Cloud Security Engineer
⚲ Warszawa
23 520 - 25 200 PLN netto (ANY)
Wymagania
- Cloud
- Microsoft Cloud Security Benchmark
- Microsoft Azure Security
Opis stanowiska
We are looking for an experienced Senior Cloud Security Engineer to support a strategic multi-cloud security project. The primary focus will be on securing Azure environments while providing security governance and oversight across AWS, GCP, Oracle Cloud, and IBM Cloud.
Key Responsibilities
• Operate and optimize Microsoft Defender for Cloud across Azure subscriptions
• Drive remediation of security findings, vulnerabilities, and audit observations
• Improve compliance with CIS Azure Benchmark and Microsoft Cloud Security Benchmark (MCSB)
• Implement and enforce Azure Policy, RBAC, and security guardrails
• Strengthen security across Entra ID, networking, Key Vault, storage, compute, and container platforms
• Support onboarding and governance of additional cloud platforms within Defender for Cloud CSPM
• Collaborate with platform and engineering teams to embed security into IaC and CI/CD pipelines
• Report on security posture, compliance, and remediation progress
Requirements
• 7+ years of hands-on cloud security experience
• Strong expertise in Microsoft Azure Security
• Advanced experience with Microsoft Defender for Cloud and CSPM
• Knowledge of CIS and MCSB frameworks
• Hands-on experience with Azure Policy, Entra ID, RBAC, Key Vault, and network security
• Experience managing audit findings and supporting compliance activities
• Working knowledge of AWS, GCP, OCI, or IBM Cloud
• Experience with Microsoft Sentinel, Defender XDR, and KQL
• Strong stakeholder communication skills
Key Responsibilities
• Operate and optimize Microsoft Defender for Cloud across Azure subscriptions
• Drive remediation of security findings, vulnerabilities, and audit observations
• Improve compliance with CIS Azure Benchmark and Microsoft Cloud Security Benchmark (MCSB)
• Implement and enforce Azure Policy, RBAC, and security guardrails
• Strengthen security across Entra ID, networking, Key Vault, storage, compute, and container platforms
• Support onboarding and governance of additional cloud platforms within Defender for Cloud CSPM
• Collaborate with platform and engineering teams to embed security into IaC and CI/CD pipelines
• Report on security posture, compliance, and remediation progress
Requirements
• 7+ years of hands-on cloud security experience
• Strong expertise in Microsoft Azure Security
• Advanced experience with Microsoft Defender for Cloud and CSPM
• Knowledge of CIS and MCSB frameworks
• Hands-on experience with Azure Policy, Entra ID, RBAC, Key Vault, and network security
• Experience managing audit findings and supporting compliance activities
• Working knowledge of AWS, GCP, OCI, or IBM Cloud
• Experience with Microsoft Sentinel, Defender XDR, and KQL
• Strong stakeholder communication skills
🔍 Dekoder Ogłoszenia
🔴
support a strategic multi-cloud security project
Projekt może być w fazie koncepcyjnej lub mieć niejasne cele, a "strategiczny" może oznaczać, że jest ważny dla firmy, ale niekoniecznie dobrze zdefiniowany.
🔴
Drive remediation of security findings, vulnerabilities, and audit observations
Oznacza to głównie reagowanie na istniejące problemy i ich naprawianie, a nie proaktywne budowanie bezpieczeństwa od podstaw.
🔴
Improve compliance with CIS Azure Benchmark and Microsoft Cloud Security Benchmark (MCSB)
Może oznaczać, że obecny stan zgodności jest niski i wymaga znaczących wysiłków naprawczych, a nie tylko drobnych usprawnień.
🔴
Collaborate with platform and engineering teams to embed security into IaC and CI/CD pipelines
Współpraca może być trudna, jeśli zespoły te nie mają priorytetu na bezpieczeństwo lub brakuje im odpowiednich zasobów i wiedzy.
🟡
Working knowledge of AWS, GCP, OCI, or IBM Cloud
Wymagane jest jedynie podstawowe, powierzchowne zrozumienie tych platform, a nie dogłębna wiedza, co może oznaczać, że główny nacisk jest na Azure.