← Back to job listings

Lead Security Architect (MDE, Entra ID, MDCA)
7505 PT Avanade Teknologi IN Company · Jakarta, Indonesia
About The Role
Summary
Join Avanade’s Security Practice to lead the architecture of integrated Microsoft security solutions for large enterprise environments. You will shape Defender and identity designs, guide implementation, manage technical stakeholders, and maintain alignment between approved architecture, security requirements, platform dependencies, and delivery outcomes.
Key Responsibilities
- Lead discovery and architecture activities across Microsoft Defender XDR, Microsoft Defender for Endpoint, Microsoft Entra ID, and Microsoft Defender for Cloud Apps.
- Assess endpoint security configurations, identity controls, user synchronization, MFA, Conditional Access, application connectors, policy requirements, and integration dependencies.
- Define Defender for Endpoint architecture covering EDR baselines, antivirus policies, Attack Surface Reduction rules, onboarding requirements, coexistence considerations, and policy deployment through Intune.
- Design Defender for Cloud Apps connectors and policies for Microsoft 365 applications, cloud discovery, threat detection, files, sessions, and Conditional Access App Control.
- Define Microsoft Entra ID design considerations for identity synchronization, Conditional Access, MFA, RBAC, PIM, licensing, and integration with Defender capabilities.
- Produce technical designs, configuration guidance, integration approaches, architecture decisions, assumptions, dependencies, and risk inputs.
- Lead design reviews, implementation walkthroughs, stakeholder discussions, and knowledge-transfer sessions.
- Provide architecture guidance during go-live, hypercare, and warranty for issues related to approved designs and configuration guidance.
.
Skill and Experiences
- Min 10+ years of experience in cybersecurity architecture, Microsoft security consulting, enterprise security delivery, or related technology roles.
- Strong architecture experience with Microsoft Defender XDR, Microsoft Defender for Endpoint, and Microsoft Defender for Cloud Apps.
- Strong knowledge of Microsoft Entra ID, Active Directory integration, identity synchronization, MFA, Conditional Access, RBAC, and Privileged Identity Management.
- Able to lead architecture workshops and explain security decisions, risks, prerequisites, and implementation guidance to technical and senior stakeholders
- Strong ownership of design quality and scope boundaries
- Experience designing EDR baselines, antivirus policies, ASR rules, endpoint onboarding, security-policy deployment, and legacy security-tool coexistence approaches.
- Knowledge of MDCA connectors, cloud discovery, threat-detection, file, session, and Conditional Access App Control policies.
- Understanding of Microsoft security licensing, access prerequisites, policy dependencies, and enterprise security governance
- Comfortable coordinating across security, identity, endpoint, Intune, SOC, engineering, delivery, and client IT teams throughout solution design and delivery
- Desirable Microsoft certifications include SC-200, MD-102, SC-900, AZ-500, SC-300, SC-401.
.
Similar roles you might like
See all →AB
Delivery Material Handler/Roof Loader (303)
American Builders and Contractors Supply Co., Inc.
Salary not disclosedPosted 4 days ago
T
Industrial Manager - Transfer of Production
thales
Salary not disclosedPosted 4 days ago
F
Corporate Sales Executive
fastretailing
Salary not disclosedPosted 4 days ago
GP
Market Executive (Surabaya)
GTN_IDN PT Global Tiket Network
Salary not disclosedPosted 4 days ago
A
Business Development Manager (Indonesia)
Avomind
Salary not disclosedPosted 4 days ago
T
Business Development Representative
Teltonika
Salary not disclosedPosted 4 days ago
0Y
Supporting staff
0100 Yayasan Bhakti Tanoto
Salary not disclosedPosted 4 days ago
A
RCM Engineer, Reliability, Oil Analysis
averis
Salary not disclosedPosted 4 days ago
This is an external listing. JobSpring does not represent or verify the employer. Report this listing
