Job description
DevSecOps Engineer (Entra ID / Terraform / Azure DevOps)
Location: Remote within the EU
Eligibility: EU nationality required
Project Overview
We are looking for a DevSecOps Engineer to support the secure management and automation of Microsoft Entra ID Conditional Access policies across multiple tenants.
The consultant will collaborate with internal teams to analyse existing policies, automate security configurations using Infrastructure as Code, and support the transition of identity security operations to a dedicated Cyber Security team.
Responsibilities
The successful consultant will be responsible for:
- Analysing existing Conditional Access policies across three Microsoft Entra ID tenants
- Developing Terraform modules to manage identity security policies through Infrastructure as Code
- Building and maintaining Azure DevOps CI/CD pipelines to automate secure deployments
- Supporting the transition of Conditional Access policy management to the Cyber Security team
- Maintaining and improving Conditional Access policies, including:
- troubleshooting existing configurations
- implementing new security policies
- improving and optimising current policies
- Supporting overall identity security governance and policy management
Mandatory Qualifications
- Bachelor’s degree in Computer Science or a related field
- In the absence of a degree, minimum 3 years of relevant professional experience may be accepted
- Advanced English (C1 level)
Mandatory Experience
- Minimum 3 years of experience in Cloud Security, including Microsoft Entra ID / Azure AD Conditional Access
- Experience working with Azure and/or AWS environments
- At least 2 years of experience with Infrastructure as Code (IaC)
- At least 2 years of experience with CI/CD pipelines and Azure DevOps Services
Preferred Skills
- Minimum 2 years of experience managing Entra ID Conditional Access policies
- Advanced knowledge of Terraform and Azure DevOps
- Experience with automation and scripting (PowerShell or Python)
- Experience with query languages and monitoring tools (KQL, Splunk, SQL)
- Understanding of identity security operations and cloud security best practices