Start Your Search Here

Job Search

Shakers

Portugal / Global

Cloud Engineer

Job Description

Azure Cloud Security Engineer

Join a global technology firm as an Azure Cloud Security Engineer inside its Cybersecurity Center of Excellence, securing Azure landing zones and the IaaS/PaaS services running on them.

The challenge

Cloud environments grow faster than the guardrails around them. You will make sure they do not: designing, implementing and validating the security controls that keep Azure landing zones compliant, segmented and least privilege by default, working shoulder to shoulder with cloud platform, infrastructure, networking and DevOps teams.

Responsibilities

Implement and validate security controls for Azure IaaS and PaaS resources against defined security baselines.

Support implementation and troubleshooting of Azure identity and access controls: RBAC, managed identities, least privilege permissions.

Implement and fine tune network security controls: NSGs, Azure Firewall, private endpoints, network segmentation.

Participate in security assessments and reviews of cloud architectures, identifying risks in cloud native services and proposing mitigations.

Define and promote security controls across CI/CD pipelines, embedding security into build, test and deployment.

Own cloud security posture monitoring and lead remediation of CSPM findings.

Enforce cloud governance across Azure environments, configuring and maintaining Azure Policies.

Champion cloud security best practices and mentor colleagues across cloud focused teams.

Requirements

Bachelor's degree in IT, Computer Science, Cybersecurity, Engineering or a related field, or equivalent practical experience.

1 to 3 years of hands on experience in Azure cloud engineering, cloud security or infrastructure roles, deploying, configuring and supporting Azure IaaS and PaaS.

Solid working knowledge of Azure landing zones: management groups, subscriptions, resource organization, policy implementation, access control.

Practical experience with Azure networking: VNets, subnets, NSGs, Azure Firewall, private connectivity.

Proven experience with Azure IAM: RBAC, managed identities, least privilege access.

Basic experience with Infrastructure as Code: Terraform, Bicep or ARM templates.

Fluent English, written and verbal.

Nice to have

Experience supporting or leading Azure landing zone implementations and advanced network security components.

Hands on experience with Azure Policy and familiarity with CSPM tools.

AZ-500 or AZ-104 certification, or equivalent cloud/cybersecurity certifications.

Familiarity with DevSecOps principles and security in CI/CD pipelines.

Why this project

Long term ,

full time

engagement inside a Cybersecurity CoE at a global technology firm, with real ownership over cloud security posture and visibility across platform, networking and DevOps teams. Not a ticket queue: hands on implementation plus design input on how the Azure estate is secured.

If you want your fingerprints on how a large Azure estate is secured, this is the one.

#CloudSecurity #Azure #DevSecOps #Cybersecurity #Shakers

#J-18808-Ljbffr

Candidatar-se Now

Similar Opportunities

View all jobs