Pracuj.pl Praca zdalna Senior

Cloud Security - Azure Key Vault Consultant

Cyclad

⚲ Warszawa

140–160 zł netto (+ VAT) / godz.

Wymagania

  • Microsoft Azure
  • Azure Key Vault
  • Azure Managed HSM
  • Microsoft Entra ID
  • Terraform
  • Bicep
  • Microsoft Defender

Opis stanowiska

Nasze wymagania:
At least 3 years of hands-on experience delivering Microsoft Azure projects.
Strong practical experience with Azure Key Vault, Azure Managed HSM, and Microsoft Entra ID.
Proven expertise in Cloud Security and Identity & Access Management (IAM).
Solid knowledge of RBAC, Conditional Access, MFA, and Privileged Identity Management (PIM).
Experience designing and implementing solutions based on Zero Trust principles.
Hands-on experience with Microsoft Sentinel, Azure Monitor, and Log Analytics.
Experience with Infrastructure as Code (IaC) tools such as Terraform, Bicep, or equivalent.
Ability to create high-quality technical documentation and deliver technical workshops or knowledge transfer sessions.

Mile widziane:
Microsoft certifications such as AZ-500, SC-300, or SC-100.
Experience with projects involving data protection, cryptography, or Hardware Security Modules (HSM).
Knowledge of Microsoft Defender for Cloud.

O projekcie:
In Cyclad we work with top international IT companies in order to boost their potential in delivering outstanding, cutting edge technologies that shape the world of the future. Currently, we are looking for an experienced
Cloud Security - Azure Key Vault Consultant to design and implement secure cloud solutions for protecting sensitive assets, including software licenses, activation keys, and confidential data within the Microsoft Azure ecosystem.
In this role, you will be responsible for delivering enterprise-grade security solutions based on Microsoft's security best practices, Zero Trust principles, and Identity & Access Management (IAM).
Location: 100% remote
Type of employment: B2B contract
Remuneration: 140 - 160 PLN net + VAT per hour on B2B
Project languages: Polish and English

Zakres obowiązków:
Design and implement a secure solution for storing software licenses, activation keys, and confidential data in Microsoft Azure.
Configure and manage Azure Key Vault and Azure Managed HSM.
Implement security controls aligned with the Zero Trust architecture.
Integrate security services with Microsoft Entra ID, Multi-Factor Authentication (MFA), Conditional Access, and Privileged Identity Management (PIM).
Configure Role-Based Access Control (RBAC) and Just-in-Time (JIT) access models.
Implement monitoring, auditing, and security event integration with Microsoft Sentinel.
Design protection mechanisms against unauthorized access, bulk key extraction, and system compromise.
Prepare technical documentation and conduct knowledge transfer sessions for the client's technical team.

Oferujemy:
Private medical care with dental care (covering 70% of costs). Family package option possible
Multisport card (also for an accompanying person)
Life insurance
Work with talented engineers on large-scale, technically challenging projects

🔍 Dekoder Ogłoszenia

🔴
delivering enterprise-grade security solutions
Oczekuje się, że kandydat będzie w stanie samodzielnie tworzyć i wdrażać złożone rozwiązania bezpieczeństwa na poziomie korporacyjnym, co może wymagać doświadczenia w pracy z dużymi, skomplikowanymi infrastrukturami.
🔴
design and implement secure cloud solutions for protecting sensitive assets
To może oznaczać nie tylko konfigurację istniejących narzędzi, ale również aktywne projektowanie od podstaw nowych, bezpiecznych architektur, co wymaga głębokiego zrozumienia ryzyka i najlepszych praktyk.
🔴
deliver technical workshops or knowledge transfer sessions
Poza technicznym wykonaniem, od kandydata oczekuje się umiejętności dzielenia się wiedzą i szkolenia innych, co może być czasochłonne i wymagać umiejętności komunikacyjnych.
🟡
At least 3 years of hands-on experience delivering Microsoft Azure projects
Chociaż podany jest minimalny staż, 'hands-on experience' sugeruje, że oczekiwane jest praktyczne, samodzielne działanie, a nie tylko nadzór.
🟡
Proven expertise in Cloud Security and Identity & Access Management (IAM)
To standardowe wymaganie, ale 'proven expertise' sugeruje, że kandydat powinien być w stanie udowodnić swoje umiejętności, np. poprzez portfolio lub referencje.