Avanade is looking for an experienced Cloud Security & Exposure Management Architect to join our security practice. This is a client-facing role where you will be engaged in some of the most exciting, complex, and leading-edge projects. You will help clients improve their cloud security and exposure management maturity by identifying, prioritizing, and reducing exploitable risks across cloud, identity, endpoint, application, and data environments, using Microsoft Security technologies and modern threat-informed approaches.
You will also be part of the Avanade Security presales and Architecture function supporting the development of proposals, solution options, and architecture inputs for enterprise clients, with a focus on cloud security, exposure management, and Microsoft Security-led transformation. This role will include partial delivery expectations for the year.
In this role, you will:
- Lead defined workstreams or small project teams within larger cloud security and exposure management engagements.
- Manage assigned deliverables, including exposure assessments, remediation plans, security control improvements, and reporting outputs against agreed engagement milestones.
- Contribute to solution architecture and pre-sales deal shaping for cloud security, Microsoft Defender, Sentinel, Entra, Defender for Cloud, and exposure management opportunities.
Build trusted relationships with client security, cloud, and operations stakeholders during delivery and pre-sales engagements.
- Design, implement, and integrate cloud security, exposure management, threat detection, and security operations capabilities, including Microsoft Sentinel, Defender for Cloud, Defender XDR, and related Microsoft Security technologies.
- Understand threat modelling, attack paths, cloud misconfigurations, identity risks, vulnerabilities, and how to prioritise remediation based on exploitability and business impact.
- Understand incident response, cyber recovery, and how exposure management can reduce the likelihood and impact of security incidents.
- Understand security operations centre functions and how exposure insights can support detection engineering, prioritised remediation, and operational risk management.
- Have a good understanding of Microsoft platforms across Windows, Microsoft 365, Entra ID, Azure, and Defender, including how risks and exposures surface across these environments.
- Understand how threat actors exploit misconfigurations, identity weaknesses, vulnerable assets, exposed services, and weak security controls.
- Apply frameworks such as MITRE ATT&CK to help clients understand attack paths, prioritise exposures, and improve cyber defence maturity.
- Understand the business, privacy, security, and compliance challenges surrounding client data, critical assets, and digital services, and articulate how exposures could increase risk to those assets.
- Be aware of emerging technologies in cyber defence, cloud security, attack surface management, vulnerability management, and exposure management.
- Develop strong working relationships with account teams, delivery teams, security architects, and client stakeholders.
- Identify customer needs and business goals, then translate them into practical cloud security and exposure management solution options.
- Support the development of security transformation and operations opportunities, using standardised tools, Microsoft Security capabilities, partner technologies, and exposure-led assessment approaches.
- Contribute to proposals, client presentations, solution discussions, and technical input throughout the sales process.
- Conduct and follow through the sales process to accomplish deal closure.