Roles & Responsibilities
2.1 Cloud and Tenant Architecture
-
Own the target-state architecture for the Group's Microsoft 365 and Azure estate, including the consolidated tenant design, subscription and management-group structure, and Azure landing zones.
-
Lead the architectural workstream of the tenant -tenant assessment, coexistence design, cutover sequencing, domain and namespace strategy, and post-migration hardening.
-
Define data-residency, licensing, and service-placement decisions in line with regulatory obligations and Group business requirements.
-
Produce and maintain High-Level and Low-Level Design documentation, reference architecture, and architecture decision records for every major platform change.
-
Assess new Microsoft and third-party services for risk, cost, and impact on integration before adoption.
2.2 Identity and Access Architecture
-
Design the Group identity architecture on Microsoft Entra ID, covering tenant topology, domain federation, guest and B2B collaboration, and lifecycle workflows across subsidiaries.
-
Define the Conditional Access policy framework, authentication strength requirements, phishing-resistant MFA rollout, and named-location and device-trust strategy.
-
Architect privileged access using Privileged Identity Management, role-assignable groups, administrative unit delegation per subsidiary, and access reviews.
-
Establish joiner-mover-leaver design, entitlement management, and application single sign-on standards for line-of-business applications.
2.3 Security Architecture (Zero Trust)
-
Own the Zero Trust reference architecture for the Group and drive its adoption across all subsidiaries.
-
Design the detection and response architecture across Microsoft Defender XDR and Microsoft Sentinel, including log-source onboarding strategy, data-collection tiers, retention design, and integration with the managed SOC provider.
-
Define data protection architecture using Microsoft Purview: sensitivity labelling taxonomy, data loss prevention, insider risk, retention, and eDiscovery readiness.
-
Set email, collaboration, and application security standards, including Defender for Office 365 policy design and SPF, DKIM, and DMARC enforcement across Group domains.
-
Design the security architecture interface with network and perimeter controls, ensuring identity, endpoint, and network layers form a coherent control set.
2.4 Endpoint and Modern Workplace Architecture
-
Define the endpoint management architecture on Microsoft Intune, covering enrolment models, Windows Autopilot, compliance and configuration baselines, update rings, and application delivery.
-
Design the BYOD and mobile posture using application protection policies and set the standard for endpoint hardening and encryption across the Group.
-
Establish the collaboration and productivity architecture for Exchange Online, SharePoint Online, OneDrive, and Microsoft Teams, including external sharing and governance controls.
-
Define backup, retention, and recovery architecture for cloud workloads, with recovery objectives agreed with the business.
2.5 Governance, Compliance, and Risk
-
Ensure all designs satisfy NCA ECC-1:2018 and ISO 27001:2022 requirements, and map implemented technical controls to the relevant domains and Annex A controls.
-
Maintain the architecture standards, technical baselines, and control-evidence set required for internal and external audit.
-
Contribute to the technology risk register: identify architectural risks, quantify impact, and propose treatment options with clear cost and effort estimates.
-
Provide technical input to Group IT policies, standards, and the Cybersecurity Steering Committee reporting pack.
2.6 Technical Leadership and Vendor Governance
-
Act as the technical authority in vendor and partner engagements: review statements of work, solution designs, and deliverables, and hold implementation partners to the agreed architecture.
-
Lead design reviews and technical assurance for projects delivered by the internal team or third parties.
-
Mentor the Infrastructure & Cloud team through documented standards, knowledge-transfer sessions, and structured development plans; build internal capability rather than concentrate it.
-
Support the Infrastructure & Cloud Manager in technology roadmap planning, capacity forecasting, and budget input for cloud and security platforms.