Avanade
AMBG - Cloud Security & Exposure Management Architect

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Avanade Cloud Security & Exposure Management Architect
Avanade is looking for an experienced Cloud Security & Exposure Management Architect to join our security practice. This is a client-facing role where you will be engaged in some of the most exciting, complex, and leading-edge projects. You will help clients improve their cloud security and exposure management maturity by identifying, prioritizing, and reducing exploitable risks across cloud, identity, endpoint, application, and data environments, using Microsoft Security technologies and modern threat-informed approaches.
You will also be part of the Avanade Security presales and Architecture function supporting the development of proposals, solution options, and architecture inputs for enterprise clients, with a focus on cloud security, exposure management, and Microsoft Security-led transformation. This role will include partial delivery expectations for the year.
In This Role, You Will
- Lead defined workstreams or small project teams within larger cloud security and exposure management engagements.
- Manage assigned deliverables, including exposure assessments, remediation plans, security control improvements, and reporting outputs against agreed engagement milestones.
- Contribute to solution architecture and pre-sales deal shaping for cloud security, Microsoft Defender, Sentinel, Entra, Defender for Cloud, and exposure management opportunities.
- Build trusted relationships with client security, cloud, and operations stakeholders during delivery and pre-sales engagements.
- Design, implement, and integrate cloud security, exposure management, threat detection, and security operations capabilities, including Microsoft Sentinel, Defender for Cloud, Defender XDR, and related Microsoft Security technologies.
- Understand threat modelling, attack paths, cloud misconfigurations, identity risks, vulnerabilities, and how to prioritise remediation based on exploitability and business impact.
- Understand incident response, cyber recovery, and how exposure management can reduce the likelihood and impact of security incidents.
- Understand security operations centre functions and how exposure insights can support detection engineering, prioritised remediation, and operational risk management.
- Have a good understanding of Microsoft platforms across Windows, Microsoft 365, Entra ID, Azure, and Defender, including how risks and exposures surface across these environments.
- Understand how threat actors exploit misconfigurations, identity weaknesses, vulnerable assets, exposed services, and weak security controls.
- Apply frameworks such as MITRE ATT&CK to help clients understand attack paths, prioritise exposures, and improve cyber defence maturity.
- Understand the business, privacy, security, and compliance challenges surrounding client data, critical assets, and digital services, and articulate how exposures could increase risk to those assets.
- Be aware of emerging technologies in cyber defence, cloud security, attack surface management, vulnerability management, and exposure management.
- Develop strong working relationships with account teams, delivery teams, security architects, and client stakeholders.
- Identify customer needs and business goals, then translate them into practical cloud security and exposure management solution options.
- Support the development of security transformation and operations opportunities, using standardised tools, Microsoft Security capabilities, partner technologies, and exposure-led assessment approaches.
- Contribute to proposals, client presentations, solution discussions, and technical input throughout the sales process.
- Conduct and follow through the sales process to accomplish deal closure.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
Qualifications


Get help with your application
Your very own career expert that helps elevate your application to the next level.
- Advanced Microsoft Security Certifications: SC-100, SC-200, SC-300, SC-400, SC-900.
- Industry-recognised certifications: CISSP, CCSP, CISM, SANS.
- Microsoft Security and Exposure Management: Build strong knowledge of Microsoft Security tools such as Defender for Cloud, Microsoft Sentinel, Defender XDR, Security Copilot, Entra ID, and Exposure Management capabilities to help clients identify, prioritise, and reduce security risks across cloud and hybrid environments.
- Cloud Security and Exposure Architecture: Support the design and implementation of secure cloud architectures, exposure management approaches, and remediation patterns that improve security posture and align to industry standards.
- RFP Responses: Support responses to RFPs related to cloud security, exposure management, security operations, and Microsoft Security services.
- Continuous Improvement: Stay updated on cloud security, exposure management, threat intelligence, vulnerability trends, and Microsoft Security capabilities to improve client recommendations and delivery quality.
- Knowledge of exposure management concepts: Including attack paths, vulnerabilities, misconfigurations, identity exposures, internet-facing assets, control gaps, and remediation prioritisation.
- Experience: Supporting cloud security assessments, posture reviews, exposure analysis, or remediation planning across Microsoft Azure and Microsoft Security environments.
- Ability: To translate technical exposure findings into business risk, prioritised actions, and clear client recommendations.
- Ability: To contribute to RFP responses related to cloud security, exposure management, and Managed Security Services.
- Beneficial Knowledge:
- Familiarity with the Defender suite of products, including Microsoft Defender for Endpoint, Microsoft Defender for Identity, Microsoft Defender for Office 365, and Microsoft Cloud App Security.
- Certifications such as CISSP, CCSP, or Azure Security Engineer.
- Experience with other cloud platforms (AWS, Google Cloud) and their security tools.
- Knowledge of regulatory compliance requirements (e.g., GDPR, HIPAA).
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Skills
Location