Overview
In this role you will act as a technical authority for cloud, identity, and endpoint security within a retail organisation undergoing a digital transformation. You will design and operate security controls across Azure, on-prem, and SaaS, collaborating with networks, infrastructure, and applications teams to embed secure-by-design principles. You will lead threat detection, incident response, and compliance activities to protect critical assets at scale. This is a hands-on, impact-driven position with a clear focus on modern security postures and cross-functional execution.
Responsibilities
- Design and implement security controls across Azure, on-prem and SaaS with CIS/NIST hardening
- Define standards for Entra ID and Active Directory, including CA, MFA, SSO, and PIM
- Own and operate the SIEM/SOAR stack (Microsoft Sentinel and Defender XDR) and develop detection rules
- Enforce secure baselines across VMware/Hyper-V, Windows Servers, and Azure IaaS
- Manage PKI/AD CS lifecycle and implement data classification and DLP using Purview
- Manage Azure Landing Zone security and secure firewall/VPN configurations in collaboration with Network Engineering
- Support audit readiness for ISO 27001, PCI DSS, Cyber Essentials Plus and track remediation progress
Key requirements
- 5–10 years in cloud or infrastructure security roles
- Deep experience with Defender for Cloud, Sentinel, and Azure security configurations
- Strong knowledge of Microsoft Entra ID, AD DS, RBAC, and hybrid identity security
- Hands-on experience with EDR (MDE), CSPM tools, and vulnerability management platforms
- Practical understanding of Zero Trust architecture and secure-by-design methodologies
- Familiarity with PCI DSS, NIST, and ISO 27001 frameworks
- Analytical mindset
- Composure under pressure during security incidents
- Excellent communication with diverse stakeholders
- Defender for Cloud
- Microsoft Sentinel
- Defender XDR
…
