Key Responsibilities
- Hands-On Azure Configuration & Management: Directly analyze, refine, and configure security controls within Microsoft Azure. This includes managing and validating Identity & Access Management (Microsoft Entra ID), Network Security Groups (NSGs), Azure Firewalls, Web Application Firewalls (WAF), Key Vaults, and secure network architectures.
- Operational Security Assurance: Perform practical configuration reviews, compliance assessments, and control effectiveness reviews. Review and challenge technical and architectural designs to ensure that cloud-native security controls are implemented in practice rather than just on paper.
- Stakeholder Liaison & Enablement: Act as the primary technical security liaison and trusted advisor between security, operational IT engineering, platform, and service teams. Provide pragmatic, risk-based security guidance to support ongoing change, release, and operational activities.
- Threat & Vulnerability Remediation: Monitor and analyze security posture using native tooling like Microsoft Defender for Cloud and Microsoft Sentinel. Identify security gaps, vulnerabilities, and misconfigurations, recommend precise technical remediation actions, and partner with platform teams to track and drive remediation through to completion.
- Continuous Security Improvement: Participate in regular technical security governance processes, including log and access reviews. Identify opportunities to automate security guardrails (e.g., via Azure Policy) and drive continual improvements in operational security practices.
- Documentation & Reporting: Translate complex technical cloud security findings, risks, and configuration baselines into clear, professional documentation and reports tailored appropriately for both technical engineers and non-technical business stakeholders.
Required Skills and Experience
- Hands-on Azure Security Infrastructure: Significant, proven experience (5+ years in information security, with substantial focus on cloud) actively configuring, securing, and maintaining Azure cloud resources. Must understand how cloud security controls are implemented and operate in practice.
- Security Technologies: Practical experience with critical security boundaries and systems, including firewalls, WAFs, modern web-based technologies, and landing zone structures.
- Native Azure Tooling Proficiency: Hands-on expertise utilizing Microsoft Defender for Cloud, Azure Policy, Microsoft Entra ID (for advanced IAM and RBAC controls), and Microsoft Sentinel or equivalent cloud SIEM systems.
- Security Design Review & Critique: Ability to review detailed technical and architectural designs, spot potential flaws, and recommend specific, practical cloud-native remediations and guardrails.
- Standards & Framework Application: Strong working knowledge of secure development principles and industry standards (e.g., ISO 27001, Cyber Essentials Plus, CIS Benchmarks, Cloud Security Alliance) and the ability to translate these high-level frameworks into hard technical controls.
- Stakeholder Management & Communication: Superb collaborative skills; able to partner effectively with engineering teams to resolve technical issues while simultaneously communicating risks and assurance status clearly to business owners and project stakeholders.
- Autonomous Execution: Self-driven, comfortable working independently to prioritize work, manage multiple operational demands, and deliver high-quality technical outcomes at pace in a complex enterprise ecosystem.
Desirable Qualifications
- Cloud-Specific Certifications: Microsoft Certified: Azure Security Engineer Associate (AZ-500) or equivalent hands-on Azure security credentials.
- Professional Security Credentials: CISSP, CISM, or equivalent certifications showing a robust foundation in security principles, or equivalent deep, practical security engineering experience.