Cloud Security Engineer
Listed on 2026-09-20
-
IT/Tech
Cybersecurity, Information Security & Data Protection, Systems Engineer
Working Pattern:
Hybrid (at least 3 days in office)
Job Type: Permanent
Level: SFIA 4
Reports to:
Principal Security Design Consultant
The Cloud Security Engineer role is designed for a hands-on security specialist with broad Microsoft Azure and Microsoft 365 experience who can implement, harden and assure cloud security controls. Candidates may have progressed through cloud engineering, infrastructure, identity and access management, security operations or consultancy roles and will be comfortable working directly in client environments.
The role supports a varied portfolio of predominantly Azure security work spanning identity and privileged access, platform governance, networking, workload protection, secrets and encryption, logging and monitoring, data protection and automation. Strong practical experience with Microsoft Entra Privileged Identity Management and wider Privileged Access Management capabilities is particularly valued, alongside experience with Microsoft Purview across information protection, data classification and data loss prevention.
This is not an exclusively identity or data-security role. The successful candidate will be expected to apply their core areas of expertise while developing and maintaining capability across the wider Azure and Microsoft 365 security landscape.
Sitting within Cyro’s Cyber Security Architecture team, the successful candidate will work closely with security architects to translate security requirements and High-Level Designs into detailed, implementable solutions. They will own Low-Level Designs, build documentation and engineering delivery, while contributing to High-Level Designs, reference architectures and reusable security patterns. The role provides a clear development path towards security architecture for candidates with the aptitude and ambition to progress in that direction.
Primary responsibilities:Azure Security Engineering:
Implement, configure, harden and troubleshoot security controls across Azure and Microsoft 365 environments.
Configure Microsoft Entra including Conditional Access, multi-factor authentication, role-based access control, managed identities, access reviews and identity lifecycle controls, with particular emphasis on Privileged Identity Management and the application of appropriate privileged access controls.
Implement platform governance using management groups, subscriptions, landing zone controls, Azure Policy and initiatives, Defender for Cloud, secure score and regulatory compliance capabilities.
Engineer network security controls including virtual networks, network security groups, Azure Firewall, web application firewall, Private Link and private endpoints, DNS security, DDoS protection and hybrid connectivity controls.
Implement Key Vault, encryption, secret and certificate management, secure storage patterns and workload identity controls.
Secure Azure workloads including virtual machines, containers and AKS, App Service, Functions, storage, databases and other platform services.
Configure security logging and monitoring using Azure Monitor, Log Analytics and Microsoft Sentinel, and integrate relevant Defender XDR telemetry.
Implement Microsoft Purview capabilities where required, including information protection, sensitivity labels, data classification, data loss prevention, retention and records controls.
Investigate and resolve cloud security issues, configuration drift, policy non-compliance and implementation defects, documenting root cause and corrective action.
Automation and Dev Sec Ops :Build and maintain secure, repeatable deployments using Bicep, Terraform, Power Shell, Azure CLI or equivalent infrastructure-as-code and automation tooling.
Integrate security guardrails, policy-as-code,…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).