Cloud Security Engineer (Azure Security)
Summary
A hands-on cloud security engineer role securing Capricorn's Microsoft Azure estate: designing and maintaining Azure Policy governance, Microsoft Defender for Cloud workload protection, and security controls across Azure infrastructure, applications and data platforms. Based in Sydney with hybrid work (2 days from home).
A little about the role
As our Cloud Security Engineer (Azure Security), you'll be responsible for securing Capricorn's cloud platforms and workloads, with a particular focus on Microsoft Azure security architecture, governance and workload protection.
Rather than end-user security, this role focuses on protecting cloud infrastructure, applications, data platforms and Azure services through strong security engineering practices, policy management and technical controls.
You'll lead the design, implementation and ongoing improvement of Azure-native security capabilities including Azure Policy, Microsoft Defender for Cloud, security posture management, workload protection and cloud governance. Working closely with infrastructure, architecture and application teams, you'll identify security risks, implement scalable controls and strengthen Capricorn's overall cloud security maturity.
This is a hands-on engineering role suited to someone who has built and secured Azure environments at scale and can confidently translate security requirements into practical technical outcomes.
What You'll Bring
We're looking for a cloud-focused security engineer with deep experience securing Azure platforms, services and workloads.
You understand the difference between end-user security and cloud security, and have hands-on experience implementing security controls across Azure infrastructure, applications, data services and cloud-native platforms.
You'll bring strong technical capability, sound judgement and the ability to independently drive security outcomes from design through to implementation. You will need:
- Strong hands-on experience securing Microsoft Azure environments in enterprise-scale organisations.
- Demonstrated experience developing, deploying and maintaining Azure Policy frameworks, policy baselines and governance controls.
- Advanced experience using Microsoft Defender for Cloud to improve cloud security posture and manage workload protection across Azure services.
- Proven capability implementing and tuning security controls for cloud-hosted applications, infrastructure and platform services.
- Experience conducting cloud security investigations, risk assessments, remediation planning and control validation.
Demonstrated experience securing and managing:
- Defender for SQL
- Defender for Storage
- Defender for Key Vault
- Defender for API Management (APIM)
- Defender for Servers
- Defender for Containers
Candidates must be able to discuss practical implementation, configuration and operational management of these services.
Azure Governance & Security Architecture
- Experience implementing Azure security baselines, subscription governance and security standards.
- Strong understanding of cloud identity, networking, logging, monitoring and security architecture principles.
- Ability to design security solutions that balance risk reduction, scalability and operational requirements.
- Experience working within security frameworks including Essential Eight and ISO 27001.
Experience We Are Specifically Looking For
The successful candidate will have experience securing Azure workloads, platforms and cloud services.
This is not primarily an end-user security role.
Candidates whose experience is predominantly focused on the following areas without significant Azure workload security experience may not be suitable:
- Defender for Endpoint
- Defender for Cloud Apps
- Intune administration
- End-user device management
- Identity-only security roles
- MFA and Conditional Access focused positions
- General IT security support roles
Highly Regarded
- Experience with Infrastructure as Code and security automation.
- Experience integrating Defender for Cloud findings into operational workflows.
- Experience with Microsoft Sentinel in cloud security monitoring and response.
- Experience securing Azure application and data platforms in complex environments.
- Experience with Azure Landing Zones and enterprise-scale cloud governance models.
- Experience with Logic Apps, Power Platform or security orchestration technologies.
A little on life at Capricorn
Joining our community is about more than just a job, so here’s what’s in it for you:
• Work flexibility – We’re all unique, and so are the ways in which we work. We have Hybrid (2 days working from home) written into our policy.
• Development Opportunities – your success is ours too. We provide training opportunities and development to give you the tools you need to grow.
• Paid parental leave – during life’s most important times, we support parents’ leave (for both parents) and their transition back to work.
• Get social – our social calendar is full, with a range of different virtual and face-to-face events to keep us connected.
• A place you want to be – from the sweeping city views, coffee on tap and the general buzz of our team, Capricorn is a place you want to be.
• A cherry on top – we’ve got a heap of benefits that our team actually use, including a fantastic reward and recognition program, wellness program, additional leave purchase and so much more!
• Amazing Benefits – Unlock amazing benefits at Capricorn. We offer all staff free gym membership near the office, discounted private health benefits and all inclusive working from home kits to get you started!
Sound like you’d be a good fit?
If you are ready to become part of a growing community and make a real impact, get in touch today.
For further information, support with your application and details on Capricorn, please visit our website at capricorn.coop/careers