Security Architect
Security ArchitectPosition OverviewThe Security Architect is a senior technical leadership role responsible for defining, governing and evolving secure enterprise architectures across Advania's Managed Services client base.The role provides strategic and technical leadership across identity, security, cloud, infrastructure, networking, data protection and operational security domains, with a particular focus on Microsoft technologies including Entra ID, Defender, Sentinel, Purview, Azure and Microsoft 365.Salary & BenefitsOur salaries are competitive within the cyber marketClick here for the list of benefits.Hybrid workingWe recognise the benefits that remote and flexible working brings.We operate a hybrid working policy that allows our employees to balance time in the office and time from home. Each team within our organisation can decide how to implement this policy. If you have any questions after applying, please reach out to our recruitment team.ResponsibilitiesKey ResponsibilitiesSecurity Architecture LeadershipAct as the lead security architecture authority across assigned Managed Services clients.Develop enterprise security strategies, roadmaps and target-state architectures.Produce and govern High-Level Designs (HLDs), Low-Level Designs (LLDs) and reference architectures.Ensure architectures align with Zero Trust, Security by Design and Secure by Default principles.Conduct architecture reviews and design assurance activities.Identity & Access Management ArchitectureDesign and govern enterprise identity strategies across cloud, hybrid and on-premises environments.Lead architecture for:Microsoft Entra IDActive DirectoryIdentity GovernancePrivileged Identity Management (PIM)Conditional AccessAuthentication ServicesFederationSingle Sign-OnB2B/B2C identity modelsDefine lifecycle management and access governance strategies.Architect integrations between Microsoft identity services and third-party platforms. Managed Identities, Conditional Access, Identity Governance, Enterprise Applications and hybrid identity capabilities are core areas already recognised within Advania's service offerings.Microsoft Security ArchitectureProvide architectural ownership across the Microsoft security ecosystem, including:Microsoft Defender SuiteMicrosoft SentinelMicrosoft PurviewSecurity CopilotMicrosoft IntuneEntra ID SecurityAzure Security ServicesMicrosoft 365 Security & ComplianceDevelop security patterns and reference architectures for:Threat protectionIdentity protectionData protectionInsider risk managementSecurity monitoringComplianceAI securityThese technologies are explicitly identified as core security architecture domains within Advania's security architecture practice.Infrastructure & Platform IntegrationDesign secure architectures spanning:AzureAWSGoogle CloudOn-premises infrastructureSaaS platformsDatacentre environmentsLead secure integration of:Third-party security productsNetwork infrastructureBusiness applicationsIdentity providersSecurity operations toolingAssess technical dependencies and integration risks across complex customer estates.Managed Services EnablementSupport the onboarding of customer environments into managed services.Ensure new solutions are operationally supportable.Define service acceptance criteria and operational design requirements.Work alongside SOC, Managed Identity, Azure and Infrastructure teams to establish support models.Provide technical governance throughout the service lifecycle.Client Advisory & Strategic EngagementAct as trusted advisor to CIO, CTO, CISO and technology leadership teams.Facilitate architecture workshops and strategy sessions.Develop security strategies, maturity roadmaps and investment plans.Present architecture solutions and recommendations to executive and board-level stakeholders.Support client security assessments, audits and transformation programmes.Service DevelopmentSupport the creation and evolution of Managed Security Services.Define architecture standards, reusable patterns and technical frameworks.Evaluate emerging technologies and services.Drive innovation across identity, cloud security, AI security and automation.What Success Looks LikeStructural review of 10 clients, understand posture, contract, roadmaps and major risksDevelop reusable patterns covering Entra ID, Purview, and Defender for CloudSupport at least 5 qualified opportunitiesQualifications & ExperienceSecurity ArchitectureMinimum 3-5 years' experience in enterprise security, cloud architecture or cyber security roles.Demonstrable experience operating as a Security Architect, Enterprise Architect or Principal Consultant.Strong understanding of:Zero Trust ArchitectureSecure Architecture FrameworksThreat ModellingSecurity GovernanceRisk ManagementSecurity EngineeringData ProtectionMicrosoft ExpertiseAdvanced experience across:Microsoft Entra IDMicrosoft Defender SuiteMicrosoft SentinelMicrosoft PurviewMicrosoft IntuneAzure SecurityMicrosoft 365 Security & ComplianceIdentity & Access ManagementDeep expertise in:AuthenticationFederationSSOMFAPIMIdentity GovernanceDirectory ServicesHybrid IdentityInfrastructureStrong understanding of:NetworkingHybrid InfrastructureAzure Landing ZonesCloud SecurityCloud based PKIInfrastructure IntegrationAPI SecuritySecurity MonitoringClient EngagementExtensive client-facing consultancy experience.Executive stakeholder management.Architecture workshop facilitation.Technical leadership across multiple concurrent clients.Desirable ExperienceManaged Services environment.Security Operations integration.Exposure Management and Vulnerability Management platforms.AI security and governance.Multi-cloud security architecture.Secure DevOps / DevSecOps.Regulatory environments including:ISO 27001NIST CSFNIS2Cyber EssentialsGDPRDORAFCA / PRACertificationsPreferredCISSPCCSPCISMSABSA PractitionerMicrosoftSC-100 Cybersecurity Architect ExpertSC-300 Identity & Access AdministratorSC-200 Security Operations AnalystAZ-500 Azure Security EngineerAZ-305 Azure Solutions ArchitectSuccess MeasuresTrusted architecture authority across assigned clients.Security architectures successfully deployed into operational managed services.Increased adoption of Microsoft security technologies.Improved client security maturity and resilience.Growth of architecture-led consultancy and managed service opportunities.Reusable architecture standards and patterns established across the business.Positive client satisfaction and stakeholder feedback.About Us:We are the tech company with people at heart.At Advania, we believe in empowering people to create sustainable value through the clever use of technology. As one of Microsoft's leading partners in the UK, specialising in Azure, Security, Dynamics 365, and Microsoft 365, we have a proven track record of success in delivering transformational IT services.Our Selection Process:We are committed to ensuring an equitable experience for all candidates, regardless of race, religion or belief, ethnic or national origin, disability, age, citizenship, marital, domestic or civil partnership status, sexual orientation, gender identity, or any other basis as protected by applicable law.Please do let us know if you’ll need any reasonable adjustments as part of the selection process by highlighting these on your application form.As part of our commitment to our clients we will need to carry out background checks, including a criminal record check, for all offers of employment. If you have any unspent criminal convictions or questions about the screening process, please notify your recruiter once the application has been submitted.#LI-Hybrid