Cloud Architect

Emkan Holding

Al Khobar

On-site

SAR 980,000 - 1,320,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Emkan Holding seeks a senior architect to own the target-state architecture for the Group's Microsoft 365 and Azure estate, including tenant and landing zones. You will lead the tenant assessment, design, and post-migration hardening while ensuring regulatory alignment and cost-effective integration.

You will design Group identity, access, and Zero Trust architectures, govern security standards, and drive adoption across subsidiaries with hands-on production experience in Entra ID and related

Qualifications

  • Extensive experience designing enterprise Microsoft 365 and Azure estates.
  • Strong knowledge of Entra ID, Intune and Defender XDR with practical implementation.
  • Proven ability to map controls to ISO 27001/NCA ECC-1 requirements and support audits.
  • Ability to lead architecture workstreams across multiple subsidiaries and vendors.

Responsibilities

  • Own target-state architecture for Microsoft 365 and Azure estate, including tenant, management group, and landing zones.
  • Define identity, access, and zero-trust architectures across subsidiaries and implement governance controls.
  • Lead security architecture, data protection, and endpoint strategies with an emphasis on risk and cost impact.
  • Provide technical leadership, oversee design reviews, and mentor the Infrastructure Cloud team.
  • Collaborate with internal stakeholders and external partners to ensure compliant, scalable solutions.

Skills

Strategic thinking
Stakeholder collaboration
Mentoring

Education

Bachelor’s degree in computer science, Information Technology, Cybersecurity, or related engineering

Tools

Entra ID
Intune
Defender XDR
Microsoft Purview
Microsoft Sentinel
Azure landing zones
PowerShell / Microsoft Graph API
Terraform / Bicep

Job description

2 1 Cloud and Tenant Architecture

Own the target-state architecture for the Group s Microsoft 365 and Azure estate including the consolidated tenant design subscription and management-group structure and Azure landing zones Lead the architectural workstream of the tenant -tenant assessment coexistence design cutover sequencing domain and namespace strategy and post-migration hardening Define data-residency licensing and service-placement decisions in line with regulatory obligations and Group business requirements Produce and maintain High-Level and Low-Level Design documentation reference architecture and architecture decision records for every major platform change Assess new Microsoft and third-party services for risk cost and impact on integration before adoption



2 2 Identity and Access Architecture

Design the Group identity architecture on Microsoft Entra ID covering tenant topology domain federation guest and B2B collaboration and lifecycle workflows across subsidiaries Define the Conditional Access policy framework authentication strength requirements phishing-resistant MFA rollout and named-location and device-trust strategy Architect privileged access using Privileged Identity Management role-assignable groups administrative unit delegation per subsidiary and access reviews Establish joiner-mover-leaver design entitlement management and application single sign-on standards for line-of-business applications



2 3 Security Architecture Zero Trust

Own the Zero Trust reference architecture for the Group and drive its adoption across all subsidiaries Design the detection and response architecture across Microsoft Defender XDR and Microsoft Sentinel including log-source onboarding strategy data-collection tiers retention design and integration with the managed SOC provider Define data protection architecture using Microsoft Purview sensitivity labelling taxonomy data loss prevention insider risk retention and eDiscovery readiness Set email collaboration and application security standards including Defender for Office 365 policy design and SPF DKIM and DMARC enforcement across Group domains Design the security architecture interface with network and perimeter controls ensuring identity endpoint and network layers form a coherent control set



2 4 Endpoint and Modern Workplace Architecture

Define the endpoint management architecture on Microsoft Intune covering enrolment models Windows Autopilot compliance and configuration baselines update rings and application delivery Design the BYOD and mobile posture using application protection policies and set the standard for endpoint hardening and encryption across the Group Establish the collaboration and productivity architecture for Exchange Online SharePoint Online OneDrive and Microsoft Teams including external sharing and governance controls Define backup retention and recovery architecture for cloud workloads with recovery objectives agreed with the business



2 5 Governance Compliance and Risk

Ensure all designs satisfy NCA ECC-1 2018 and ISO 27001 2022 requirements and map implemented technical controls to the relevant domains and Annex A controls Maintain the architecture standards technical baselines and control-evidence set required for internal and external audit Contribute to the technology risk register identify architectural risks quantify impact and propose treatment options with clear cost and effort estimates Provide technical input to Group IT policies standards and the Cybersecurity Steering Committee reporting pack



2 6 Technical Leadership and Vendor Governance

Act as the technical authority in vendor and partner engagements review statements of work solution designs and deliverables and hold implementation partners to the agreed architecture Lead design reviews and technical assurance for projects delivered by the internal team or third parties Mentor the Infrastructure Cloud team through documented standards knowledge-transfer sessions and structured development plans build internal capability rather than concentrate it Support the Infrastructure Cloud Manager in technology roadmap planning capacity forecasting and budget input for cloud and security platforms Bachelor’s degree in computer science, Information Technology, Cybersecurity, or a related engineering discipline.8 to 10 years of progressive experience in IT infrastructure, cloud, and security, including at least four years in architecture or senior design capacity.Demonstrable ownership of an enterprise Microsoft 365 and Azure estate, including hands-on production experience with Entra ID, Intune, Defender XDR, and Microsoft Purview.Practical working knowledge of NCA ECC-1:2018 and ISO 27001:2022, including control mapping and audit evidence preparation.Identity: Entra ID, Conditional Access, Privileged Identity Management, entitlement management, B2B and external identities, SSO and SCIM provisioning.Security: Defender XDR (Endpoint, Office 365, Identity, Cloud Apps), Microsoft Sentinel, KQL for hunting and analytics, Secure Score and Exposure Management.Data protection: Microsoft Purview sensitivity labels, DLP, insider risk management, retention and records management.Endpoint: Intune, Windows Autopilot, compliance and configuration baselines, application protection policies.Cloud platform: Azure landing zones, networking, RBAC, Azure Policy, and infrastructure as code (Bicep or Terraform).Automation: PowerShell and Microsoft Graph API for configuration, reporting, and migration tooling.Architecture practice: Zero Trust, defense in depth, segregation of duties, and documented design patterns.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cloud Platform & DevOps Engineer
Cloud Platform & DevOps Engineer

E-Solutions • Riyadh

On-site
SAR 300,000 - 520,000
Senior Specialist - Cybersecurity Architecture
Senior Specialist - Cybersecurity Architecture

Qiddiya | القدية • Riyadh

On-site
SAR 180,000 - 260,000
Cloud Architect: Enterprise Azure & Modern Workplace Leader
Cloud Architect: Enterprise Azure & Modern Workplace Leader

Emkan Holding • Al Khobar

On-site
SAR 980,000 - 1,320,000
Application Security Engineer
Application Security Engineer

Practical DevSecOps • Al Khobar

On-site
SAR 90,000 - 120,000
Senior Microsoft Security Administrator
Senior Microsoft Security Administrator

al watania information systems (wisys) • Saudi Arabia

On-site
SAR 180,000 - 250,000
Enterprise Computing & Cloud Architect
Enterprise Computing & Cloud Architect

Client of Eram Talent • Eastern Province

On-site
SAR 400,000 - 660,000
Sr. Advisor Cybersecurity Architect
Sr. Advisor Cybersecurity Architect

Confidential • Dhahran Compound

On-site
SAR 360,000 - 600,000
Senior Specialist - Cybersecurity Architecture
Senior Specialist - Cybersecurity Architecture

Qiddiya Investment Company • Riyadh

On-site
SAR 60,000 - 90,000
Security Consultant
Security Consultant

Paramount Computer System • Saudi Arabia

On-site
SAR 100,000 - 150,000
Enterprise Network & Security Architect
Enterprise Network & Security Architect

Saudi Business Machines • Dhahran Compound

On-site
SAR 257,000 - 348,000