Senior Cloud Security Engineer

Doghouse Recruitment — Netherlands · Posted ~10 hours ago

Senior €120K + car

Skills

Azure Entra ID Cloud security Policy as Code Identity security Vulnerability scanning Supply chain security Security engineering CI/CD Cloud Security Vulnerability Scanning

🔓 Log in to save this job, tailor your resume & track your apply process — 7 days free, no card needed.

Log in to add to target list

Summary ✨ AI‑Generated

A senior security engineer is sought to protect a mission-critical Azure environment. You will build security guardrails as code, integrate supply-chain and vulnerability scanning into delivery pipelines, strengthen identity controls, and address emerging threats from agentic AI within a modern, highly regulated infrastructure environment.

Highlights

Take ownership of security for a mission-critical Azure platform in a senior engineering team. The role emphasizes security by design, policy as code, software supply-chain protection, vulnerability scanning, and emerging AI security challenges, with a €120K salary plus a car.

Description

Cloud Security Engineer – Azure | Entra ID | Policy as Code | Amsterdam [€120K + car] [Business Critical IT / Enterprise] The baseline is covered, nobody is getting breached today. I am looking for the engineer that is thinking about tomorrow: guardrails in code, supply chain and vulnerability scanning inside the pipelines, and an answer for agentic AI security. My client runs business critical infrastructure for large organisations, much of it in highly regulated sectors under DORA and NIS. Each client environment belongs to one dedicated team that designs it, builds it and then runs it for years, with the technical mandate inside that team rather than above it. Security touches it all. Not in a separate function checking other people’s work after the fact. As part of a team of senior engineers each with their own niche, on an environment that is close to greenfield and properly mission critical. What you’ll do Your job is the security of a live Azure platform, from the identity model down to the egress rules. Entra ID is where most of it starts, so Conditional Access, Privileged Identity Management, role based access control and identity governance, and you know why Entra is not simply a part of Azure. Guardrails go in as code through Terraform and Azure DevOps, so the insecure thing becomes hard to deploy rather than something you catch afterwards. Defender for Cloud covers posture, Sentinel covers detection and the KQL is yours to write and tune. Beyond that there is real room: supply chain security, vulnerability management, and securing how the teams build with AI agents are all areas waiting for someone with a view on them. Regulation is part of the furniture here, so you should know what DORA, NIS and ISO ask of you, but the auditing is somebody else’s job. Yours is making sure it is green when they arrive. Your profile 6+ years in Azure infrastructure or cloud engineering, with security as your focus in recent years, so you can still build the platform you are securingEntra ID at depth: Conditional Access, Privileged Identity Management, role based access control, identity governanceSentinel and Defender for Cloud, with your own KQL rather than the built in rulesTerraform and Azure DevOps pipelines, plus PowerShell, and ideally AnsibleSupply chain security and vulnerability management, or a strong interest in taking that onComfortable working inside regulated environments such as DORA, NIS and ISOFluent English, Dutch is a plus What’s in it for you Up to €120K gross per year, a lease car, and a strong package on top of that. A permanent contract from day one. Three days a week in the Amsterdam office, the rest from wherever you work best. Budget for certification, training and conferences, and the room to actually use it. Interested? Contact me at s.vanderiet@doghouse.nl