Role Purpose
Lead and own the overall Microsoft cloud and platform security posture across the Client’s M365, Azure and hybrid environment. Set security standards, drive Secure Score improvement, own Sentinel and Defender effectiveness, and act as the senior technical authority and escalation point for platform security decisions and complex incidents.
Key Responsibilities
- Design, implement and continuously improve security controls across M365 and Azure, including Defender suite, Sentinel, Entra ID, and Azure governance and policy frameworks.
- Define and maintain technical security standards, baselines and patterns for platform, cloud and M365 services aligned to CIS, NIST, ISO 27001 and Sanlam Group standards.
- Monitor and improve Microsoft Secure Score and other posture KPIs; conduct security assessments and gap analyses across the Microsoft estate.
- Act as L3/L4 escalation for complex or major incidents involving M365, Azure and platform security; guide containment, forensics and recovery in collaboration with the SOC.
- Review and approve security designs for initiatives impacting Microsoft or cloud platforms; maintain architecture decision records and control rationale.
- Govern PKI, Azure Key Vault, DevSecOps controls, GitHub Advanced Security and AI/Copilot security guardrails in collaboration with the Platform/DevSecOps engineer.
- Provide escalation support and technical mentorship to all security engineers; uplift team capability across Microsoft security technologies.
- Represent platform security in architecture, project and Group forums; ensure local controls align to Sanlam Group cyber standards and audit expectations.
- Coordinate with infrastructure, EUC, cloud platform, risk, audit and project delivery stakeholders to ensure security is embedded across delivery initiatives.
Scope Boundaries
- Does not own day-to-day EUC/endpoint operations (Intune/MECM) or IAM lifecycle administration; provides technical standards, challenge authority and escalation support to those roles.
- Infrastructure, cloud and application teams retain operational ownership of their platforms; this role provides security leadership, guidance and escalation.
- Policy approval, budget authority and formal risk acceptance remain with cyber leadership and governance forums.
Decision Rights
- Approve or recommend Microsoft and platform security design patterns, baseline controls and technical control configurations within delegated authority.
- Direct emergency containment measures for critical platform security threats in line with incident procedures and delegated emergency response authority.
- Escalate material control gaps, remediation delays, unsupported platforms or elevated residual risks to cyber leadership and relevant accountability owners.
- Recommend security tooling, architecture enhancements and operating model changes to improve resilience, compliance and efficiency.
Core Technologies
Technology Area
Tools & Platforms
Microsoft Security Defender for Endpoint, Defender for Office 365, Defender for Identity, Defender for Cloud Apps
SIEM & Detection Microsoft Sentinel, Secure Score, Microsoft Defender XDR
Azure Security Defender for Cloud, Azure RBAC, NSGs, security policies, logging
Identity (oversight) Entra ID, Conditional Access, Identity Protection, PIM
Data Protection Microsoft Purview (oversight), DLP, sensitivity labels
Platform Controls PKI governance, Azure Key Vault oversight, GitHub Advanced Security, Power Automate governance, Copilot Security guardrails