TRCD-26-04339
Director / Principal Security Architect (Microsoft E5 Security & Purview)
Director-level, hands-on Security Architect to own end-to-end target security architecture and delivery governance for a large Microsoft E5 Security and Purview transformation. The role spans Microsoft Entra ID, Microsoft Defender suite (MDE/MDO/MDCA/MDI), Microsoft 365 Defender XDR, and Microsoft Purview (DLP, Insider Risk, eDiscovery, Information Protection, Compliance Manager). Candidate must be able to personally configure and troubleshoot key controls (Conditional Access, Identity Protection, ASR, DLP, sensitivity labels), lead wave-based rollouts and hypercare, define RBAC and XDR correlation standards, and drive legacy tool decommissioning. Requires 15+ years cybersecurity experience with strong stakeholder management up to CISO/board level and proven at-scale enterprise delivery.
Position summary
- Location
- India
- Workplace
- On-site
- Employment
- Contract
- Experience
- Minimum 15 years and Maximum 20 years
Role overview
Why This Role Matters.
Director-level, hands-on Security Architect to own end-to-end target security architecture and delivery governance for a large Microsoft E5 Security and Purview transformation. The role spans Microsoft Entra ID, Microsoft Defender suite (MDE/MDO/MDCA/MDI), Microsoft 365 Defender XDR, and Microsoft Purview (DLP, Insider Risk, eDiscovery, Information Protection, Compliance Manager). Candidate must be able to personally configure and troubleshoot key controls (Conditional Access, Identity Protection, ASR, DLP, sensitivity labels), lead wave-based rollouts and hypercare, define RBAC and XDR correlation standards, and drive legacy tool decommissioning. Requires 15+ years cybersecurity experience with strong stakeholder management up to CISO/board level and proven at-scale enterprise delivery.
Your Impact
Deliver Enterprise Value
Help organisations solve complex business problems through modern technology, consulting expertise and measurable outcomes.
Collaboration
Work Across Teams
Collaborate with consultants, architects, engineers and client stakeholders throughout the project lifecycle.
Growth
Learn Continuously
Gain exposure to enterprise technologies, certifications, mentoring and real-world project experience.
Career Path
Grow With Ubique
Build a long-term consulting career with opportunities to take on greater responsibility and leadership over time.
Responsibilities
What You'll Be Doing.
Every role at Ubique contributes directly to solving meaningful business challenges for our clients.
Personally configure, test, and troubleshoot Conditional Access, Identity Protection, ASR rules, DLP policies, and sensitivity labels when required — particularly during initial deployment, escalations, or complex wave cutovers where deep technical credibility is needed.
Define enterprise-wide architectural standards for RBAC, cross-domain XDR correlation, and legacy tool decommissioning (CrowdStrike, Checkpoint EDR, Symantec DLP, Sophos).
Design the enterprise sensitivity label taxonomy, data governance model, and DLP control framework aligned to regulatory and business requirements.
Act as technical escalation point for Critical/High severity issues during stabilization and hypercare — diagnosing and resolving configuration issues directly alongside the delivery team, not just directing from above. 2. Program & Delivery Oversight
Lead architecture governance across all engagement phases and Knowledge Transfer.
Define wave exit criteria, oversee validation/testing activities, and sign off on architectural compliance before wave progression.
Step into delivery workstreams directly during resource gaps, tight deadlines, or high-complexity configuration work to keep wave timelines on track. 3. Leadership-Level Client & Stakeholder Management
Act as the primary architectural point of contact for client CISO, IT leadership, and Business Unit stakeholders — building trusted-advisor relationships at the most senior levels.
Present architecture decisions, risk trade-offs, and roadmap progress confidently in board-level and steering committee forums, translating technical complexity into business risk language.
Facilitate workshops with Business Units and Compliance teams to validate data classification, policy exceptions, and adoption impacts.
Manage difficult stakeholder conversations (scope, risk acceptance, delays) with composure and commercial judgment, protecting both client outcomes and PwC delivery integrity. 4. Team Leadership & Capability Building
Technology stack
Tools & Technologies.
The platforms and technologies you'll use to build modern, enterprise-grade solutions.
Microsoft E5 Security
Microsoft Entra ID
Azure AD
Conditional Access
Identity Protection
RBAC
Microsoft Defender
Microsoft Defender for Endpoint
MDE
Microsoft Defender for Office 365
MDO
Microsoft Defender for Cloud Apps
MDCA
MCAS
Microsoft Defender for Identity
MDI
Microsoft 365 Defender
XDR
Microsoft Purview
DLP
Requirements
Skills & Experience.
We value curiosity, collaboration and continuous learning. If you don't meet every requirement but believe you can make an impact, we'd still love to hear from you.
Essential
Required Qualifications
Microsoft Entra ID architecture and hands-on configuration (Conditional Access, Identity Protection, RBAC)
Microsoft Defender for Endpoint (MDE) architecture and onboarding
Microsoft Defender for Office 365 (MDO) architecture and configuration
Microsoft Defender for Cloud Apps (MDCA/MCAS) architecture and configuration
Microsoft Defender for Identity (MDI) architecture and configuration
Microsoft 365 Defender XDR architecture and cross-domain correlation
Microsoft Purview Information Protection (sensitivity labels) design and rollout
Microsoft Purview DLP policy design and rollout
Microsoft Purview Insider Risk Management fundamentals and tuning concepts
Microsoft Purview eDiscovery fundamentals
Microsoft Purview Compliance Manager fundamentals
Attack Surface Reduction (ASR) rules configuration and troubleshooting
Enterprise security architecture leadership (target architecture, standards, governance)
Wave-based/phased rollout governance, validation/testing, stage-gates, sign-off
Hypercare/stabilization escalation handling (hands-on troubleshooting)
Legacy tool migration/consolidation planning (e.g., CrowdStrike, Checkpoint EDR, Symantec DLP, Sophos)
Large-scale enterprise implementation experience (10,000+ endpoints/servers, multi-region)
Executive stakeholder management (CISO/CIO/board-level) and risk trade-off communication
Preferred
Nice to Have
Microsoft certifications: SC-100, SC-200, SC-300, SC-400
CISSP
CISM
TOGAF
Experience in manufacturing/logistics/industrial/critical infrastructure environments (OT/IT convergence)
Proposal/SOW development
Change control / formal change management support
Adaptive Protection (risk-based tuning) in Purview (as referenced)
What you'll gain
More Than Just A Job.
We're committed to helping every team member grow professionally, personally and technically while working on meaningful projects.
Global Exposure
Collaborate with international clients and multicultural teams on enterprise programmes.
Continuous Learning
Expand your expertise through mentoring, certifications and hands-on project experience.
Career Growth
Take ownership, develop leadership skills and grow your consulting career over time.
Flexible Working
Hybrid and remote collaboration designed around trust and delivering exceptional outcomes.
People First
Join a supportive culture where collaboration, respect and long-term relationships come first.
Enterprise Projects
Work on meaningful technology initiatives for leading organisations across industries.
Apply
Apply for Director / Principal Security Architect (Microsoft E5 Security & Purview)
One page, about two minutes. We only ask for what we actually need to have a first conversation.