Overview
In this contract role you will shape Flagstone’s cloud security, detection, and incident response. You will own parts of the security stack and contribute hands-on across Azure hardening, monitoring, and tooling. Your work will have visible impact as you coordinate pen tests and strengthen security in delivery pipelines. You’ll collaborate with engineering squads to reduce risk and improve response across the security lifecycle. This is a opportunity to drive real security outcomes in a fast-growing fintech environment.
Responsibilities
- Own and operate alerting and monitoring during transition and maintain stability
- Tune and improve Microsoft Sentinel deployment, data connectors, and reduce alert noise
- Operate Defender XDR and Defender for Cloud, including policy management
- Extend automated security checks in CI/CD (shift-left)
- Coordinate remediation to reduce vulnerability time-to-fix with engineering squads
- Support data-loss-prevention controls
- Safeguard AI usage and secure AI workloads and data exposure
- Investigate suspicious activity surfaced by Sentinel and Defender
- Support incident response activities including containment and post-incident review
- Contribute to detection-as-code and infrastructure-as-code (Terraform or Bicep)
- Coordinate penetration test engagements and prioritise remediation with teams
Key requirements
- Hands-on SIEM experience, preferably Microsoft Sentinel
- Azure security experience across Defender for Cloud, Entra ID, and cloud posture management
- Experience IaC with Terraform or Bicep in security context
- Experience driving vulnerability remediation with engineering squads
- Familiarity with data-loss-prevention controls
- AI security familiarity and/or use of AI tools to augment security workflows
- Ability to perform threat modelling and communicate risk clearly
- Growth mindset and curiosity
- SC-200 certification
- KQL proficiency for detection and threat hunting
- Experience in a fintech or financial services environment
- growth mindset
- curiosity
- clear communication of security risk
- Microsoft Sentinel
- Defender XDR
- Defender for Cloud
…
