Cloud Security Engineer Consultant

  • Salary: Competitive

  • Location: Hybrid (London/Home)

  • Working Pattern: Hybrid (at least 3 days in office)

  • Job Type: Permanent

  • Start date: ASAP

  • Level: SFIA 4

  • Reports to: Principal Security Design Consultant

THE VACANCY:

The Cloud Security Engineer role is designed for a hands-on security specialist with broad Microsoft Azure and Microsoft 365 experience who can implement, harden and assure cloud security controls. Candidates may have progressed through cloud engineering, infrastructure, identity and access management, security operations or consultancy roles and will be comfortable working directly in client environments.

The role supports a varied portfolio of predominantly Azure security work spanning identity and privileged access, platform governance, networking, workload protection, secrets and encryption, logging and monitoring, data protection and automation. Strong practical experience with Microsoft Entra Privileged Identity Management and wider Privileged Access Management capabilities is particularly valued, alongside experience with Microsoft Purview across information protection, data classification and data loss prevention.

This is not an exclusively identity or data-security role. The successful candidate will be expected to apply their core areas of expertise while developing and maintaining capability across the wider Azure and Microsoft 365 security landscape.

Sitting within Cyro’s Cyber Security Architecture team, the successful candidate will work closely with security architects to translate security requirements and High-Level Designs into detailed, implementable solutions. They will own Low-Level Designs, build documentation and engineering delivery, while contributing to High-Level Designs, reference architectures and reusable security patterns. The role provides a clear development path towards security architecture for candidates with the aptitude and ambition to progress in that direction.

Primary responsibilities:

Azure Security Engineering:

  • Implement, configure, harden and troubleshoot security controls across Azure and Microsoft 365 environments. 

  • Configure Microsoft Entra ID controls including Conditional Access, multi-factor authentication, role-based access control, managed identities, access reviews and identity lifecycle controls, with particular emphasis on Privileged Identity Management and the application of appropriate privileged access controls. 

  • Implement platform governance using management groups, subscriptions, landing zone controls, Azure Policy and initiatives, Defender for Cloud, secure score and regulatory compliance capabilities. 

  • Engineer network security controls including virtual networks, network security groups, Azure Firewall, web application firewall, Private Link and private endpoints, DNS security, DDoS protection and hybrid connectivity controls. 

  • Implement Key Vault, encryption, secret and certificate management, secure storage patterns and workload identity controls. 

  • Secure Azure workloads including virtual machines, containers and AKS, App Service, Functions, storage, databases and other platform services. 

  • Configure security logging and monitoring using Azure Monitor, Log Analytics and Microsoft Sentinel, and integrate relevant Defender XDR telemetry. 

  • Implement Microsoft Purview capabilities where required, including information protection, sensitivity labels, data classification, data loss prevention, retention and records controls. 

  • Investigate and resolve cloud security issues, configuration drift, policy non-compliance and implementation defects, documenting root cause and corrective action. 

Automation and DevSecOps:

  • Build and maintain secure, repeatable deployments using Bicep, Terraform, PowerShell, Azure CLI or equivalent infrastructure-as-code and automation tooling. 

  • Integrate security guardrails, policy-as-code, secrets handling and security testing into Azure DevOps or GitHub-based delivery pipelines. 

  • Develop scripts, reusable modules and operational runbooks that improve consistency, supportability and delivery efficiency. 

Design, Assurance and Documentation:

  • Gather technical requirements, contribute to HLDs and own LLDs, build guides, configuration standards, test plans, runbooks and as-built documentation, progressively taking on greater design responsibility with support from experienced security architects. 

  • Perform cloud security configuration reviews and hardening assessments against Microsoft security guidance, CIS benchmarks, the NCSC CAF, ISO 27001 and client standards. 

  • Test changes, remediate findings and provide implementation assurance and operational handover to client and managed service teams. 

client and team engagement:

  • Lead defined engineering work packages under general direction, planning activity, managing dependencies and maintaining delivery quality. 

  • Work directly with client architects, engineers, service teams and stakeholders to explain implementation choices, risks and operational impacts. 

  • Support technical discovery, estimates, proposals and client demonstrations, and contribute to reusable patterns and the development of Cyro's cloud security services. 

Essential skills and experience:   

  • Strong hands-on experience engineering and securing Microsoft Azure environments.

  • Practical capability across several Azure security domains, including identity, governance, networking, workload protection, logging and secrets management.

  • Experience with Microsoft Entra ID, including practical exposure to Privileged Identity Management, together with experience across a selection of Azure security technologies such as Azure Policy, Defender for Cloud, Key Vault, Azure Monitor and Log Analytics. 

  • Experience using infrastructure-as-code or scripting tools such as Bicep, Terraform, PowerShell or Azure CLI.

  • Ability to interpret architectural requirements and translate HLDs into accurate LLDs, build documentation, test plans and operational runbooks. 

  • Strong troubleshooting skills and experience resolving cloud configuration, access, policy and integration issues. 

  • Understanding of cloud security principles including least privilege, defence in depth, secure-by-design, segmentation, encryption and continuous monitoring. 

  • Good client-facing communication, documentation and stakeholder engagement skills. 

  • Ability to work autonomously under general direction, lead defined work packages and guide colleagues where appropriate. 

  • Eligibility for UK Security Clearance (successful appointment will be subject to being granted Security Clearance). 

  • Willingness to work across a varied portfolio of cloud security engineering activities, applying existing strengths while developing capability in other areas. 

desirable Skills and Experience:   

  • Hands-on experience with Microsoft Purview, particularly Information Protection, sensitivity labels, data classification or data loss prevention. 

  • Microsoft certifications such as AZ-500, AZ-104, SC-300, SC-400 or SC-100. 

  • Experience with Microsoft Sentinel, Defender XDR or Defender for Cloud Apps. 

  • Experience implementing security controls through Azure DevOps or GitHub CI/CD pipelines. 

  • Knowledge of the Microsoft Cloud Security Benchmark, CIS Azure benchmarks, the NCSC CAF, ISO 27001 or NIST guidance. 

  • Experience securing hybrid environments or familiarity with AWS or GCP security controls. 

  • Exposure to security design or architecture activities, or a demonstrable interest in developing towards a security architecture role. 

  • Experience working in or with Critical National Infrastructure, UK Government or similarly regulated environments. 

Levels of responsibility: SFIA Level 4

So why choose Cyro for your next opportunity?

To build, run and maintain a successful compliance programme, you need a connected approach – a team you can trust from strategy to support, and everything in between. At Cyro, this is what we do!

As part of our team, you could be working with some of the biggest names in the Critical Nation Infrastructure and Service Provider sectors including London Underground, Network Rail, Transport for London, RNLI, MOD and more. You’ll help us ensure the most important messages get through – however tough the conditions.

Here are just some of the ways we’re different:

  • You’ll go further with us. We understand the importance of career development and will give you all the support you need to realise your potential. You’ll receive formal training, e-learning and mentoring from top professionals. And we offer opportunities to transfer to other sectors – or even different technology areas.

  • You’ll make a difference. You could be working outdoors, battling the elements, or in one of our many offices helping us develop the network infrastructures of tomorrow.

  • You’ll be treated as an individual. We’re not a vast corporation, which means every individual counts. With us, you’ll be valued and supported, involved and empowered from day one.

  • You’ll be well rewarded. We offer salary progression that reflects market rates and personal performance, a flexible working environment and excellent training.

Excellent Employee Benefits:

Cyro is committed to ensuring that we offer industry leading career opportunities, salary and benefits packages. Join us and you can expect to receive:

  • 25 days holiday, including public holidays, plus the option to buy or sell five days each year

  • Company pension scheme

  • A range of family friendly policies

  • An employee-funded car leasing scheme

  • Occupational health support

  • Cyro Rewards Scheme

apply now:

Please send your CV to hr@cyro.uk

Click here to view our company information pack

Cyro is an equal opportunities employer and is committed to diversity and inclusion.

We reserve the right to close this vacancy once we have received sufficient applications.

This job description sets out the duties and responsibilities of the job at the time when it was drawn up.  Such duties and responsibilities may vary from time to time without changing the general character of the duties or the level of responsibility entailed.  Such variations are a common occurrence and cannot in themselves justify a reconsideration of the grading of the job.