04 Aug
|
Avanade
|
Sydney
Summary
We are seeking a highly skilled Cloud Security specialist with deep expertise across the Microsoft Cloud security ecosystem to help clients design, implement, and optimize secure cloud environments. The successful candidate will work with enterprise customers to assess security posture, define cloud security strategies, architect secure solutions, and deliver security transformation initiatives across Microsoft Azure and Microsoft Security platforms.
This is a client-facing consulting role requiring a blend of technical expertise, advisory capability, and stakeholder management skills. The consultant will collaborate with security leaders, cloud architects, engineers, and business stakeholders to enable secure adoption of cloud technologies while maintaining compliance and resilience.
Key Responsibilities
Security Advisory & Consulting
- Conduct cloud security assessments, maturity reviews, and gap analyses.
- Advise clients on Microsoft security best practices, Zero Trust architecture, and cloud governance.
- Develop security roadmaps, operating models, and remediation plans.
- Support security strategy and cloud transformation initiatives.
Cloud Security Architecture
- Design secure Azure landing zones and enterprise cloud platforms.
- Architect solutions aligned with Microsoft Cloud Adoption Framework (CAF) and Well-Architected Framework (WAF).
- Define security controls for identity, networking, data protection, and workload security.
- Conduct architecture reviews and security design assurance activities.
Microsoft Security Platform Implementation
- Implement and optimize:
- Microsoft Defender for Cloud
- Microsoft Defender XDR
- Microsoft Sentinel (SIEM/SOAR)
- Microsoft Entra ID
- Microsoft Purview
- Azure Key Vault
- Azure Policy and Governance Controls
- Configure Continuous Security Monitoring and Threat Detection capabilities.
Identity & Access Management
- Design and implement:
- Microsoft Entra ID
- Conditional Access
- Privileged Identity Management (PIM)
- Identity Governance
- Role-Based Access Control (RBAC)
- Implement Zero Trust identity strategies.
DevSecOps & Automation
- Integrate security controls into CI/CD pipelines.
- Implement Infrastructure as Code security using Terraform, Bicep, and Azure DevOps.
- Establish Policy-as-Code and compliance automation.
- Support secure application and container deployment practices.
Governance, Risk & Compliance
- Align cloud environments with security and regulatory frameworks such as:
- ISO 27001
- NIST
- CIS Benchmarks
- SOC 2
- Essential Eight (where applicable)
- Assist with audit readiness and security governance activities.
- Develop security standards, policies, and reference architectures.
Client & Stakeholder Engagement
- Facilitate workshops and technical design sessions.
- Present recommendations to technical and executive audiences.
- Support presales activities including solution design, effort estimation, and proposal development.
- Mentor junior consultants and engineers.
.
Skills & Experience
Technical Skills
- Strong hands-on experience with Microsoft Azure security services.
- Expertise in
- Microsoft Defender for Cloud
- Microsoft Sentinel
- Microsoft Entra ID
- Microsoft Purview
- Azure Policy
- Azure Firewall
- Azure Key Vault
- Network Security Groups (NSGs)
- Private Endpoints
- Solid understanding of
- Zero Trust Architecture
- Cloud Security Architecture
- Identity & Access Management
- Security Monitoring & Incident Response
- Secure Network Design
Cloud & Platform Knowledge
- Azure IaaS, PaaS, and cloud-native services.
- Azure Landing Zones and Enterprise-Scale Architecture.
- Kubernetes and Azure Kubernetes Service (AKS) security.
- Hybrid cloud and cloud migration security considerations.
DevSecOps
- Terraform, Bicep, ARM Templates.
- Azure DevOps and GitHub Actions.
- CI/CD Security and Infrastructure as Code.
Consulting Skills
- Client-facing consulting experience.
- Stakeholder management and workshop facilitation.
- Strong communication, documentation, and presentation skills.
- Ability to translate business requirements into secure technical solutions.
Preferred Qualifications
Certifications
- Microsoft Certified: Azure Security Engineer Associate (AZ-500)
- Microsoft Certified: Cybersecurity Architect Expert (SC-100)
- Microsoft Certified: Azure Administrator Associate (AZ-104)
- Microsoft Certified: Azure Solutions Architect Expert
- CISSP
- CCSP
- CISM
Experience
- 5+ years of cloud security, cybersecurity, or security consulting experience.
- 3+ years of hands-on Microsoft Azure security experience.
- Experience delivering security solutions within enterprise or consulting environments.
- Exposure to large-scale cloud transformation and modernization programs is highly desirable.
Note: Australian citizenship is mandatory
.
📌 Cloud Security Specialist (Sydney)
🏢 Avanade
📍 Sydney