Quick Overview
Job Description
“I am hugely excited about my future and the future of CyberOne. I have enjoyed my time here immensely and have learnt a huge amount in a short space of time, year-for-year I've learnt more here than I have at Microsoft and PwC.” - CyberOne Consultant
About CyberOne
CyberOne is a pure-play Microsoft security partner dedicated to helping enterprises realise the full value of the Microsoft Security portfolio—across Defender XDR, Sentinel, Entra, Purview, Intune, Copilot for Security and more. We combine deep technical expertise with outcome-driven services that accelerate secure cloud adoption, modernise threat protection and simplify compliance.
Job Title: Senior Azure Security Engineer
Location: Hybrid; 1 day per month reporting in London office
Employment Type: Full-time
Purpose of Role
We are seeking an experienced Senior Azure Security Engineer to join the Cyber Security team. The role is responsible for designing, implementing, securing and supporting Microsoft security technologies across cloud, identity, endpoint, infrastructure and security monitoring platforms.
The engineer will work closely with Security Operations, Infrastructure, Cloud Engineering, Architecture, Identity and Application teams to strengthen security controls, improve monitoring capabilities, automate security processes and support the organisation's cyber resilience. The role combines Azure security engineering, Microsoft Sentinel, Microsoft Defender, cloud security architecture, automation and operational support across a hybrid enterprise environment.
Main Duties and Responsibilities
Act as a Subject Matter Expert for Microsoft Azure security, Microsoft Sentinel, Microsoft Defender XDR and associated Microsoft security technologies.
Design, implement and support enterprise security controls across Azure, Microsoft Entra ID and the Microsoft security ecosystem.
Engineer and maintain Microsoft Sentinel capabilities, including data connectors, analytics rules, KQL queries, workbooks, watchlists, automation rules and playbooks.
Design, implement and optimise Microsoft Defender capabilities, including Defender for Endpoint, Defender for Identity, Defender for Cloud, Defender for Office 365 and Defender XDR.
Develop security monitoring use cases, threat detections and hunting queries aligned to business risks, threat intelligence and MITRE ATT&CK.
Design secure cloud and hybrid architecture patterns and provide practical technical guidance to projects and engineering teams.
Engineer telemetry and logging solutions using Azure Monitor, Log Analytics, Azure Monitor Agent, Data Collection Rules, custom tables and API-based integrations.
Design and implement security automation using Logic Apps, Azure Functions, REST APIs, PowerShell and Python.
Perform technical security assessments and review cloud solutions against enterprise security standards, control requirements and secure-by-design principles.
Implement and maintain cloud security baselines, hardening standards, policy controls and configuration-management practices.
Support vulnerability and configuration-risk remediation across Azure and Microsoft security platforms.
Support cyber incident investigations and provide security expertise during critical incidents and major technology changes.
Produce and maintain High-Level Designs, Low-Level Designs, engineering standards, operating procedures, support documentation and implementation records.
Lead platform enhancements, proof-of-concepts, migrations, upgrades, troubleshooting and service-improvement activities.
Build platform health monitoring, operational dashboards and KPI/KRI reporting for the Proactive Security function.
Person Specification
Essential Experience
Proven Azure security engineering experience within a large, complex enterprise environment.
Strong hands-on experience implementing and supporting Azure security services across IaaS, PaaS and hybrid environments.
Practical experience with Microsoft Entra ID security, including Conditional Access, Privileged Identity Management, Identity Protection and hybrid identity controls.
Strong experience with Microsoft Sentinel and Microsoft Defender XDR, including Endpoint, Identity, Cloud and Office 365 security capabilities.
Experience designing and implementing cloud security architecture, platform hardening, technical security controls and security baselines.
Experience onboarding and validating infrastructure, cloud, application, identity and security telemetry.
Experience developing KQL queries, analytics rules, workbooks, automation and threat-hunting content.
Experience conducting technical risk assessments, security-control validation and vulnerability-remediation support.
Experience with REST APIs, PowerShell, Python, automation, enterprise troubleshooting and operational support.
Experience working with Security Operations, Incident Response, Cloud, Infrastructure, Identity and Architecture teams.
Technical Knowledge and Skills
Azure security and governance: Azure Policy, Defender for Cloud, Azure Monitor, Log Analytics, Azure Arc, Key Vault, managed identities, role-based access control, landing-zone security and cloud security posture management.
Cloud and network security: Virtual Networks, Network Security Groups, Azure Firewall, Private Endpoints, Private Link, secure connectivity, segmentation and hybrid-cloud security patterns.
Identity security: Microsoft Entra ID, Conditional Access, Privileged Identity Management, Identity Protection, authentication, access control, federation and identity governance.
Microsoft security platform: Microsoft Sentinel, Defender XDR, Defender for Endpoint, Defender for Identity, Defender for Office 365 and Defender for Cloud.
Security monitoring: KQL, analytics rules, hunting queries, workbooks, data connectors, Data Collection Rules, watchlists, automation rules, playbooks and ingestion optimisation.
Automation and engineering: Logic Apps, Azure Functions, REST APIs, PowerShell, Python, Azure DevOps, Git, CI/CD and Infrastructure-as-Code concepts.
Secure engineering: Security architecture, technical risk assessment, platform hardening, vulnerability remediation, control validation, secure development practices and operational readiness.
Desirable Experience
Experience securing Azure landing zones and enterprise-scale cloud platforms.
Experience with Security Orchestration, Automation and Response solutions and automated control validation.
Experience with Privileged Access Management and Zero Trust security principles.
Experience supporting security platforms in a regulated financial-services environment.
Exposure to multi-cloud or hybrid-cloud environments, including AWS or GCP.
Qualifications
Degree or equivalent professional experience in Information Technology, Cyber Security, Engineering or a related discipline.
Microsoft AZ-500 and SC-200 certifications are strongly preferred.
Microsoft SC-100, SC-300 or AZ-104 certifications are desirable.
Additional cloud-security certifications such as CISSP, CCSP or relevant GIAC qualifications are advantageous.
