Cloud Architecture Security Expert
Summary
Contract role via Ework Group for an insurance-sector client: designs, secures and maintains Microsoft Azure and hybrid cloud environments, defines architecture patterns, and governs identity and cloud security (Entra ID, RBAC, Defender, Sentinel). Hybrid in Warsaw (1 day/week on-site); engagement currently planned through end of 2026.
Dla naszego klienta poszukujemy osoby na stanowisko 🔹 Cloud Architecture Security Expert 🔹
Lokalizacja : Warszawa - świadczenie usług w modelu hybrydowym (1 dzień w tygodniu w biurze w Warszawie, 4 dni zdalnie)
Branża : ubezpieczenia
*na ten moment nie jest planowane przedłużenie zamówienia specjalisty po 31.12.2026
- Praktyczne doświadczenie w projektowaniu, wdrażaniu i utrzymaniu środowisk Microsoft Azure oraz hybrydowych
- Umiejętność definiowania wzorców architektonicznych dla usług chmurowych
- Znajomość zasad projektowania wysokiej dostępności, skalowalności, wydajności i odporności usług cloud
- Doświadczenie w tworzeniu i utrzymaniu dokumentacji architektonicznej oraz standardów technicznych
- Rozumienie kluczowych usług Azure: subskrypcje, management groups, sieci, storage, compute, Azure Monitor, Log Analytics, Key Vault, Azure Policy i Azure Resource Manager
- Praktyczne doświadczenie w projektowaniu i wdrażaniu zabezpieczeń dla Azure oraz Microsoft 365
- Znajomość IAM w środowiskach Microsoft: Microsoft Entra ID, RBAC, MFA, Conditional Access, PIM oraz zasada najmniejszych uprawnień
- Doświadczenie w przeglądach konfiguracji, architektury i bezpieczeństwa środowisk chmurowych
Mile widziane:
- Doświadczenie w Infrastructure as Code: Terraform, Bicep lub ARM Templates
- Znajomość Azure DevOps, GitHub Actions lub innych narzędzi CI/CD
- Doświadczenie z Microsoft Defender for Cloud, Defender XDR, Sentinel oraz CSPM/CNAPP
- Znajomość CASB, SSE/SASE, Azure Landing Zones i enterprise-scale governance
- Doświadczenie w środowiskach wielochmurowych: AWS, GCP
- Znajomość kontenerów, Kubernetes/AKS oraz bezpieczeństwa workloadów kontenerowych
- Praktyczna znajomość ISO 27001, NIS2, DORA, RODO lub wymagań sektora regulowanego
- Doświadczenie w budowaniu standardów Cloud Governance: tagowanie, budżety, limity, zarządzanie subskrypcjami i kosztami
- Certyfikaty: AZ-500, SC-100, SC-300, AZ-104, CCSP, CISSP, CISM lub równoważne
What they ask for
Required
- Practical experience designing, implementing and maintaining Microsoft Azure and hybrid environments
- Ability to define architectural patterns for cloud services
- Knowledge of high availability, scalability, performance and resilience design principles for cloud services
- Experience creating and maintaining architectural documentation and technical standards
- Understanding of key Azure services: subscriptions, management groups, networking, storage, compute, Azure Monitor, Log Analytics, Key Vault, Azure Policy, Azure Resource Manager
- Practical experience designing and implementing security for Azure and Microsoft 365
- Knowledge of IAM in Microsoft environments: Microsoft Entra ID, RBAC, MFA, Conditional Access, PIM and least privilege
- Experience in configuration, architecture and security reviews of cloud environments
Preferred
- Infrastructure as Code experience: Terraform, Bicep or ARM Templates
- Knowledge of Azure DevOps, GitHub Actions or other CI/CD tools
- Experience with Microsoft Defender for Cloud, Defender XDR, Sentinel and CSPM/CNAPP
- Knowledge of CASB, SSE/SASE, Azure Landing Zones and enterprise-scale governance
- Experience in multi-cloud environments: AWS, GCP
- Knowledge of containers, Kubernetes/AKS and container workload security
- Practical knowledge of ISO 27001, NIS2, DORA, GDPR (RODO) or regulated sector requirements
- Experience building Cloud Governance standards: tagging, budgets, limits, subscription and cost management
- Certifications: AZ-500, SC-100, SC-300, AZ-104, CCSP, CISSP, CISM or equivalent