Job Description & How to Apply Below
Executive Summary
The D365 Security Solution Architect is responsible for designing and governing end-to-end enterprise security architecture across Microsoft Dynamics 365 Finance & Supply Chain Management, IoT-enabled manufacturing systems, and enterprise identity platforms.
The architect ensures secure digital transformation aligned with Zero Trust principles, identity governance, and threat verification frameworks across IT and OT environments.
Ideal Candidate:
- 12+ years IT experience with 5+ years in D365 Security Architecture.
- Strong Azure Security & Active Directory expertise.
- Experience securing Manufacturing ERP landscapes.
- Exposure to OT/IT convergence ecosystems.
Responsibilities:
- Design secure D365 security models aligned with business roles.
- Implement enterprise IAM strategies with Azure AD, MFA, PIM.
- Secure IoT device communication & identity lifecycle.
- Lead threat verification, risk assessment, and SIEM integration.
- Ensure compliance with regulatory and internal audit requirements.
Key Focus Areas:
- D365 F&O Security Architecture (RBAC, SoD, Compliance)
- Identity & Access Management (IAM)
- Azure AD / Active Directory (Hybrid Identity)
- IoT Security for Smart Manufacturing
- Threat Modelling & Verification Frameworks
- Zero Trust & Conditional Access Design
Solution Scope Coverage
1️⃣ Enterprise ERP Security (D365 F&O)
- Role-based security model design (RBAC)
- Segregation of Duties (SoD) governance
- Field-level & record-level security
- Cross-legal entity access control
- Audit & compliance alignment (ISO, SOC, GDPR)
- Security design documentation & role matrix definition
2️⃣ Identity & Access Management (IAM)
- Azure AD (Entra ) architecture
- Hybrid identity (On-Prem AD + Azure AD)
- Single Sign-On (SSO) implementation
- Conditional Access & MFA
- Privileged Identity Management (PIM)
- Access lifecycle governance (Joiner-Mover-Leaver process)
- Identity governance & periodic access reviews
3️⃣ Active Directory & Enterprise Integration
- Secure AD group design for Manufacturing operations
- B2B/B2C access management
- Federation & external vendor access
- Secure API authentication between D365 and third-party systems
4️⃣ IoT & Smart Manufacturing Security
- Secure device authentication (certificate-based)
- Encryption of shop-floor data transmissions
- Secure integration between:
- MES
- WMS
- PLC/SCADA systems
- D365 ERP
- IT/OT network segmentation architecture
- Secure cloud-to-edge communication design
5️⃣ Threat Verification & Risk Management Framework
- Threat modeling (STRIDE / MITRE ATT&CK frameworks)
- Vulnerability assessment coordination
- Penetration test governance
- Security monitoring via:
- Microsoft Defender
- Azure Sentinel
- SIEM platforms
- Incident response planning
- Continuous security posture assessment
Architecture Deliverables
- Enterprise Security Architecture Blueprint
- D365 Role & SoD Matrix
- IAM Governance Framework
- IoT Security Design Document
- Threat Verification & Monitoring Framework
- Risk Register & Mitigation Plan
- Compliance Mapping Documentation
Technical Competency Requirements
- Microsoft Dynamics 365 F&O Security Architecture
- Azure Security & Identity Services
- Active Directory (Hybrid)
- IoT Security Design
- Cloud & Network Security Principles
- Zero Trust Architecture
- Manufacturing ERP Ecosystem Knowledge
Industry Domain Expertise
- Discrete & Process Manufacturing
- Supply Chain Security Controls
- IT/OT Convergence Security
Engagement Model
The architect will:
- Lead security design workshops
- Conduct security gap assessments
- Define governance standards
- Collaborate with Infrastructure, OT, and Compliance teams
- Provide security sign-off before production deployments
Certifications (Preferred)
- Microsoft Certified:
Azure Security Engineer Associate
- Microsoft Certified:
Identity & Access Administrator
- CISSP (Certified Information Systems Security Professional) / CISM (Certified Information Security Manager)
- TOGAF (The Open Group Architecture Framework) - Enterprise Architecture
Note that applications are not being accepted from your jurisdiction for this job currently via this jobsite. Candidate preferences are the decision of the Employer or Recruiting Agent, and are controlled by them alone.
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
Search for further Jobs Here:
×