoft Defender for Cloud Apps.
  • Assess endpoint security configurations, identity controls, user synchronization, MFA, Conditional Access, application connectors, policy requirements, and integration dependencies.
  • Define Defender for Endpoint architecture covering EDR baselines, antivirus policies, Attack Surface Reduction rules, onboarding requirements, coexistence considerations, and policy deployment through Intune.
  • Design Defender for Cloud Apps connectors and policies for Microsoft 365 applications, cloud discovery, threat detection, files, sessions, and Conditional Access App Control.
  • Define Microsoft Entra ID design considerations for identity synchronization, Conditional Access, MFA, RBAC, PIM, licensing, and integration with Defender capabilities.
  • Produce technical designs, configuration guidance, integration approaches, architecture decisions, assumptions, dependencies, and risk inputs.
  • Lead design reviews, implementation walkthroughs, stakeholder discussions, and knowledge-transfer sessions.
  • Provide architecture guidance during go-live, hypercare, and warranty for issues related to approved designs and configuration guidance.
Qualifications
  • Min 10+ years of experience in cybersecurity architecture, Microsoft security consulting, enterprise security delivery, or related technology roles.
  • Strong architecture experience with Microsoft Defender XDR, Microsoft Defender for Endpoint, and Microsoft Defender for Cloud Apps.
  • Strong knowledge of Microsoft Entra ID, Active Directory integration, identity synchronization, MFA, Conditional Access, RBAC, and Privileged Identity Management.
  • Able to lead architecture workshops and explain security decisions, risks, prerequisites, and implementation guidance to technical and senior stakeholders
  • Strong ownership of design quality and scope boundaries
  • Experience designing EDR baselines, antivirus policies, ASR rules, endpoint onboarding, security-policy deployment, and legacy security-tool coexistence approaches.
  • Knowledge of MDCA connectors, cloud discovery, threat-detection, file, session, and Conditional Access App Control policies.
  • Understanding of Microsoft security licensing, access prerequisites, policy dependencies, and enterprise security governance
  • Comfortable coordinating across security, identity, endpoint, Intune, SOC, engineering, delivery, and client IT teams throughout solution design and delivery
  • Desirable Microsoft certifications include SC-200, MD-102, SC-900, AZ-500, SC-300, SC-401.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Microsoft Technical Security Consultant (Defender, Intune & Entra ID SME)
Microsoft Technical Security Consultant (Defender, Intune & Entra ID SME)

Avanade • Daerah Khusus Ibukota Jakarta

On-site
IDR 895,896,000 - 1,254,256,000
Principal Defender & Entra Security Architect
Principal Defender & Entra Security Architect

Avanade • Jakarta Pusat

On-site
IDR 400,000,000 - 700,000,000
Microsoft Security Consultant (Presales & Delivery)
Microsoft Security Consultant (Presales & Delivery)

Avanade • Kota Yogyakarta

On-site
IDR 1,112,061,000 - 1,454,235,000
Microsoft Security Architect: Defender | Intune | Entra ID
Microsoft Security Architect: Defender | Intune | Entra ID

Avanade • Daerah Khusus Ibukota Jakarta

On-site
IDR 895,896,000 - 1,254,256,000
Azure Security Lead & Microsoft Defender Expert
Azure Security Lead & Microsoft Defender Expert

Avanade • Kota Yogyakarta

On-site
IDR 1,112,061,000 - 1,454,235,000
Security Engineer Staff
Security Engineer Staff

PT. Intikom Berlian Mustika • Indonesia

On-site
IDR 180,000,000 - 300,000,000
Security Engineer Staff
Security Engineer Staff

PT Intikom Berlian Mustika • Jakarta Pusat

On-site
IDR 279,000,000 - 446,400,000
Azure Cloud Solutions Architect
Azure Cloud Solutions Architect

Avanade • Jakarta Pusat

On-site
IDR 600,000,000 - 1,000,000,000
Security Architect & Engineering
Security Architect & Engineering

BFI • Indonesia

On-site
IDR 600,000,000 - 900,000,000
Medical & Health Insurance
Performance Bonus
Flexible Time
+4
Senior Consultant - Power Platforms, D365 CRM
Senior Consultant - Power Platforms, D365 CRM

Avanade • Kota Yogyakarta

On-site
IDR 90,000,000 - 120,000,000