OmDev Logo
GetYourJob
0
Publié il y a 37 jours

Azure Security Engineer - CDI - Permanent

Entreprise
Localisation
Paris, France
Hybride
Type de contrat
CDI
Niveau
Rémunération
65 000 - 70 000€• Salaire annuel

Salaire du marché

Médiane du marché
55k€
Au-dessus du marché
53k€fourchette habituelle62k€
Cette offre : 68k€

Basé sur 19 offres pour ce poste (tous niveaux, Paris, 3 dernières semaines). Fourchette habituelle 53k€–62k€, médiane 55k€. Cette offre (68k€) est au-dessus de la fourchette.

0vues
0clics

Description du poste

Salary: 65000€/70000€

Context

The client is the Cloud division of a large insurance group, in charge of a Managed Public Cloud Foundations product. This product delivers the first layer of compliance applied to everything deployed in the cloud across group entities, and also carries the deployment of global security assets such as SOC resources.
A major group-wide programme, funded and steered by Group Security, aims to shift Azure policy management from audit mode to deny mode, moving from detective to preventive control.
A POC is running: two to three policies have been deployed following a first version of the global process. These pilot policies have a deliberately narrow scope, so the operational process will need revision as volume grows.
The commitment made to Group Security covers roughly 45 policies, with at least half expected by the end of the year. Policies have been graded by complexity: delivery starts with the easiest remediation targets, while workshops with stakeholders define the development approach for the complex ones in parallel.
Environment: 27 tenants under management, deployment at management group level through cross-tenant managed identities, management group structure aligned with the Cloud Adoption Framework and identical across tenants, locked root management group.
Scope starts with the Group Operations entity, but everything must be designed for global group use.
The whole delivery chain operates in English.

Missions

The consultant joins the product team and takes ownership of the full policy development cycle, working alongside and then taking over from the Cloud Platform Engineer currently running the POC.

  • Pre-assessment
    Analyse the security controls issued by Group Security. Each control from the security baseline must be translated into one or several policies.
    Assess impact, identify exceptions and exemptions, and qualify risk before any development starts.

  • Policy development
    Write and maintain custom policy definitions and initiatives. All policies are custom, most of them derived from built-in policies.
    Work on JSON definitions, select the appropriate effect (audit, auditIfNotExists, deny, append, modify, deployIfNotExists) and manage dependencies between policies.

  • Infrastructure-as-code integration
    Terraform modules already exist. Understand the repository structure, respect existing conventions and anticipate side effects, in particular the fact that changing a display name triggers destroy and recreate.
    CI/CD currently runs on Azure DevOps, development happens on GitHub Enterprise, with a full migration to GitHub planned in the medium term.

  • Deployment lifecycle
    Apply the three-stage rollout: sandbox in audit mode to measure real impact, then pre-production and production with policies deployed in deny mode but left unassigned.
    Assignment is performed in waves by a separate team (Cloud Brokers) that verifies compliance before activating the effect. The consultant stays in a permanent feedback loop with that team.

  • Cross-team collaboration
    Work with DevOps, operational and security teams to align policy enforcement with group security requirements.

  • Documentation
    Document policies and modules for maintainability and knowledge sharing.

  • Nice to have, not required at start
    Contribute to improving the governance process (RACI, development cycle, grading criteria).
    Attend steering committees and explain, from the policy developer standpoint, why a given control or scope carries risk and why the development cycle should evolve.

Keywords

  • Governance

  • Security and Compliance

  • Audit / Consulting

  • Design and Maintenance in Operational Condition (MCO)

Exigences du poste

Stack technique :

TerraformAzure PolicyAzure governanceCloud security complianceAzure DevOpsMicrosoft Defender for Cloud

Plan d'action

Un plan personnalisé pour postuler intelligemment à cette offre.

Publié par

Recruteur
Recruteur

Intéressé par cette offre ?

Cliquez sur "Postuler" pour accéder à l'offre.