
Security Azure Engineer
- London
- Permanent
- Full-time
- Implement and maintain secure Azure architectures in line with best practices
- Develop and support cloud security policies and technical standards
- Conduct security assessments, risk analysis, and contribute to security roadmaps
- Collaborate with teams to integrate security into CI/CD and cloud-native applications
- Configure and manage Microsoft Defender for Cloud, Defender for Endpoint, and Sentinel
- Deploy Microsoft Purview for compliance and information protection
- Manage Microsoft 365 Defender (Office 365, Identity, Endpoint)
- Support Conditional Access, Entra ID, and Identity Governance setups
- Implement Data Loss Prevention (DLP) and sensitivity labels
- Work with Azure Key Vault and manage encryption and certificate strategies
- Collaborate with our SOC and managed Sentinel provider on incident handling
- Help ensure compliance with ISO 27001, SOC 2, GDPR, and NIS2
- Support configuration and monitoring in Microsoft Compliance Manager
- Maintain security documentation and assist in audit preparation
- Configure insider risk management, audit, and eDiscovery capabilities
- Track Secure Score and recommend improvements
- Configure monitoring and alerts using Microsoft tools (Sentinel, Defender)
- Participate in incident response and post-incident reviews
- Contribute to the development of business continuity and disaster recovery plans
- Track KPIs and generate reports using Microsoft compliance and security solutions
- Work closely with DevOps, infrastructure, and application teams
- Provide technical security guidance to colleagues
- Communicate technical risks and recommendations to key stakeholders
- Bachelor's degree in Computer Science, Information Security, or similar
- 2+ years in cloud security roles, with at least 1 years in Microsoft Azure environments
- Experience in enterprise-level cloud environments, preferably in regulated industries
- Deep expertise in Azure security and Microsoft Defender suite
- Advanced skills in Microsoft Sentinel, Purview, Intune, and Defender for Endpoint
- Strong experience with Entra ID/Active Directory, Conditional Access, and PIM
- Hands-on with PowerShell and Microsoft Graph API for security automation
- Familiarity with M365 security, Zero Trust models, and Microsoft Information Protection
- Knowledge of compliance tools and frameworks (e.g. GDPR, ISO 27001, NIS2)
- Experience with Azure Firewall, NSGs, ASGs, and endpoint management
- Microsoft Certified: Azure Security Engineer Associate (AZ-500)
- Microsoft Certified: Cybersecurity Architect Expert (SC-100) or working toward it
- One or more of: MS-500, SC-400, SC-900
- CISSP, CISM, CCSP, or similar
- Excellent communication and technical documentation skills
- Strong problem-solving and analytical thinking
- Ability to work independently and as part of cross-functional teams
- Comfortable presenting findings and recommendations to non-technical stakeholders
- 24 days annual leave rising to 29 days
- Enhanced parental leave
- Medicash (Health Cash Plans)
- Wellness Days
- Flexible Fridays (Opportunity to finish early)
- Birthday day off
- Employee assistance program
- Travel loan scheme
- Charity days
- Breakfast provided
- Social Events throughout the year
- Hybrid Working