
Avanade is looking for an experienced Cloud Security & Exposure Management Architect to join our security practice. This is a client-facing role where you will be engaged in some of the most exciting, complex, and leading-edge projects. You will help clients improve their cloud security and exposure management maturity by identifying, prioritizing, and reducing exploitable risks across cloud, identity, endpoint, application, and data environments, using Microsoft Security technologies and modern threat-informed approaches.
You will also be part of the Avanade Security presales and Architecture function supporting the development of proposals, solution options, and architecture inputs for enterprise clients, with a focus on cloud security, exposure management, and Microsoft Security-led transformation. This role will include partial delivery expectations for the year.
In this role, you will:
• Lead defined workstreams or small project teams within larger cloud security and exposure management engagements.
• Manage assigned deliverables, including exposure assessments, remediation plans, security control improvements, and reporting outputs against agreed engagement milestones.
• Contribute to solution architecture and pre-sales deal shaping for cloud security, Microsoft Defender, Sentinel, Entra, Defender for Cloud, and exposure management opportunities.
Build trusted relationships with client security, cloud, and operations stakeholders during delivery and pre-sales engagements.
• Design, implement, and integrate cloud security, exposure management, threat detection, and security operations capabilities, including Microsoft Sentinel, Defender for Cloud, Defender XDR, and related Microsoft Security technologies.
• Understand threat modelling, attack paths, cloud misconfigurations, identity risks, vulnerabilities, and how to prioritise remediation based on exploitability and business impact.
• Understand incident response, cyber recovery, and how exposure management can reduce the likelihood and impact of security incidents.
• Understand security operations centre functions and how exposure insights can support detection engineering, prioritised remediation, and operational risk management.
• Have a good understanding of Microsoft platforms across Windows, Microsoft 365, Entra ID, Azure, and Defender, including how risks and exposures surface across these environments.
• Understand how threat actors exploit misconfigurations, identity weaknesses, vulnerable assets, exposed services, and weak security controls.
• Apply frameworks such as MITRE ATT&CK to help clients understand attack paths, prioritise exposures, and improve cyber defence maturity.
• Understand the business, privacy, security, and compliance challenges surrounding client data, critical assets, and digital services, and articulate how exposures could increase risk to those assets.
• Be aware of emerging technologies in cyber defence, cloud security, attack surface management, vulnerability management, and exposure management.
• Develop strong working relationships with account teams, delivery teams, security architects, and client stakeholders.
• Identify customer needs and business goals, then translate them into practical cloud security and exposure management solution options.
• Support the development of security transformation and operations opportunities, using standardised tools, Microsoft Security capabilities, partner technologies, and exposure-led assessment approaches.
• Contribute to proposals, client presentations, solution discussions, and technical input throughout the sales process.
• Conduct and follow through the sales process to accomplish deal closure.
• Advanced Microsoft Security Certifications such as: SC-100, SC-200, SC-300, SC-400, SC-900.
• Industry-recognised certifications such as: CISSP, CCSP, CISM, SANS.
• Microsoft Security and Exposure Management: Build strong knowledge of Microsoft Security tools such as Defender for Cloud, Microsoft Sentinel, Defender XDR, Security Copilot, Entra ID, and Exposure Management capabilities to help clients identify, prioritise, and reduce security risks across cloud and hybrid environments.
• Cloud Security and Exposure Architecture: Support the design and implementation of secure cloud architectures, exposure management approaches, and remediation patterns that improve security posture and align to industry standards.
• RFP Responses: Support responses to RFPs related to cloud security, exposure management, security operations, and Microsoft Security services.
• Continuous Improvement: Stay updated on cloud security, exposure management, threat intelligence, vulnerability trends, and Microsoft Security capabilities to improve client recommendations and delivery quality.
• Knowledge of exposure management concepts, including attack paths, vulnerabilities, misconfigurations, identity exposures, internet-facing assets, control gaps, and remediation prioritisation.
• Experience supporting cloud security assessments, posture reviews, exposure analysis, or remediation planning across Microsoft Azure and Microsoft Security environments.
• Ability to translate technical exposure findings into business risk, prioritised actions, and clear client recommendations.
• Ability to contribute to RFP responses related to cloud security, exposure management, and Managed Security Services.
• Beneficial Knowledge: Familiarity with the Defender suite of products, including Microsoft Defender for Endpoint, Microsoft Defender for Identity, Microsoft Defender for Office 365, and Microsoft Cloud App Security.
• Certifications such as CISSP, CCSP, or Azure Security Engineer.
• Experience with other cloud platforms (AWS, Google Cloud) and their security tools.
• Knowledge of regulatory compliance requirements (e.g., GDPR, HIPAA).

Avanade is the world’s leading expert on Microsoft. Trusted by over 7,000 clients worldwide, we deliver AI-driven solutions that unlock the full potential of people and technology, optimize operations, foster innovation and drive growth.
As Microsoft’s Global SI Partner we combine global scale with local expertise in AI, cloud, data analytics, cybersecurity, and ERP to design solutions that prioritize people and drive meaningful impact.
We champion diversity, inclusion, and sustainability, ensuring our work benefits society and business.