Cyber:
Deloitte Cyber is seeking a Microsoft 365 Security Consultant to help clients navigate complex cybersecurity challenges and secure their Microsoft 365 environments. You will deliver advisory and implementation services across the Microsoft security stack, enabling clients to transform their security posture and achieve business objectives.
Position Summary
Level: Lead Solution Advisor
Work you’ll do:
As a Microsoft 365 Senior Security Consultant, you will be at the front lines with our clients supporting them with their Cyber needs specifically helping them navigate the journey on securing their Microsoft 365 (M365) platform. This will include:
- Act as a senior advisor and technical lead for Microsoft security solutions—including Purview, Intune, Sentinel, Security Copilot, Entra ID, SCCM, and the full Defender suite (Defender for Office, Endpoints, Servers, Vulnerabilities, Cloud Apps, XDR)—guiding clients on secure implementation strategies and best practices.
- Lead transformation initiatives for clients transitioning from third-party security tools to the Microsoft security stack, ensuring seamless migration, integration, and optimization of security controls and processes.
- Deliver expert security assessments and technical health checks for Microsoft 365 environments, analyzing configurations, controls, and operational practices. Advise on remediation actions in alignment with leading industry standards (NIST, CIS, CISA, PCI DSS) and Deloitte’s Microsoft 365 Cyber Risk Framework.
- Lead and support proof-of-concept and production deployments of Microsoft cloud security technologies, ensuring robust protection and compliance.
- Advise clients through transitions to Microsoft 365 security services, overseeing solution setup, service configuration, and risk mitigation—including hands-on experience with MFA, Conditional Access, Purview Compliance Manager, Information Protection (MPIP), and Data Loss Prevention (DLP).
- Develop, configure, and deliver comprehensive cloud security and compliance reports, translating technical findings into actionable recommendations for stakeholders.
- Provide advanced troubleshooting and technical support for Microsoft security services, collaborating with Microsoft to resolve complex issues in multi-vendor, multi-protocol environments.
- Implement and advocate for industry-leading cyber risk management practices, including policy development, incident response, data protection, and access control within Microsoft 365 environments.
- Manage the full lifecycle of Microsoft 365 security engagements—from discovery and assessment through design, deployment, testing, hypercare/handover—ensuring high-quality outcomes.
- Maintain thorough documentation of technical issues, analyses, client communications, and resolutions as part of ongoing cyber risk mitigation.
- Provide internal technical training and contribute to thought leadership, including Point-of-Views (PoVs) on M365 security challenges and emerging best practices.
- Maintain a strong understanding of Microsoft licensing models (E3, E5, EMS E3, EMS E5) to ensure security solutions align with client entitlements and maximize value.
The Team
Enterprise Security teams at Deloitte embed security throughout digital transformation, securing clients’ technical backbones and enabling secure innovation. We deliver services in security architecture, cloud security orchestration, application security, and secure enablement for emerging technologies. Deloitte Cyber helps organizations confidently pursue growth and innovation by proactively managing cyber risks and transforming legacy programs into Secure.Vigilant.Resilient.TM cyber programs.
Must-Have Skills & Experience
- · 5+ years of experience in technical consulting, client problem solving, architecting, and designing solutions in a consulting role.
- · 5+ years of hands-on technical experience implementing and operating Microsoft 365 enterprise-level messaging, collaboration, and security services which includes:
- · Entra ID (Azure AD), Multi-Factor Authentication (MFA), Conditional Access, Microsoft Purview, Defender for Office 365, Exchange Online protection, Defender for Endpoints/Servers, Intune, SCCM, MEM, Microsoft Sentinel, Defender for Cloud, Defender for Identify, Defender for Vulnerability Management, Defender for XDR, Security Copilot, Teams, SharePoint Online, OneDrive for Business, Defender for Cloud Apps and Power Platform.
Good-to-Have Skills & Certifications
- Microsoft certifications (SC-900, SC-100, SC-200, SC-300, SC-400)
- Cybersecurity certifications (CCSP, CCSK, CISSP, CCNP, CCNA)
Education
- Btech/BA/BS/Mtech/MS degree preferred, ideally in Computer Science, Cyber Security, Information Security, Engineering, or Information Technology