Cloud Security Engineer
Jobtailor
DublinFull-timeMid LevelOn-site
Job Description
Job Description
\n Responsibilities\n
- \n
- Support DOCOsoft’s cloud security operations and enhance the security posture of Azure-hosted environments. \n
- Administer and optimize Microsoft Defender (Cloud, Identity, Endpoint) and Azure-native security tools. \n
- Manage identity and access using Conditional Access, Entra ID Governance, and PIM. \n
- Maintain hardening standards across Azure resources (Key Vault, Storage, App Services, VMs, networking). \n
- Improve Azure Secure Score in line with internal policies and ISO 27001. \n
- Support secure design and review of Azure PaaS/IaaS workloads. \n
- Advise on network security, API protection, encryption, segmentation, and Zero Trust. \n
- Conduct threat modelling to embed security-by-design. \n
- Integrate security into CI/CD pipelines and GitHub workflows. \n
- Assess Terraform/Bicep IaC and enforce policy-as-code (Azure Policy, GitHub Advanced Security). \n
- Implement automated guardrails to reduce misconfigurations and strengthen compliance. \n
- Identify and remediate cloud vulnerabilities with engineering. \n
- Support internal/external audits and maintain documentation and compliance evidence. \n
- Enhance monitoring with Azure Monitor, Log Analytics, and Sentinel. \n
- Develop KQL queries, dashboards, and detection rules; investigate alerts, manage incidents, and maintain cloud-specific incident response playbooks. \n
- \n
- Bachelor’s degree in Computer Science engineering, or related field. \n
- 4+ years in MS Azure cloud engineering with at least 2 years in MS Azure security engineering roles \n
- Strong hands‑on experience with Azure security tools (Defender for Cloud, Sentinel, Entra ID, Key Vault, Azure Firewall, WAF, NSGs). \n
- Proficiency in Kusto Query Language (KQL) for Log analysis, threat hunting, and developing security detections in Sentinel and Log Analytics. \n
- Understanding of Azure networking, identity, encryption, and cloud governance. \n
- Experience with IaC security for Bicep (Terraform acceptable) and DevSecOps practices. \n
- Desirable Certifications: AZ‑500, SC‑200, SC‑100 \n
- Knowledge of OWASP Top 10, secure coding, and secure API practices. \n
- Strong documentation, analytical, and communication skills. \n
- Familiarity with ISO 27001, ISO 22301 SOC 2, GDPR, and cloud security best practices. \n
Posted 2 weeks ago