> Markdown version of [/jobs/ext/2930321-security-architect-microsoft-security-platform](https://www.wearedevelopers.com/jobs/ext/2930321-security-architect-microsoft-security-platform). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Architect - Microsoft Security Platform - **Company:** Colt Technology Services - **Location:** London, UK (Remote available) - **Experience:** Expert - **Salary:** £64,530.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Active Directory, Artificial Intelligence, Microsoft Azure, Software as a Service, Cloud Computing, Cloud Computing Security, Cyber Security, Data Governance, Information Leak Prevention, Data Security, Infrastructure as a Service (IaaS), Identity and Access Management, Microsoft Security Essentials, Microsoft Office, Platform as a Service (PAAS), Azure Active Directory, Zero Trust Network Access, Security Information and Event Management, Enterprise Data Management, Microsoft Power Automate, Large Language Models, Cyber Threat Analysis, Information Technology, Microsoft Sentinel, Security Orchestration, Automation & Response - **Published:** September 16, 2026 - **Apply:** https://www.adzuna.co.uk/jobs/details/5885291982 ## About the Role * 5+ years of experience in information security within large-scale enterprise or telecommunications environments * Deep expertise in Microsoft 365 E5 security capabilities, including: * Microsoft Defender (Endpoint, Identity, Office 365, Cloud Apps) * Microsoft Entra ID (P2), Conditional Access and identity protection * Microsoft Sentinel (SIEM integration) * Microsoft Purview Strong experience designing and implementing Microsoft Purview capabilities, including DLP, Information Protection, Insider Risk and eDiscovery Strong understanding of Zero Trust architecture principles, particularly identity-driven security models Experience deploying and operating Defender and SIEM capabilities, integrated within a wider security ecosystem Experience conducting security design reviews and translating policy into practical controls Experience performing risk assessments aligned to recognised methodologies Strong understanding of cloud security concepts across IaaS, PaaS and SaaS, particularly within Azure environments Ability to translate complex technical security concepts into clear business-aligned outcomes Good understanding of networking and enterprise platforms (Windows/Active Directory, Linux/Unix environments) Engineering/Computer Science degree or equivalent practical experience Strong team player with the ability to lead initiatives across multiple stakeholders Excellent communication and stakeholder management skills Understanding of security risks associated with AI/LLM technologies, including prompt injection, data leakage and over-permissioning risks (e.g. Microsoft Copilot) Fluent in English (technical and non-technical communication) Might haves: * Experience designing and implementing security and governance controls for AI/LLM platforms, including Microsoft Copilot integrated with Microsoft Purview * Experience consolidating endpoint and SaaS security capabilities into the Microsoft Defender ecosystem * Experience with Security Copilot and security automation * Understanding of Telecoms Security Act (TSA) requirements and implementation approaches * Experience working in regulated environments (telecommunications, financial services, critical infrastructure) ## Description This role acts as the design authority and subject matter expert for Microsoft security technologies, including Defender, Entra ID and Purview, and will play a key role in modernising Colt's security posture. The successful candidate will work closely with Security Engineering, SOC, Threat Intelligence and Risk functions, as well as wider technology teams (DIO, Network Engineering, Service Delivery), to design and implement integrated, Zero Trust-aligned security architectures across the Colt estate. The role combines: * Deep technical ownership of the Microsoft Security stack (E5) * Security design, architecture and assurance * Strategic transformation across Colt technology domains You will play a critical role in driving: * Identity-driven and endpoint-focused security architecture for user-facing environments * Data protection and compliance capabilities through Microsoft Purview * Modern SOC enablement leveraging Defender and Sentinel telemetry alongside broader tooling * The secure adoption of Microsoft Copilot and AI/LLM-driven capabilities, ensuring appropriate governance, data protection and access controls * Act as the design authority for Microsoft Security architecture, covering Defender, Entra ID and Purview capabilities * Define and maintain the target architecture for the Microsoft security platform, aligned to Colt's Zero Trust strategy * Lead the design and implementation of Microsoft Defender capabilities across endpoints, identities and user-facing services, ensuring integration with wider security tooling where required * Define appropriate integration patterns between Microsoft Defender and non-Microsoft security tooling, particularly across server and infrastructure environments * Design and deliver Microsoft Purview solutions, including Data Loss Prevention (DLP), Information Protection, Insider Risk and data governance * Define and implement identity-first security controls using Entra ID (P2), including Conditional Access, MFA and Privileged Identity Management (PIM) * Support the modernisation of Colt's SOC operating model, leveraging Defender and Sentinel for user and endpoint telemetry, alongside integration of broader infrastructure data sources * Conduct security architecture reviews and provide assurance for solutions leveraging Microsoft security technologies, including defining requirements and supporting formal sign-off or risk acceptance * Ensure consistent deployment and operationalisation of Microsoft security capabilities at scale, across a complex, hybrid estate * Ensure alignment with regulatory requirements such as TSA, DORA and ISO27001 * Drive adoption of Secure by Design principles across Microsoft-based platforms and solutions * Define and implement security and governance controls for Microsoft Copilot and AI/LLM services, ensuring enterprise data is appropriately protected * Assess and mitigate risks associated with AI/LLM usage, including prompt injection, data leakage, over-permissioned access and unintended data exposure * Ensure AI-enabled services follow Zero Trust principles, enforcing least-privilege access to enterprise data accessed by Copilot and related tools * Engage with Microsoft and other vendors to stay aligned with emerging capabilities and roadmap developments, particularly across XDR, data protection and AI * Produce high-quality architecture artefacts, standards and guidance documentation ## Related Videos - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Developer Tools for Microsoft Azure](https://www.wearedevelopers.com/videos/450-developer-tools-for-microsoft-azure) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [Develop enterprise-ready applications for Microsoft Teams with Azure resources on modern web technologies](https://www.wearedevelopers.com/videos/187-develop-enterprise-ready-applications-for-microsoft-teams-with-azure-resources-on-modern-web-technologies) - [Building Sovereign AI: Lessons from Deploying Secure RAG Systems using Confidential Computing](https://www.wearedevelopers.com/videos/100108-building-sovereign-ai-lessons-from-deploying-secure-rag-systems-using-confidential-computing) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 164: AI Agents, AI Blindspots and MCP security problems](https://www.wearedevelopers.com/magazine/578-dev-digest-164-ai-agents-ai-blindspots-and-mcp-security-problems) - [Dev Digest 196: AI Killed DevOps, LLM Political Bias & AI Security](https://www.wearedevelopers.com/magazine/659-dev-digest-196-ai-killed-devops-llm-political-bias-ai-security) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline)