Cloud Security Engineer (DED)

  •  Reference Number: 29733
  •  Posted: 09 October 2026
  •  Form of employment: Contract
  •  Apply by: 04 December 2026

Functieomschrijving

The ideal candidate is a Cloud Security Engineer with deep Azure, Sentinel, Defender for Cloud, and KQL expertise who has specifically built data exfiltration detection capabilities and implemented cloud security controls at an enterprise scale.

What you'll do

  • Deploy Microsoft Defender for Cloud protections (Key Vault, Storage, Databases, AI, API) across several Azure tenants using Azure Policy and Policy-as-Code pipelines.
  • Centralize logging in Microsoft Sentinel by turning on audit and resource logs and connecting Azure, M365 and AWS.
  • Build and tune exfiltration detections in KQL that flag unusual data volumes, rate changes and abnormal access patterns across M365, PaaS and SaaS services.
  • Detect exfiltration from Azure IaaS workloads by:
    • enabling Defender for Servers and VNet/NSG flow logs with Traffic Analytics;
    • using Firewall logs to baseline normal outbound traffic;
    • alerting on large or unusual transfers to the internet or unknown destinations.
  • Map exfiltration paths to controls and document coverage gaps and recommendations.
  • Create triage playbooks and runbooks with clear escalation paths, then hand them over to the InfoSec/SOE team.

Required Skills
  • 5+ years in cloud security engineering, including at least 3 years of hands-on Azure work.
  • Being able to map exfiltration points to controls and document coverage gaps, such as exfiltration through legitimate native features.
  • To be able to build and test custom Sentinel exfiltration detections in KQL. These should cover unusual volumes, rate changes and abnormal patterns, including Exchange and Microsoft Graph API activity spikes.
  • Has deployed Microsoft Defender for Cloud plans at enterprise scale in more than one tenant.
  • Strong Microsoft Sentinel skills: data connectors, analytics rules, KQL, workbooks and automation rules.
  • Azure Policy / Policy-as-Code and deployment through CI/CD (Azure DevOps or GitHub).
  • Good understanding of M365 audit logs, Entra ID and Defender XDR / Cloud Apps.
  • Works within a formal change process (ServiceNow CRQ) and can document clearly.
  • AWS GuardDuty, CloudTrail and Organizations-level security setup.
  • Microsoft Purview: DLP, Insider Risk Management and audit.
  • Background in detection engineering or threat hunting focused on data exfiltration.
  • Experience after an incident or in a remediation program.
  • Certifications such as SC-200, AZ-500 or SC-100.
    • AWS Security Specialty is a plus.

header-over-companydesc

Experis to światowy lider rekrutacji specjalistów i kadry zarządzającej w kluczowych obszarach IT. Z nami znajdziesz konkurencyjne oferty zatrudnienia oraz ciekawe projekty IT skierowane zarówno do ekspertów z wieloletnim doświadczeniem, jak i osób, które dopiero zaczynają swoją przygodę w branży IT.

jefferson Wells is Norway's largest consulting & recruitment company with over 800 consultants. We offer recruitment of managers and highly qualified consultants with expertise in IT. Among our customers, you will find over 90 percent of Norway's largest listed companies. Experis is part of ManpowerGroup and has been named one of the world's most ethical companies.
Chandler, Colorado
The employment agency - Certificate No. 412