Enduir is a leading cybersecurity and technology consulting firm dedicated to providing cutting-edge solutions to clients across various industries. With a focus on innovation and excellence, we deliver robust cybersecurity and technology resilience strategies and services to safeguard our clients' digital infrastructure from evolving threats.
Position Summary
We are hiring a Senior Technical Architect who can serve as the primary technical lead on remediation and modernization projects for mid-size companies. This person will bring hands on hybrid experience across on premises environments and either Azure or AWS, and should be comfortable scoping work, building pragmatic plans, and leading delivery with clear communication.
You’ll Excel Here If You
- Lead technical solutioning for mid-size environments: diagnose problems (for example, AD misconfigurations, fragile backup and DR, firewall or segmentation gaps, cloud posture issues) and propose pragmatic fixes and modernization paths with clear options and tradeoffs.
- Design and implement hybrid infrastructure: produce and execute reference designs for AD and Entra, Azure or AWS landing zones, VNet or VPC connectivity, segmentation, logging and SIEM onboarding, and backup and DR, owning build, cutovers, and rollback plans.
- Serve as the primary technical lead on remediation projects: plan sprints, sequence changes, coordinate MSPs and vendors, maintain as built documentation and runbooks, and deliver on time and on budget.
- Stay calm and effective through change events: triage and stabilize during incidents and outages, guide migrations and cutovers, make sensible risk calls, and keep stakeholders informed.
- Work with Enduir subject matter experts and client engineers to produce one cohesive solution: set technical direction, unblock issues, and ensure configurations are operationally feasible for the team that will run them.
- Understand DevOps and platform rhythms as awareness rather than a core skill: know how CI/CD, infrastructure as code, and secrets management work in the client environment so you can help harden pipelines and cloud services, especially following an incident, without disrupting delivery.
- Communicate crisply: translate technical constraints into sponsor friendly updates and engineer ready tasks; brief CIO, CTO, or CISO stakeholders as needed to keep decisions moving.
- Track outcomes: show resilience uplift (for example, RTO/RPO improvements), stability and performance gains, and cost-aware choices, delivered on time and on budget.
- Contribute reusable value: add templates, checklists, and simple scripts that improve speed, quality, and consistency across similar projects.
Example Projects and Responsibilities
1. Infrastructure Security Resilience Assessment
Situation: A mid-size company needs a clear view of security gaps and a pragmatic, feasible plan to strengthen resilience across on-premises environments and Azure or AWS.
Responsibilities:
Lead discovery and baseline using Enduir’s assessment approach; review Active Directory and Entra, firewall and segmentation, endpoint and email security, logging and SIEM, backups and DR, and cloud posture (Azure or AWS).
- Serve as the primary technical lead: define the scope and depth of testing, identify quick wins versus structural fixes, and design remediation patterns the client can operate.
- Provide hands on configuration for high value changes, for example AD hardening, Conditional Access and MFA, firewall rules, SIEM onboarding, and backup immutability and restore testing.
- Lead two to three junior consultants: assign work packets, review configurations and evidence, coach on quality, and keep the team aligned to the plan.
- Own day to day delivery, schedule, budget, risks, and sponsor communication; keep stakeholders informed with clear status and next steps.
2. Ransomware Recovery
Situation: The organization has experienced a ransomware event and needs coordinated containment, recovery, and durable hardening.
Responsibilities:
- Act as the technical lead for recovery in partnership with incident leaders; set the recovery plan and execution rhythm across identity, endpoints, email, logging, and backups and DR.
- Execute critical configurations: rotate or disable compromised credentials, enforce MFA and Conditional Access, stand up clean room or bounce back infrastructure, rebuild from gold images, validate backup integrity, and perform targeted restores; expand SIEM telemetry coverage.
- Direct two to three junior team members through endpoint rebaselining, EDR deployment, email hygiene fixes (DMARC, DKIM, SPF), and backup verification; ensure clean documentation and handoff to operations.
- Coordinate MSPs and vendors for credential rekeys, license resets, escalations, and support cases.
- Maintain tight cadence, issue and risk management, and budget control; communicate decisions and rollback options clearly to sponsors.
3. IT Integration (Post Merger)
Situation: A mid-size acquisition requires a pragmatic integration of identity, networks, tools, and cloud resources without business disruption.
Responsibilities:
- Own the integration architecture and cutover plan: AD consolidation or trusts, Azure or AWS landing zone alignment, VNet or VPC peering and routing, firewall policy harmonization, and backup and DR alignment.
- Lead two to three junior consultants through migration wave planning and execution; prepare and test scripts, validate changes, and document as built configurations and runbooks for handoff.
- Coordinate MSPs and vendors; manage dependencies, change control, and rollback paths.
- Guide pilots and validation tests; align identity, access, and segmentation to the target security baseline and operating model.
- Control scope, schedule, and budget; provide concise executive updates to keep sponsors aligned during cutovers and stabilization.
Qualifications and Experience
- 5-9 years in infrastructure consulting or solutions architecture delivering remediation and modernization projects for mid-size companies; comfortable as the primary technical lead and day to day driver.
- Hybrid infrastructure mastery: deep hands-on skill in Active Directory and Entra (directory services, Group Policy, identity hardening) and one cloud platform (Azure or AWS), plus strength in at least one of firewalls and segmentation, backups and DR, or storage.
- Breadth across adjacent areas: networking (VLANs, routing, VPN/SD-WAN), virtualization (VMware), email and endpoint security, logging and SIEM onboarding, monitoring and observability, and basic identity federation patterns.
- Working knowledge of AI/ML tools and deployment patterns, with the ability to evaluate AI-enabled configurations and controls as part of client architecture reviews.
- Experience advising on AI integration considerations in cross-cutting technical designs, as AI capabilities are increasingly implemented across client environments.
- Consulting and delivery: able to scope engagements, shape SOWs, build pragmatic plans, manage scope, schedule, and budget, and provide clear executive and engineer level communication.
- Team leadership: comfortable leading two to three junior consultants or client engineers; assigns work packets, reviews configurations and evidence, and ensures quality and alignment to plan.
- Change event readiness: steady and structured during incidents, outages, migrations, and cutovers; plans rollback paths, manages risk and issue logs, and keeps stakeholders aligned.
- Incident involvement: willing to participate in post incident stabilization and resilience uplift; learns quickly from incident findings and converts them into durable configuration changes.
- Automation orientation (nice to have): PowerShell for Windows and AD tasks; Terraform or CloudFormation/Bicep for repeatable builds and guardrails.
- Tool familiarity: common enterprise stacks such as Defender/CrowdStrike, Sentinel/Splunk, Veeam/Rubrik/Cohesity, and Palo Alto/Fortinet/Cisco firewalls (specific vendor experience is helpful but not required).
- Work setup and travel: remote or hybrid; typically 10 to 30 percent travel for workshops, migrations, and cutovers.