Posted on: 18/05/2026
About the Role :
We are looking for a seasoned Cybersecurity Architect to join our advanced Security Operations Centre. This senior role will serve as a technical authority in Microsoft Security and MXDR environments, responsible for designing secure platforms, building advanced detections, and automating responses within a governance led SOC model. The position offers the opportunity to influence SOC architecture, detection engineering, and automation strategy while acting as a trusted advisor to enterprise clients.
Key Responsibilities :
- Design SOC/MXDR platforms and implement advanced security controls.
- Onboard clients into multi-tenant SOC environments and build custom detections.
- Develop proactive detection strategies using KQL queries, integrated threat intelligence, and behavioral analytics.
- Architect and maintain automated incident response playbooks using Azure Logic Apps.
- Lead major incident responses, including malware analysis, forensic investigations, and adversary TTP analysis.
- Drive continuous improvement of MXDR services, refining processes and enhancing detection capabilities.
- Mentor SOC analysts across tiers (L1/L2/L3) and guide collaborative investigations.
- Present technical findings and strategic recommendations to senior stakeholders.
- Operate within a governance-led SOC model, ensuring compliance with ISO 27001, SOC2, PCI-DSS, and
NIST frameworks.
Required Skills & Experience :
- 12+ years of overall experience in cybersecurity, with at least 7- 10 years in advanced SOC operations, Incident Response, Threat Hunting, or Detection Engineering.
- Hands-on expertise in Microsoft Sentinel (advanced KQL, analytics rules, connector onboarding).
- Deep knowledge of Microsoft Defender XDR (Endpoint, Identity, Office 365, Cloud Apps).
- Strong experience with Entra ID, GDAP, PIM, and Zero Trust access models.
- Experience with Azure Lighthouse for multi-tenant SOC operations.
- Detection-as-Code expertise (GitHub/Azure DevOps, CI/CD pipelines, MITRE ATT&CK mapping).
- Advanced incident response skills, including malware analysis and forensic techniques.
- Strong consulting and communication skills to advise clients on security posture improvements.
Preferred Certifications :
- Microsoft Certified : SC-200 (Security Operations Analyst)
- Microsoft Certified : SC-100 (Cybersecurity Architect Expert)
- Microsoft Certified : Azure Security Engineer Associate (AZ-500)
- GIAC Certified Forensic Analyst (GCFA), GIAC Certified Incident Handler (GCIH), CISSP, OSCP (or equivalent).
Did you find something suspicious?
Posted by
Recruiter
Last Active: NA as recruiter has posted this job through third party tool.
Posted in
CyberSecurity
Functional Area
Cyber Security
Job Code
1636701