At a Glance
- Tasks: Design and implement cloud security architectures for Microsoft environments while driving automation in cyber defense.
- Company: Join WTW’s Global Information and Cyber Security Defence team, a leader in security solutions.
- Benefits: Enjoy a hybrid work model with remote options and opportunities for professional growth.
- Why this job: Be at the forefront of cloud security, tackling evolving threats and enhancing enterprise protection.
- Qualifications: Strong experience with Microsoft Defender, Sentinel, and cloud security best practices required.
- Other info: Ideal for strategic thinkers passionate about cybersecurity and innovation.
The predicted salary is between 60000 - 84000 £ per year.
We are seeking an experienced Microsoft Cloud Security Architect to join WTW’s Global Information and Cyber Security Defence (ICSD) function. This role will be instrumental in designing and implementing cloud security architectures, securing WTW cloud environments, and driving automation across cyber defence operations.
The ideal candidate will have extensive expertise in Microsoft Defender XDR, Defender for Cloud, Microsoft Sentinel, Conditional Access, and Identity Protection. Additional experience with SOAR, UEBA, SIEM, Email Security, Cloud Workload Protection, CSPM is highly desirable. This role requires a strategic thinker who can integrate cloud security solutions, automate detection and response processes, and enhance Cyber Defence operations to protect enterprise environments against evolving threats. This is a hybrid role with remote working style; however, the candidate is expected to be in the office once a week or as needed.
The Role:
Microsoft Cloud Security Architecture & Strategy
- Design and implement Microsoft Cloud Security Architectures for Azure, Microsoft 365, and hybrid cloud environments.
- Lead the adoption of Zero Trust security models across Identity, Devices, Networks, and Applications.
- Ensure Defender XDR and Defender for Cloud are optimised for advanced threat detection and response.
- Develop enterprise-wide security frameworks and standards to align with industry best practices (NIST, ISO 27001, CIS, GDPR, etc.).
- Assess and improve cloud security postures using CSPM and CWPP tools.
- Configure and manage Microsoft Defender XDR (Defender for Endpoint, Defender for Identity, Defender for Cloud Apps, Defender for Office 365) for holistic security coverage.
- Deploy and fine-tune Microsoft Defender for Cloud to detect cloud vulnerabilities, misconfigurations, and compliance risks.
- Integrate Defender solutions with Sentinel and SOAR automation to enhance SOC operations.
Microsoft Sentinel, SIEM, UEBA & SOAR
- Architect and optimise Microsoft Sentinel for SIEM, UEBA, and threat intelligence integration.
- Develop custom analytics rules, alerting mechanisms, and advanced KQL queries for proactive threat detection.
- Implement SOAR workflows and automated response playbooks to streamline incident response.
- Enhance User and Entity Behaviour Analytics (UEBA) in Sentinel for insider threat detection and anomaly monitoring.
Identity Security & Conditional Access
- Design and enforce Identity Security policies, including Azure AD Conditional Access, MFA, and Identity Protection.
- Implement Privileged Identity Management (PIM) and Just-in-Time (JIT) access controls to mitigate identity-based attacks.
- Monitor and respond to identity compromise threats using Microsoft Defender for Identity and Sentinel UEBA.
Email Security
- Strengthen email security using Microsoft Defender for Office 365 (MDO) and Darktrace Email.
- Implement advanced phishing detection, threat intelligence feeds, and anomaly-based behavioural analysis for email protection.
- Automate email security response actions using SOAR and Defender for Office 365 AIR (Automated Investigation and Response).
Security Automation & Process Documentation
- Develop security automation workflows using Microsoft Sentinel playbooks, Logic Apps, and Power Automate.
- Document security architectures, integrations, and automation processes in runbooks, SOPs, and technical guidelines.
- Establish security governance frameworks to ensure compliance and risk management alignment.
- Work closely with GSOC, Threat Hunting, Insider Threats, Threat Intelligence, and ICS Change teams to align cloud security strategies with business needs.
- Stay up to date with emerging threats, Microsoft security innovations, and industry trends to drive continuous security enhancements.
- Provide training and mentorship to SOC teams on Microsoft cloud security best practices.
The Requirements:
Must-Have Skills:
- Strong hands-on experience with Microsoft Defender for Cloud for cloud security posture management (CSPM) and workload protection (CWP).
- Knowledge of WIZ Cloud, Microsoft Defender for Cloud, Azure Policy, and Security Baselines.
- Proficiency in Microsoft Sentinel SIEM for threat detection, incident response, and threat hunting.
- Experience designing SOAR workflows for automated security response and incident triage.
- Expertise in KQL queries, custom detection rules, and UEBA use cases.
- Strong understanding of Entra ID Security, Conditional Access, Identity Protection, and Privileged Access Management (PIM).
- Experience with Just-in-Time (JIT) access, Zero Trust identity models, and identity compromise detection.
- Hands-on experience securing email environments using Microsoft Defender for Office 365 (MDO) and Darktrace Email AI-driven security.
- Expertise in anti-phishing, Safe Links/Safe Attachments, attack simulation, and email threat intelligence.
- Experience automating security tasks using Microsoft Sentinel playbooks, Logic Apps, Power Automate, and KQL-based automation.
- Ability to write clear and detailed documentation for security architecture, processes, and incident response procedures.
Beneficial Skills:
- Experience working with global Cyber Defence/SOC teams.
- Knowledge of MITRE ATT&CK framework and its application in threat detection and response.
- Understanding of compliance standards (ISO 27001, NIST CSF, GDPR, SOC 2).
- Familiarity with third-party integrations (e.g., Threat Intelligence Platforms, SOAR tools, Security APIs).
Certifications (Preferred):
- Microsoft Certified: Cybersecurity Architect Expert (SC-100).
- Microsoft Certified: Azure Security Engineer Associate (AZ-500).
- Microsoft Certified: Security Operations Analyst Associate (SC-200).
- Microsoft Certified: Identity and Access Administrator Associate (SC-300).
- Certified Information Systems Security Professional (CISSP).
- Certified Cloud Security Professional (CCSP).
#J-18808-Ljbffr
Microsoft Cloud Security Architect employer: WTW
Contact Detail:
WTW Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Microsoft Cloud Security Architect
✨Tip Number 1
Make sure to stay updated on the latest Microsoft security innovations and industry trends. This knowledge will not only help you in interviews but also demonstrate your commitment to continuous learning in the field of cloud security.
✨Tip Number 2
Network with professionals in the cybersecurity field, especially those who work with Microsoft technologies. Engaging in discussions or attending relevant webinars can provide insights and potentially lead to referrals for the position.
✨Tip Number 3
Familiarize yourself with the specific tools mentioned in the job description, such as Microsoft Defender XDR and Sentinel. Hands-on experience or even lab practice with these tools can set you apart from other candidates.
✨Tip Number 4
Prepare to discuss real-world scenarios where you've implemented cloud security solutions or automated processes. Being able to share concrete examples will showcase your expertise and problem-solving skills during the interview.
We think you need these skills to ace Microsoft Cloud Security Architect
Some tips for your application 🫡
Tailor Your CV: Make sure your CV highlights your experience with Microsoft Defender XDR, Defender for Cloud, and other relevant tools mentioned in the job description. Use specific examples to demonstrate your expertise in cloud security architectures and automation.
Craft a Strong Cover Letter: In your cover letter, express your passion for cloud security and how your skills align with WTW’s needs. Mention your strategic thinking abilities and provide examples of how you've successfully integrated cloud security solutions in previous roles.
Highlight Relevant Certifications: List any relevant certifications such as Microsoft Certified: Cybersecurity Architect Expert or Microsoft Certified: Azure Security Engineer Associate. This will strengthen your application and show your commitment to professional development in the field.
Showcase Your Problem-Solving Skills: Use your application to illustrate your problem-solving skills, especially in relation to identity security and incident response. Provide examples of how you've developed automated workflows or enhanced security postures in past positions.
How to prepare for a job interview at WTW
✨Showcase Your Technical Expertise
Be prepared to discuss your hands-on experience with Microsoft Defender for Cloud, Sentinel, and other relevant tools. Highlight specific projects where you implemented cloud security architectures or automated security processes.
✨Demonstrate Strategic Thinking
Discuss how you approach designing security frameworks and integrating Zero Trust models. Provide examples of how you've assessed and improved cloud security postures in previous roles.
✨Prepare for Scenario-Based Questions
Expect questions that assess your problem-solving skills in real-world scenarios. Be ready to explain how you would handle identity compromise threats or optimize incident response workflows using SOAR.
✨Stay Updated on Industry Trends
Show your passion for cybersecurity by discussing recent trends, emerging threats, and Microsoft security innovations. This demonstrates your commitment to continuous learning and improvement in the field.