Live opening · Posted 16 hours ago
At a glance
The key details from the original listing.
Your early-applicant advantage
Live timing from JobBeeper.
About the role
Description supplied by the original job listing.
Job description:
1. Microsoft Defender for Cloud Implementation — Proven, hands-on expertise with Microsoft Defender for Cloud, including CSPM and Defender workload plans (CWPP), with demonstrated ability to design and deploy Defender capabilities at scale. 2. Azure Security Services & Configuration — Deep knowledge of Azure Policy (Audit/Deny/DeployIfNotOnce initiatives), Guest Configuration, Update Manager, Log Analytics, Key Vault, RBAC, and PIM/JIT access controls. 3. Automated Posture Management & Remediation — Experience implementing CNAPP/CSPM posture management with auto-remediation capabilities covering storage configurations, encryption, network controls, diagnostics, and resilience policies. 4. Defender Plan Coverage & Reporting — Ability to enable and manage Defender plans across multiple workload types (Servers, Storage, Key Vault, SQL, Resource Manager) with central coverage and cost reporting dashboards. 5. Vulnerability & Patch Management Integration — Experience surfacing missing OS/package patches and exploitable CVEs, prioritising exploitable vulnerabilities, and integrating with Azure Update Manager for critical patch baselines and scheduled deployments. 6. ServiceNow SecOps Integration — Demonstrated experience integrating Defender for Cloud findings with the ServiceNow SecOps module for feedback loops to infrastructure and application teams, with KPI/SLA dashboards. 7. Multi-Vendor Environment Coordination — Comfortable operating in a multi-vendor delivery environment, coordinating across internal and external stakeholders.
Mandatory Skills: CNAPP Services .
Profile description:
1. CIEM Concepts (Cloud Infrastructure Entitlement Management) — Familiarity with CIEM in Azure, including privileged access governance, service principal oversight, standing privilege detection, and role-assignment alerting. 2. Identity & Privileged Access Posture — Experience detecting standing privileged RBAC and over-permissioned service principals, supporting shifts to just-in-time (JIT) and privileged identity management (PIM) with periodic access reviews. 3. Multi-Cloud Posture Awareness — Understanding of AWS/GCP equivalent posture management solutions (given wider CSPM/CNAPP scope beyond Azure), enabling alignment with the broader multi-cloud security strategy. 4. CTEM Lifecycle Alignment — Familiarity with Continuous Threat and Exposure Management (CTEM) phases (Scope, Discover, Prioritize, Validate, Mobilize) to ensure posture outputs feed the exposure-management lifecycle. 5. Diagnostic & Logging Architecture — Experience configuring diagnostic settings to central Log Analytics for Key Vault, Storage, App Service, Logic Apps, and Event Hub with drift alerting capabilities. 6. Network & Resilience Controls — Knowledge of network security controls, public network access restrictions, Azure Firewall configurations, and VM backup policy implementations within Defender for Cloud. 7. Scanning Frequency Automation — Experience supporting increased scanning frequency toward continuous as part of the broader automation goal across the cloud estate.
Work arrangement
No
More openings worth a look
Recently tracked roles with full details and direct application links.