Key Responsibilities
- Design, implement and maintain Azure security governance frameworks using Azure Policy and Management Groups
- Enhance and optimise Microsoft Defender for Cloud across Azure workloads, Kubernetes environments, applications, and virtual machines
- Deploy, configure and support Microsoft Defender for Endpoint, Defender for Identity and Defender for Cloud Apps
- Configure and enhance Microsoft Sentinel, including log ingestion, monitoring and threat detection use cases
- Develop and maintain security automation and SOAR playbooks using Azure Logic Apps
- Perform vulnerability management activities and drive remediation of security risks
- Implement security controls and validation within Azure DevOps and CI/CD pipelines
- Carry out advanced threat hunting and investigation using KQL
- Work closely with infrastructure, platform and engineering teams to improve cloud security posture and resilience
Required Skills & Experience
- Strong experience in Azure Security Engineering environments
- Excellent knowledge of Microsoft Defender technologies including:
- Defender for Cloud
- Defender for Endpoint
- Defender for Identity
- Defender for Cloud Apps
- Strong Microsoft Sentinel experience
- Expertise with Microsoft Entra ID (Azure AD), Azure Policy and Intune
- Advanced Kusto Query Language (KQL) skills
- Experience with PowerShell, Terraform and/or Bicep
- Experience securing Azure DevOps and CI/CD pipelines
- Knowledge of security monitoring, threat detection, incident response and cloud governance
Desirable
- AZ-500 Azure Security Engineer Associate
- SC-200 Security Operations Analyst
- SC-100 Cybersecurity Architect Expert
- CISSP, CCSP or similar security certifications
What's on Offer?
- £700 - £750 per day Outside IR35
- Flexible working
- High-profile cloud security programme
- Enterprise-scale Azure environment
- Opportunity to influence security strategy and engineering standards
- Modern Microsoft security estate including Defender XDR, Sentinel and Azure-native services
Seniority Level:
Not Specified