Senior Microsoft Cloud & Platform Security Lead
Araxi Group
Role Purpose
Lead and own the overall Microsoft cloud and platform security posture across
the Client’s M365, Azure and hybrid environment. Set security standards, drive
Secure Score improvement, own Sentinel and Defender effectiveness, and act as
the senior technical authority and escalation point for platform security decisions
and complex incidents.
Key Responsibilities
- Design, implement and continuously improve security controls across M365
and Azure, including Defender suite, Sentinel, Entra ID, and Azure
governance and policy frameworks.
- Define and maintain technical security standards, baselines and patterns for
platform, cloud and M365 services aligned to CIS, NIST, ISO 27001 and
Sanlam Group standards.
- Monitor and improve Microsoft Secure Score and other posture KPIs;
conduct security assessments and gap analyses across the Microsoft estate.
- Act as L3/L4 escalation for complex or major incidents involving M365, Azure
and platform security; guide containment, forensics and recovery in
collaboration with the SOC.
- Review and approve security designs for initiatives impacting Microsoft or
cloud platforms; maintain architecture decision records and control
rationale.
- Govern PKI, Azure Key Vault, DevSecOps controls, GitHub Advanced Security
and AI/Copilot security guardrails in collaboration with the
Platform/DevSecOps engineer.
- Provide escalation support and technical mentorship to all security
engineers; uplift team capability across Microsoft security technologies.
- Represent platform security in architecture, project and Group forums;
ensure local controls align to Sanlam Group cyber standards and audit
expectations.
- Coordinate with infrastructure, EUC, cloud platform, risk, audit and project
delivery stakeholders to ensure security is embedded across delivery
initiatives.
Scope Boundaries
- Does not own day-to-day EUC/endpoint operations (Intune/MECM) or IAM
lifecycle administration; provides technical standards, challenge authority
and escalation support to those roles.
- Infrastructure, cloud and application teams retain operational ownership of
their platforms; this role provides security leadership, guidance and
escalation.
- Policy approval, budget authority and formal risk acceptance remain with
cyber leadership and governance forums.
Decision Rights
- Approve or recommend Microsoft and platform security design patterns,
baseline controls and technical control configurations within delegated
authority.
- Direct emergency containment measures for critical platform security
threats in line with incident procedures and delegated emergency response
authority.
- Escalate material control gaps, remediation delays, unsupported platforms
or elevated residual risks to cyber leadership and relevant accountability
owners.
- Recommend security tooling, architecture enhancements and operating
model changes to improve resilience, compliance and efficiency.
Core Technologies
Technology Area
Tools & Platforms
Microsoft Security Defender for Endpoint, Defender for Office
365, Defender for Identity, Defender for
Cloud Apps
SIEM & Detection Microsoft Sentinel, Secure Score, Microsoft
Defender XDR
Azure Security Defender for Cloud, Azure RBAC, NSGs,
security policies, logging
Identity (oversight) Entra ID, Conditional Access, Identity
Protection, PIM
Data Protection Microsoft Purview (oversight), DLP,
sensitivity labels
Platform Controls PKI governance, Azure Key Vault oversight,
GitHub Advanced Security, Power
Automate governance, Copilot Security
guardrails