Sobre esta vaga de Security Architect — Microsoft Security Platform na Accenture
Avanade India
Security Architect — Microsoft Security Platform
Practice: Cyber Security, Avanade India
Location: Bengaluru / Delhi NCR / Mumbai, India (Hybrid)
Experience: 14–18 years in the cyber security domain, with deep, current, hands-on architecture experience across the Microsoft security platform — Microsoft Sentinel, Defender, Purview, Entra ID and Intune
Role Summary
Avanade India’s Cyber Security practice is looking for a Security Architect with genuine depth across the full Microsoft security estate. This is a senior, client-facing role for someone who can hold a security conversation with a CISO in the morning, defend a Sentinel data architecture with a SOC team in the afternoon, and be equally credible in both rooms.
The emphasis is on breadth across the Microsoft security platform combined with real depth in each pillar — threat protection, cloud security, identity, data security and compliance — and the ability to design them as one integrated architecture rather than a set of separately deployed products. You will lead security architecture on client engagements, shape pursuits as the security SME, and build the standards, IP and skilling that the practice runs on.
Key Responsibilities
- Own end-to-end security architecture for client engagements — target-state security architecture, Zero Trust design, control mapping and multi-year security roadmaps grounded in the client’s risk profile and regulatory context.
- Architect and lead Microsoft Sentinel implementations: workspace and tenant design, ingestion strategy, log tiering and cost optimisation, detection engineering in KQL, UEBA, SOAR playbooks and threat intelligence integration.
- Lead migrations from legacy SIEM platforms (Splunk, QRadar, ArcSight and similar) to Microsoft Sentinel — content and use-case migration, parallel running, validation and decommissioning.
- Design across Microsoft Defender XDR — Defender for Endpoint, Defender for Identity, Defender for Office 365 and Defender for Cloud Apps — covering deployment architecture, policy design, tuning, incident correlation and cross-product investigation.
- Architect cloud workload and posture security with Defender for Cloud — CSPM and CWPP, secure score improvement, regulatory compliance dashboards, and container, server and database protection.
- Design Microsoft Purview solutions across data security and compliance: information protection and sensitivity labelling, DLP, insider risk management, data lifecycle and records, eDiscovery and Compliance Manager.
- Architect identity security on Entra ID: conditional access design, Privileged Identity Management, identity governance and entitlement management, passwordless and phishing-resistant authentication, and identity threat detection and response.
- Design endpoint security through Intune — security baselines, attack surface reduction and compliance policies — integrated with Defender for Endpoint.
- Lead security assessments and maturity reviews — gap analysis against NIST CSF, ISO 27001, CIS and Microsoft Zero Trust maturity, with prioritised, costed remediation roadmaps.
- Design SOC target operating models and detection strategy: use-case catalogues, detection engineering lifecycle, incident response runbooks, threat hunting, automation and MDR/managed service interlock.
- Advise on securing AI adoption — Copilot readiness and oversharing remediation, data security posture for AI, agent governance, and the controls that make AI deployment defensible.
- Align security architecture to regulatory and data protection requirements — India’s DPDP Act, GDPR, and sector guidance such as RBI, SEBI or IRDAI where applicable.
- Act as security design authority across delivery: design reviews, architecture governance, escalation support and assurance of security deliverable quality.
- Lead security solutioning on pursuits — workshops, solution architecture, estimation, proposals and RFP responses — presenting credibly to CISO-level stakeholders.
- Build practice IP: reference architectures, deployment accelerators, detection content libraries, assessment frameworks and delivery playbooks.
- Mentor security architects, consultants and analysts; drive certification and skilling across the security capability.
Required Skills & Experience
- 15–20 years in cyber security across architecture, engineering, consulting or security operations, with a substantial recent focus on the Microsoft security platform.
- Deep, hands-on architecture experience across Microsoft Sentinel, Defender XDR, Defender for Cloud, Purview, Entra ID and Intune — beyond product positioning, into design decisions, trade-offs and known pitfalls.
- Strong Microsoft Sentinel depth: ingestion and cost architecture, KQL proficiency, detection engineering, automation with Logic Apps, and experience running or migrating a SIEM at enterprise scale.
- Proven design experience across the Defender suite, including deployment at scale, policy and exclusion strategy, alert tuning and reduction of analyst noise.
- Solid Purview experience across information protection, DLP and at least one of insider risk, data lifecycle or eDiscovery — including classification and labelling strategy.
- Strong identity security background: Entra ID architecture, conditional access, privileged access, identity governance, and hybrid identity in complex estates.
- Working knowledge of Azure platform security — network security, Key Vault, encryption, and how platform design affects security posture.
- Practical command of security frameworks and standards: NIST CSF, ISO 27001, CIS Controls, MITRE ATT&CK, and Zero Trust reference models.
- Experience with data protection and regulatory requirements applicable to Indian and global clients, and the ability to translate them into technical controls.
- Demonstrated experience leading security assessments and producing prioritised, executive-ready roadmaps and business cases.
- Incident response and threat landscape awareness — able to reason about attacker behaviour, not only about product configuration.
- Strong client-facing consulting skills, including CISO and executive stakeholder engagement and pre-sales solutioning, estimation and proposal work.
- Track record of mentoring and technically leading security teams on medium-to-large engagements.
- Clear technical writing — architecture documents, assessment reports, standards and runbooks at client-ready quality.
Preferred / Good to Have
- Microsoft certifications: SC-100, SC-200, SC-300, SC-400 or AZ-500; industry certifications such as CISSP, CISM, CCSP or ISO 27001 Lead Auditor.
- Experience supporting Microsoft security specializations and partner programmes — capability alignment, audit and evidence preparation.
- Experience designing or running MDR / managed security services — shift models, SLAs and service transition.
- Automation and IaC for security deployment — PowerShell, Logic Apps, Bicep or Terraform for repeatable security configuration.
- Exposure to OT/IoT security (Defender for IoT) or to securing manufacturing and critical infrastructure environments.
- Multi-cloud security experience (AWS, GCP) and integration of third-party tooling into Sentinel.
- Experience in regulated industries — BFSI, healthcare, energy or public sector — including regulator-facing work.
- Experience in a global delivery / SI or Microsoft partner environment with distributed teams.
- Thought leadership — speaking, publishing or detection content shared with the security community.
.
NA
.