- Company Name
- InvitISE Ltd
- Job Title
- Senior Security Engineer (Defender, PurView)
- Job Description
-
**Job title**
Senior Security Engineer (Defender, PurView)
**Role summary**
Lead hands‑on remediation and hardening across Azure and endpoint environments. Improve Defender for Cloud findings, close vulnerabilities, and strengthen the organization’s security posture through configuration hardening, patching, and policy deployment. Operate on a contract basis, providing practical solutions rather than advisory services.
**Expectations**
- Deliver measurable improvements in Defender for Cloud Secure Score and overall risk.
- Meet compliance requirements for ISO 27001, SOC 2, GDPR, and NIS 2.
- Deploy and maintain Defender for Endpoint, EASM, Purview, and cloud identity controls.
- Automate tasks using PowerShell and Microsoft Graph.
- Work in a hybrid environment, attending office three days per week.
**Key responsibilities**
- Remediate Azure and endpoint security findings; close vulnerabilities.
- Harden configurations and manage patching across cloud and on‑prem environments.
- Configure and enforce DLP, sensitivity labels, and insider risk with Purview.
- Manage Entra ID (Conditional Access, PIM, cloud identity controls).
- Conduct or support compliance uplift activities for ISO 27001, SOC 2, GDPR, NIS 2.
- Automate remediation and monitoring using PowerShell and Microsoft Graph.
- Maintain documentation, runbooks, and security dashboards.
- Collaborate with threat squad, DevSecOps, and operations teams to integrate security into CI/CD pipelines.
**Required skills**
- Expertise in Defender for Cloud, Defender for Endpoint, and Enterprise Attack Surface Management (EASM).
- Hands‑on vulnerability remediation, Secure Score improvement, and configuration hardening.
- Strong knowledge of Purview (DLP, sensitivity labels, insider risk).
- Proficiency in Entra ID, Conditional Access, Privileged Identity Management (PIM).
- Scripting in PowerShell; use of Microsoft Graph API for automation.
- Understanding of ISO 27001, SOC 2, GDPR, and NIS 2 compliance frameworks.
- Familiarity with Zero Trust concepts and cloud identity best practices.
**Required education & certifications**
- Microsoft Certified: Azure Security Engineer Associate (AZ‑500)
- Microsoft Certified: Microsoft Purview Information Protection Strategy (SC‑100) – or actively pursuing
- One of: Microsoft 365 Security Administrator (MS‑500), Microsoft Security Operations Analyst (SC‑400), or Microsoft Security Fundamentals (SC‑900)
- Desired: Certified Cloud Security Professional (CCSP)
---