Skills
11 days ago
Exclusive opportunity
Share this opportunity
Share this opportunity to other talents of your network:
✓ Offer them a visibility boost with clients.
✓ Help your contacts find their next job.
Important information
Contract type:
Permanent contract
Salary:
65000€/70000€
Location:
Paris, France
Starting date:
2 to 4 weeks
Work mode:
Hybrid, Onsite
Published on:
19 August 2026
What they need
Context
The client is the Cloud division of a large insurance group, in charge of a Managed Public Cloud Foundations product. This product delivers the first layer of compliance applied to everything deployed in the cloud across group entities, and also carries the deployment of global security assets such as SOC resources.
A major group-wide programme, funded and steered by Group Security, aims to shift Azure policy management from audit mode to deny mode, moving from detective to preventive control.
A POC is running: two to three policies have been deployed following a first version of the global process. These pilot policies have a deliberately narrow scope, so the operational process will need revision as volume grows.
The commitment made to Group Security covers roughly 45 policies, with at least half expected by the end of the year. Policies have been graded by complexity: delivery starts with the easiest remediation targets, while workshops with stakeholders define the development approach for the complex ones in parallel.
Environment: 27 tenants under management, deployment at management group level through cross-tenant managed identities, management group structure aligned with the Cloud Adoption Framework and identical across tenants, locked root management group.
Scope starts with the Group Operations entity, but everything must be designed for global group use.
The whole delivery chain operates in English.
Missions
The consultant joins the product team and takes ownership of the full policy development cycle, working alongside and then taking over from the Cloud Platform Engineer currently running the POC.
Pre-assessment
Analyse the security controls issued by Group Security. Each control from the security baseline must be translated into one or several policies.
Assess impact, identify exceptions and exemptions, and qualify risk before any development starts.Policy development
Write and maintain custom policy definitions and initiatives. All policies are custom, most of them derived from built-in policies.
Work on JSON definitions, select the appropriate effect (audit, auditIfNotExists, deny, append, modify, deployIfNotExists) and manage dependencies between policies.Infrastructure-as-code integration
Terraform modules already exist. Understand the repository structure, respect existing conventions and anticipate side effects, in particular the fact that changing a display name triggers destroy and recreate.
CI/CD currently runs on Azure DevOps, development happens on GitHub Enterprise, with a full migration to GitHub planned in the medium term.Deployment lifecycle
Apply the three-stage rollout: sandbox in audit mode to measure real impact, then pre-production and production with policies deployed in deny mode but left unassigned.
Assignment is performed in waves by a separate team (Cloud Brokers) that verifies compliance before activating the effect. The consultant stays in a permanent feedback loop with that team.Cross-team collaboration
Work with DevOps, operational and security teams to align policy enforcement with group security requirements.Documentation
Document policies and modules for maintainability and knowledge sharing.Nice to have, not required at start
Contribute to improving the governance process (RACI, development cycle, grading criteria).
Attend steering committees and explain, from the policy developer standpoint, why a given control or scope carries risk and why the development cycle should evolve.
Keywords
Governance
Security and Compliance
Audit / Consulting
Design and Maintenance in Operational Condition (MCO)
Profile wanted
- Proven experience as an Azure cloud engineer or architect in policy development within large enterprise environments
- Real command of Azure Policy: custom definitions, initiatives, assignments, exemptions
- Deep understanding of policy effects and their implications, including managed identity risks
- Strong policy lifecycle culture: audit start, measure before enforcing, avoid blocking production pipelines
- QA and testing mindset with zero tolerance for incidents on the security perimeter
- Operational autonomy with Terraform: reading, editing modules, understanding plan and apply, anticipating resource recreation
- Experience securing and organising a Terraform chain is a plus
- Knowledge of CI/CD on Azure DevOps and GitHub Actions appreciated
- Azure governance: management groups, subscriptions, RBAC, landing zones, Cloud Adoption Framework, multi-tenant context
- Familiarity with compliance frameworks such as CIS and NIST, security baselines
- Experience with Microsoft Defender for Cloud and its integration with Azure Policy
- Understanding of GitOps practices and policy-as-code
- Fluent professional English, written and spoken
- Ability to hold architect-level discussions in steering committees and with security teams, defending technical trade-offs and documenting reasoning
Other offers great for you!
These companies are also looking for great profiles
Audensiel
Azure Cloud Operations Engineer (F/H) - CDI
Permanent contract
In 2 to 4 weeks
Strasbourg, France
Hybrid
Skills
5 days ago
Exclusive opportunity
Soors
Azure Security Engineer H/F
Freelance
In 2 to 4 weeks
Paris, France
Hybrid
Skills
5 days ago
Exclusive opportunity
Visian
Ingénieur Sécurité Applicative IA
Freelance
In 2 to 4 weeks
Paris, France
Hybrid
Top Recruiter
Skills
4 days ago
Exclusive opportunity