Azure Security Engineer

Company: Futureheads
Apply for the Azure Security Engineer
Location: Greater London
Job Description:

Azure Security Engineer Contract | 3 Months Initial | Outside IR35 | Hybrid (London)Sector: Data, Research & Business Intelligence

We are working with a leading organisation in the data and business intelligence sector that is seeking an Azure Security Engineer to support a focused security remediation and compliance uplift programme. This is a hands‑on delivery role, suited to an engineer who enjoys actively fixing security issues rather than producing advisory‑only outputs. You will work closely with infrastructure, cloud, and engineering teams to remediate vulnerabilities, harden configurations, and measurably improve Microsoft security posture.

Role Overview

The Azure Security Engineer will play a key role in strengthening Microsoft security controls across Azure, endpoints, and data platforms. The primary focus will be on Defender for Cloud remediation, Defender suite optimisation, and Purview‑led data protection and compliance uplift. You will be embedded within delivery teams, working through actionable remediation tasks and driving tangible risk reduction week by week.

Key Responsibilities

  • Remediate vulnerabilities identified through Defender for Cloud
  • Manage and optimise Defender for Endpoint, including attack surface reduction and device hardening
  • Operate and tune External Attack Surface Management (EASM) findings
  • Improve Secure Score through direct technical remediation
  • Work with SOC teams to triage, respond to, and close security findings
  • Implement and manage Microsoft Purview (DLP, sensitivity labels, insider risk, records management)
  • Support compliance uplift against ISO 27001, SOC 2, GDPR, and NIS2
  • Maintain audit evidence, runbooks, and security documentation
  • Hands‑on remediation including patching, configuration changes, and policy deployment
  • Partner with engineering and product teams to close findings rather than escalates them
  • Improve security posture across identity, endpoints, networking, and cloud workloads
  • Implement Conditional Access, PIM, Key Vault, and encryption standards
  • Tune Microsoft Sentinel analytics, automation rules, and alert noise
  • Support incident investigation, triage, and threat hunting when required
  • Produce security metrics and reporting to demonstrate measurable improvement
  • Work closely with DevOps, Infrastructure, Desktop, and Cloud teams
  • Translate security risk into clear, actionable remediation steps
  • Build repeatable processes to reduce future remediation effort

Required Experience & Skills

  • Strong hands‑on experience with: Defender for Cloud, Defender for Endpoint, External Attack Surface Management (EASM)
  • Working knowledge of Microsoft Purview (DLP, sensitivity labels, insider risk)
  • Proven experience closing vulnerabilities and improving security posture
  • Azure identity and access security expertise (Entra ID, Conditional Access, PIM)
  • PowerShell and/or Microsoft Graph for automation or scripted remediation

Desirable

  • Experience with Microsoft Sentinel (analytics rules, workbooks, automation)
  • Knowledge of Zero Trust security principles
  • Experience working in regulated or audited environments
  • Familiarity with Microsoft Compliance Manager

Certifications

Required

  • AZ-500 – Azure Security Engineer Associate
  • SC-100 (or commitment to complete within 12 months)
  • Plus one of: MS-500, SC-400, SC-900

Desirable

  • CCSP
  • Additional Microsoft Defender or M365 security certifications

#J-18808-Ljbffr…

Posted: March 18th, 2026