Senior Microsoft Cloud & Platform Security Lead

Araxi Group

Role Purpose

Lead and own the overall Microsoft cloud and platform security posture across

the Client’s M365, Azure and hybrid environment. Set security standards, drive

Secure Score improvement, own Sentinel and Defender effectiveness, and act as

the senior technical authority and escalation point for platform security decisions

and complex incidents.

Key Responsibilities

  • Design, implement and continuously improve security controls across M365

and Azure, including Defender suite, Sentinel, Entra ID, and Azure

governance and policy frameworks.

  • Define and maintain technical security standards, baselines and patterns for

platform, cloud and M365 services aligned to CIS, NIST, ISO 27001 and

Sanlam Group standards.

  • Monitor and improve Microsoft Secure Score and other posture KPIs;

conduct security assessments and gap analyses across the Microsoft estate.

  • Act as L3/L4 escalation for complex or major incidents involving M365, Azure

and platform security; guide containment, forensics and recovery in

collaboration with the SOC.

  • Review and approve security designs for initiatives impacting Microsoft or

cloud platforms; maintain architecture decision records and control

rationale.

  • Govern PKI, Azure Key Vault, DevSecOps controls, GitHub Advanced Security

and AI/Copilot security guardrails in collaboration with the

Platform/DevSecOps engineer.

  • Provide escalation support and technical mentorship to all security

engineers; uplift team capability across Microsoft security technologies.

  • Represent platform security in architecture, project and Group forums;

ensure local controls align to Sanlam Group cyber standards and audit

expectations.

  • Coordinate with infrastructure, EUC, cloud platform, risk, audit and project

delivery stakeholders to ensure security is embedded across delivery

initiatives.

Scope Boundaries

  • Does not own day-to-day EUC/endpoint operations (Intune/MECM) or IAM

lifecycle administration; provides technical standards, challenge authority

and escalation support to those roles.

  • Infrastructure, cloud and application teams retain operational ownership of

their platforms; this role provides security leadership, guidance and

escalation.

  • Policy approval, budget authority and formal risk acceptance remain with

cyber leadership and governance forums.

Decision Rights

  • Approve or recommend Microsoft and platform security design patterns,

baseline controls and technical control configurations within delegated

authority.

  • Direct emergency containment measures for critical platform security

threats in line with incident procedures and delegated emergency response

authority.

  • Escalate material control gaps, remediation delays, unsupported platforms

or elevated residual risks to cyber leadership and relevant accountability

owners.

  • Recommend security tooling, architecture enhancements and operating

model changes to improve resilience, compliance and efficiency.

Core Technologies

Technology Area

Tools & Platforms

Microsoft Security Defender for Endpoint, Defender for Office

365, Defender for Identity, Defender for

Cloud Apps

SIEM & Detection Microsoft Sentinel, Secure Score, Microsoft

Defender XDR

Azure Security Defender for Cloud, Azure RBAC, NSGs,

security policies, logging

Identity (oversight) Entra ID, Conditional Access, Identity

Protection, PIM

Data Protection Microsoft Purview (oversight), DLP,

sensitivity labels

Platform Controls PKI governance, Azure Key Vault oversight,

GitHub Advanced Security, Power

Automate governance, Copilot Security

guardrails