LAB3 logo

Principal Consultant - Security

Hiring from
Australia
Work type
Hybrid
Posted
Is this job info correct?

510,810 remote jobs, straight from company career pages

100% free · New jobs every hour

Show job description
Posted Wednesday 7 October 2026 at 1:00 pm

LAB3 is one of the largest Azure engineering practices in the Australasia region with a focus on Cloud & DevOps, Data, IoT & AI, Modern Workplace, Security, and Network services. 

We are looking for a Principal Consultant to join our Security Practice. You will be responsible for shaping, designing, and leading the delivery of enterprise‑grade Microsoft security solutions across cloud, hybrid, and identity platforms.

The role combines deep technical expertise with strong client engagement and consulting capability. You will act as a trusted security advisor to clients, working across complex and high‑profile environments to uplift security maturity and enable secure transformation.

Role responsibilities:

  • Lead end-to-end Microsoft security engagements from strategy and architecture through to delivery and operational handover, owning technical direction, quality and outcomes across complex client programmes

  • Architect and build Microsoft Sentinel environments covering data onboarding, log source integration, analytics rule design, KQL-based threat detection and SOAR automation with the ability to conduct Sentinel assessments and produce actionable remediation roadmaps where required

  • Provide architectural leadership across Microsoft Defender XDR for Endpoint, Identity, Office 365 and Cloud Apps, and lead Defender for Cloud deployments covering CSPM, CWPP and Secure Score optimisation

  • Lead the design of hybrid and cloud identity security architectures across Active Directory and Microsoft Entra ID, including identity governance, passwordless authentication, Zero Trust alignment and least-privilege access models

  • Embed security controls into IaC and CI/CD pipelines through DevSecOps practices, define endpoint security and application control strategies including WDAC, and lead security automation and orchestration across cloud and identity platforms

  • Act as a trusted security advisor to senior client stakeholders, leading workshops, threat modelling sessions and security roadmap engagements, and producing high-quality deliverables for technical and executive audiences

  • Support pre-sales and engagement shaping, contribute to LAB3 security reference architectures and intellectual property, and mentor engineers and consultants to uplift capability across the Security Practice

Technical Skills:

Microsoft Cloud & Security Platforms

    • Senior‑level technical leadership with the expectation that hands‑on engineering involvement may be required from time to time.
    • Expert‑level knowledge of Microsoft Azure security services and cloud‑native security controls.
    • Microsoft Defender for Cloud (CSPM & CWPP) including Secure Score optimisation, regulatory compliance, and workload protection.
    • Azure Policy for governance, compliance enforcement, and security posture management.
    • Security Operations, SIEM & XDR
    • Microsoft Sentinel (SIEM/SOAR) architecture, analytics design, KQL hunting, automation, and playbooks.
    • Microsoft Defender XDR across Endpoint, Identity, Office 365, and Cloud Apps.
    • Security operations leadership across hybrid and cloud environments.
    • Identity & Access Management
    • Hybrid identity security across Active Directory and Microsoft Entra ID.
    • Microsoft Entra ID Governance, including Joiner‑Mover‑Leaver processes, access packages, entitlement management, and access reviews.
    • Microsoft Entra External ID (B2B, B2C, cross‑tenant access).
    • Workload and service identities using managed identities, service principals, and least‑privilege access models.
    • Authentication & Zero Trust
    • Passwordless and phishing‑resistant authentication (FIDO2, Windows Hello for Business, MFA).
    • Application of Zero Trust principles across identity, device, application, and data layers.
    • Data Protection & Compliance
    • Microsoft Purview for Data Loss Prevention (DLP) and Information Protection.
    • Data discovery, classification, sensitivity labelling, and policy‑based protection controls.
    • Endpoint & Application Security
    • Endpoint protection and hardening using Microsoft Defender technologies.
    • Windows Defender Application Control (WDAC) strategy and policy design.
    • DevSecOps, Automation & Delivery

    Security‑as‑code and CI/CD integration.

    • Security automation and orchestration using Microsoft tooling.
    • Delivery within Agile environments (Azure DevOps, Jira).
    • Strong architectural documentation and operational runbooks.

What’s in it for you?
  • Be part of a team that leverages modern technologies to solve real problems and provides top level of customer satisfaction 
  • Work with a Microsoft Partner of the Year award winner with multiple specialisations 
  • Be supported by experienced peers and leaders that value technical expertise and encourage innovation, with clear career pathways and ongoing learning 
  • Enjoy a supportive workplace that promotes inclusion, flexibility, diversity, and celebrates differences. 
  • Take advantage of largely working from home in our remote/hybrid workplace and enjoy the flexibility to balance your life 
  • Thrive in a community with strong values #BeTrue #TeamUp #StandOut #ThinkAhead #FearLessAchieveMore 

Similar jobs

Apply for this job