Summary
✨ AI‑Generated
A senior Azure security engineering opportunity focused on protecting business-critical cloud platforms. You will own identity and access security, implement policies that prevent insecure deployments, and work within dedicated engineering teams responsible for designing, building, and operating client environments over the long term.
Highlights
Own the security posture of critical Azure platforms, with security embedded directly into engineering teams. The role offers substantial technical ownership and long-term responsibility for client environments.
Description
Azure Security Engineer – Entra ID | Defender | Azure Policy | Amsterdam / Rotterdam [€120K]
[Business Critical IT / Managed Services]
Security here is not a review at the end.
It is the engineer inside the team writing the Azure Policy that makes the insecure thing impossible to deploy.
My client runs the infrastructure behind systems that large organisations cannot afford to lose, a good part of it in regulated sectors.
Each client environment belongs to one dedicated team that designs it, builds it and then runs it for years, with the technical mandate sitting inside the team.
Security is not a separate department reviewing other people’s work here, it lives inside the team that owns the platform.
You join one of those teams as the engineer who owns that side of it.
What you’ll do
You own the security posture of an Azure platform that has to stay up and stay clean.
Identity is the biggest piece, so Entra ID with Conditional Access, Privileged Identity Management, managed identities and workload identity federation instead of secrets sitting in config.
Around that is the network: hub and spoke segmentation, Azure Firewall, NSGs, Private Link and private endpoints, WAF at the edge, and egress control that actually holds.
Defender for Cloud gives you the posture picture across subscriptions, Microsoft Sentinel gives you detection, and you write your own KQL analytics rules rather than living off the defaults.
Guardrails go in as code, so Azure Policy initiatives with deny and deployIfNotExists on top of the landing zone, deployed through Terraform or Bicep.
Add Key Vault, certificate and secret lifecycle, AKS hardening, and Microsoft Cloud Security Benchmark and CIS baselines as the yardstick.
You also do ordinary infrastructure work, because a security engineer who cannot build is not much use in a team like this.
Your profile
6+ years in infrastructure or cloud engineering, with security as your main focus in recent yearsEntra ID in depth: Conditional Access, Privileged Identity Management, managed identities, workload identity federationDefender for Cloud and Microsoft Sentinel, including writing your own KQL detection rulesAzure network security: hub and spoke design, Azure Firewall, NSGs, Private Link, WAF, egress controlGuardrails as code: Azure Policy initiatives, Terraform or Bicep, plus PowerShell or PythonKey Vault, certificate and secret management, and AKS hardeningFluent English, Dutch is a plus
What’s in it for you
Up to €120K gross per year on target, plus a car.
A permanent contract from the start.
Hybrid, so roughly half your week from home and the rest from the office in Amsterdam or Rotterdam or at the client site.
Budget for security certification, training and conferences, and the time to actually use it.
Interested?
Contact me at sander@doghouse-recruitment.nl