Find a jobRecruiters

Azure Security Engineer - CDI

Exclusive opportunity

2 to 4 weeks

Hybrid, Onsite

Azure Security Engineer - CDI

Futurwork

Azure Security Engineer - CDI

Skills

TerraformAzure PolicyAzure governanceCloud security complianceAzure DevOpsMicrosoft Defender for Cloud

11 days ago

Exclusive opportunity

Share this opportunity

Share this opportunity to other talents of your network:
✓ Offer them a visibility boost with clients.
✓ Help your contacts find their next job.

Important information


Contract type:

Permanent contract

Salary:

65000€/70000€

Location:

Paris, France

Starting date:

2 to 4 weeks

Work mode:

Hybrid, Onsite

Published on:

19 August 2026

What they need


Context

The client is the Cloud division of a large insurance group, in charge of a Managed Public Cloud Foundations product. This product delivers the first layer of compliance applied to everything deployed in the cloud across group entities, and also carries the deployment of global security assets such as SOC resources.
A major group-wide programme, funded and steered by Group Security, aims to shift Azure policy management from audit mode to deny mode, moving from detective to preventive control.
A POC is running: two to three policies have been deployed following a first version of the global process. These pilot policies have a deliberately narrow scope, so the operational process will need revision as volume grows.
The commitment made to Group Security covers roughly 45 policies, with at least half expected by the end of the year. Policies have been graded by complexity: delivery starts with the easiest remediation targets, while workshops with stakeholders define the development approach for the complex ones in parallel.
Environment: 27 tenants under management, deployment at management group level through cross-tenant managed identities, management group structure aligned with the Cloud Adoption Framework and identical across tenants, locked root management group.
Scope starts with the Group Operations entity, but everything must be designed for global group use.
The whole delivery chain operates in English.

Missions

The consultant joins the product team and takes ownership of the full policy development cycle, working alongside and then taking over from the Cloud Platform Engineer currently running the POC.

  • Pre-assessment
    Analyse the security controls issued by Group Security. Each control from the security baseline must be translated into one or several policies.
    Assess impact, identify exceptions and exemptions, and qualify risk before any development starts.

  • Policy development
    Write and maintain custom policy definitions and initiatives. All policies are custom, most of them derived from built-in policies.
    Work on JSON definitions, select the appropriate effect (audit, auditIfNotExists, deny, append, modify, deployIfNotExists) and manage dependencies between policies.

  • Infrastructure-as-code integration
    Terraform modules already exist. Understand the repository structure, respect existing conventions and anticipate side effects, in particular the fact that changing a display name triggers destroy and recreate.
    CI/CD currently runs on Azure DevOps, development happens on GitHub Enterprise, with a full migration to GitHub planned in the medium term.

  • Deployment lifecycle
    Apply the three-stage rollout: sandbox in audit mode to measure real impact, then pre-production and production with policies deployed in deny mode but left unassigned.
    Assignment is performed in waves by a separate team (Cloud Brokers) that verifies compliance before activating the effect. The consultant stays in a permanent feedback loop with that team.

  • Cross-team collaboration
    Work with DevOps, operational and security teams to align policy enforcement with group security requirements.

  • Documentation
    Document policies and modules for maintainability and knowledge sharing.

  • Nice to have, not required at start
    Contribute to improving the governance process (RACI, development cycle, grading criteria).
    Attend steering committees and explain, from the policy developer standpoint, why a given control or scope carries risk and why the development cycle should evolve.

Keywords

  • Governance

  • Security and Compliance

  • Audit / Consulting

  • Design and Maintenance in Operational Condition (MCO)

Profile wanted


  1. Proven experience as an Azure cloud engineer or architect in policy development within large enterprise environments
  2. Real command of Azure Policy: custom definitions, initiatives, assignments, exemptions
  3. Deep understanding of policy effects and their implications, including managed identity risks
  4. Strong policy lifecycle culture: audit start, measure before enforcing, avoid blocking production pipelines
  5. QA and testing mindset with zero tolerance for incidents on the security perimeter
  6. Operational autonomy with Terraform: reading, editing modules, understanding plan and apply, anticipating resource recreation
  7. Experience securing and organising a Terraform chain is a plus
  8. Knowledge of CI/CD on Azure DevOps and GitHub Actions appreciated
  9. Azure governance: management groups, subscriptions, RBAC, landing zones, Cloud Adoption Framework, multi-tenant context
  10. Familiarity with compliance frameworks such as CIS and NIST, security baselines
  11. Experience with Microsoft Defender for Cloud and its integration with Azure Policy
  12. Understanding of GitOps practices and policy-as-code
  13. Fluent professional English, written and spoken
  14. Ability to hold architect-level discussions in steering committees and with security teams, defending technical trade-offs and documenting reasoning

Other offers great for you!

These companies are also looking for great profiles

Audensiel

Azure Cloud Operations Engineer (F/H) - CDI

Permanent contract

In 2 to 4 weeks

Strasbourg, France

Hybrid

Skills

Cloud ArchitectTerraformCI/CDMicrosoft Azure

5 days ago

Exclusive opportunity

Soors

Azure Security Engineer H/F

Freelance

In 2 to 4 weeks

Paris, France

Hybrid

Skills

TerraformAzure PolicyAzure DevOpsJSON

5 days ago

Exclusive opportunity

Visian

Ingénieur Sécurité Applicative IA

Freelance

In 2 to 4 weeks

Paris, France

Hybrid

Top Recruiter

Skills

LLMs / Large language modelsPythonApplication SecuritySAST/SCACI/CDDocker/Kubernetes

4 days ago

Exclusive opportunity

Professional network built for talents

© 2026. All Rights Reserved.

Freelancers

Create a profile

Join a collective

Solutions and tools