> Markdown version of [/jobs/ext/65234-principal-microsoft-cloud-ai-security-architect](https://www.wearedevelopers.com/jobs/ext/65234-principal-microsoft-cloud-ai-security-architect). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Principal Microsoft Cloud & AI Security Architect - **Company:** WTW inc. - **Location:** Atlanta, GA, United States - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Amazon Web Services, Data Analysis, Microsoft Azure, Microsoft Online Services, Cloud Computing, Cloud Computing Security, Cloud Engineering, Cyber Security, Multi-Factor Authentication, Identity and Access Management, Information Systems Security Architecture Professional, Microsoft Office, Performance Tuning, Phishing, Kusto Query Language, Zero Trust Network Access, Runbook, Security Information and Event Management, Google Cloud, Microsoft Power Automate, Delivery Pipeline, Multi-Cloud, Data Lakes, Cybercrime, Microsoft Sentinel, Virtual Agents, CIS Benchmarks, Oracle Cloud Infrastructure, Security Orchestration, Automation & Response - **Published:** May 30, 2026 - **Apply:** https://www.juju.com/job/00000000g3ivl4 ## About the Role + Deep expertise in Microsoft Sentinel architecture, tuning, SIEM/UEBA, KQL, custom detections and threat hunting. + Strong hands-on experience with: + **Agentic AI for Security** + **Sentinel Data Lake** (pipelines, analytics, cost optimisation, AI enablement) + **Microsoft Sentinel MCP** for enriched context-aware analytics + **Microsoft Sentinel Graph** for automated incident correlation and graph-driven workflows 2. Cloud Security Architecture (Microsoft + Multi-Cloud) + Expertise designing security architectures across Azure, with additional exposure to AWS, GCP, OCI or hybrid environments. + Strong experience with Defender XDR, Defender for Cloud, CSPM, CWPP, and multi-cloud security controls. 3. Cloud Posture & Risk Management (Wiz) + Hands-on experience with: Wiz Cloud, Wiz Defend, Wiz Runtime Sensor, Wiz Code + Strong ability to operationalise CSPM/CWP findings into actionable remediation. 4. Identity Security & Access Management + Deep understanding of Entra ID security, Conditional Access, MFA, Identity Protection, PIM/JIT. + Ability to define identity strategies and detect/mitigate identity-led attacks. 5. Email Security & Threat Containment + Expertise with Microsoft Defender for Office 365, phishing protection, Safe Links/Attachments, automated email response, and Darktrace Email. 6. Security Automation & Engineering + Strong experience developing SOAR workflows and automation pipelines using: Sentinel Playbooks, Azure Logic Apps, Power Automate, Graph Security API, KQL-based automation + Ability to document architectures, runbooks, and processes clearly and accurately. 7. Governance, Standards & Compliance + Working knowledge of NIST CSF, ISO 27001, CIS Benchmarks, GDPR and SOC2. + Ability to embed governance in cloud and SOC engineering processes. 8. Leadership & Cross-Functional Collaboration + Experience guiding and developing engineering teams. + Strong communication, stakeholder management, and ability to influence global cyber defence functions. Qualifications The Requirements + Deep hands-on expertise in Microsoft Sentinel, including architecture, SIEM/UEBA, KQL, custom detections, automation, Sentinel Data Lake, MCP, Sentinel Graph, and Agentic AI-driven security. + Strong experience with Wiz (Wiz Defend, Runtime Sensor, Wiz Code) and solid understanding of CSPM/CWPP for cloud posture and workload protection. + Proven ability to integrate and automate security workflows using Sentinel Graph, Microsoft Graph Security API, Playbooks, Logic Apps, Power Automate, and KQL-based automation. + Advanced identity security skills across Entra ID, Conditional Access, MFA, Identity Protection, Privileged Identity Management (PIM), Just-in-Time (JIT) access, and Zero Trust identity models. + Strong background in email security, including Microsoft Defender for Office 365, Darktrace Email, anti-phishing controls, Safe Links/Safe Attachments, phishing simulations, and email threat intelligence. + Ability to produce clear, well-structured security architecture documentation, runbooks, and incident response procedures. ## Description * Architect and implement next generation Microsoft cloud security across Azure and multi cloud environments. * Drive adoption of Agentic AI for Security to enable autonomous detection, adaptive response, and continuous security posture improvement. * Enhance Microsoft Sentinel with MCP (Model Context Protocol), Sentinel Data Lake, and Sentinel Graph capabilities for advanced analytics, threat correlation, and automated workflows. * Optimise and operationalise Defender XDR, Defender for Cloud, and Wiz to enhance cloud posture, workload protection, and risk visibility. * Strengthen identity protection through Entra ID, Conditional Access, MFA, PIM/JIT, and Defender for Identity. * Lead the automation of security operations using Sentinel Playbooks, Logic Apps, Power Automate, and advanced SOAR workflows. * Drive proactive threat detection, email threat defence, and automated containment using MDO and Darktrace Email. * Partner closely with GSOC, Incident Response, Threat Hunting, TI and Cloud Engineering teams to deliver unified detection, response, and governance. * Manage, mentor and strengthen a team of Cyber Defence Security Engineers. ## Related Videos - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [Technical Documentation - How Can I Write Them Better and Why Should I Care?](https://www.wearedevelopers.com/videos/681-technical-documentation-how-can-i-write-them-better-and-why-should-i-care) - [WWC24 - Chris Wysopal, Helmut Reisinger and Johannes Steger - Fighting Digital Threats in the Age of AI](https://www.wearedevelopers.com/videos/926-wwc24-chris-wysopal-helmut-reisinger-and-johannes-steger-fighting-digital-threats-in-the-age-of-ai) - [Deep Fakes: The Lies We Can’t See](https://www.wearedevelopers.com/videos/1187-deep-fakes-the-lies-we-can-t-see) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Dev Digest 164: AI Agents, AI Blindspots and MCP security problems](https://www.wearedevelopers.com/magazine/578-dev-digest-164-ai-agents-ai-blindspots-and-mcp-security-problems) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 162: AI careers, MCP, AWS best practices & floppy sweaters](https://www.wearedevelopers.com/magazine/571-dev-digest-162-ai-careers-mcp-aws-best-practices-floppy-sweaters)