This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
The Microsoft Security Engineer will design, implement, and maintain secure solutions across an organization’s cloud and hybrid environments, with a strong focus on protecting identities, data, applications, and infrastructure. This role is responsible for identifying vulnerabilities, responding to security incidents, and proactively strengthening the organization’s security posture using industry best practices and Microsoft security technologies. The engineer collaborates closely with IT teams, developers, and stakeholders to ensure compliance with security standards, implement risk mitigation strategies, and continuously improve monitoring and threat detection capabilities.
Job Responsibility:
Implement and manage security solutions using Microsoft security tools and platforms
Monitor security alerts and respond to incidents in a timely manner
Conduct vulnerability assessments and coordinate remediation efforts
Design and enforce identity and access management (IAM) policies
Secure cloud environments, including Azure resources and hybrid infrastructure
Develop and maintain security documentation, policies, and procedures
Collaborate with cross-functional teams to integrate security into system design
Ensure compliance with regulatory and organizational security requirements
Perform risk assessments and recommend mitigation strategies
Stay current with emerging threats, technologies, and security best practices
Requirements:
Hands-on experience securing Microsoft 365 and Microsoft Azure environments
Strong understanding of Microsoft Defender security products and their configuration
Strong knowledge of Microsoft Entra ID, identity architecture, Conditional Access, IAM, and Zero Trust principles
Proven ability to analyse security alerts, correlate events, and perform basic incident response activities
Experience with SIEM platforms, incident management processes, and security automation
Knowledge of common security frameworks and standards including National Institute of Standards and Technology (NIST), International Organization for Standardization (ISO 27001), CIS Benchmarks, and Cyber Essentials
Industry certifications such as Microsoft Certified: Security Operations Analyst Associate, Microsoft Certified: Identity and Access Administrator Associate, Microsoft Certified: Azure Security Engineer Associate, or equivalent experience (at least one typically essential)
Nice to have:
Experience with Microsoft 365 Defender Suite (Defender for Endpoint, Defender for Cloud Apps, Defender for Identity, Defender for Office 365 and Microsoft Defender for Entra ID)
Experience implementing or managing Microsoft Purview (data loss prevention, information protection, insider risk)
Experience supporting SOC operations or security analyst duties
Experience with risk management processes, threat modelling (e.g., STRIDE), and secure‑by‑design assurance frameworks
Participation in pen testing or red/blue team exercises
Experience with regulatory and compliance environments (NHS DSPT, GDPR, FCA, ISO audits)
Broader cloud experience across AWS or hybrid environments
Experience integrating third‑party security tools with Microsoft cloud environments (e.g., Cloudflare, Palo Alto, Datadog, Rapid7)
Experience of creating Phishing payloads and end user training programmes