> Markdown version of [/jobs/ext/18729-senior-cloud-security-consultant](https://www.wearedevelopers.com/jobs/ext/18729-senior-cloud-security-consultant). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Cloud Security Consultant - **Company:** NVISO - **Location:** Brussel, Belgium (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Artificial Intelligence, Microsoft Azure, Microsoft Online Services, Cloud Computing, Cloud Computing Security, CompTIA Security+, Cyber Security, Multi-Factor Authentication, Identity and Access Management, Information Lifecycle Management, Python (Programming Language), Key Management, Massachusetts Comprehensive Assessment Systems, Windows PowerShell, Role-Based Access Control, Azure Active Directory, Cloud Services, Phishing, Kusto Query Language, Microsoft SharePoint, EndPointSecurity, Scripting, Application Enhancement Tool, Cloud Platform System, Data Classification, Microsoft Power Automate, Firewalls (Computer Science), Microsoft InTune, Information Technology, Cybercrime, Bicep, Microsoft Sentinel, CIS Benchmarks, Terraform - **Published:** May 22, 2026 - **Apply:** https://www.careerjet.be/jobad/bed3139a7fc837b2460f754824b431250c ## About the Role * You hold citizenship in one of the 32 NATO member states. * 2 to 3 years of experience in information security specific to Azure or Microsoft 365 cloud environments. * Proven expertise with Microsoft's cloud services, including Entra ID, Microsoft Sentinel, and Microsoft Defender for Cloud, Defender for Endpoint, Defender for Cloud Apps, Defender for Identity, Intune, and/or Purview. * Experience with cloud security best practices and related frameworks. For example: CIS Benchmarks, Microsoft Cloud Security Benchmark, etc. * Strong communication, documentation and reporting skills. * Relevant current Microsoft cloud certifications. For example: AZ-104, SC-900, SC-200, SC-300, SC-401, or AZ-500. Preferred * Bachelor's degree in Computer Science, Cyber Security, Information Security, Engineering, Information Technology, or related studies. * Experience in consulting. * Other vendor-agnostic cybersecurity certifications. E.g. SSCP, CompTIA Security+, or equivalent. * Experience with scripting languages such as PowerShell or Python. ## Description * Brussel * Vast * Voltijds * 18 uren geleden Who are we? It all starts with the mission: NVISO is here to protect European society from potentially devastating cyber attacks! This means we offer cyber security services to private and governmental organizations to help them better prepare for, prevent, detect and respond to cyber security incidents. All of this is built on four fundamental values that define who we are: We are Proud, We Break Barriers, We Care and No BS! Tasks You will be joining NVISO's Cloud Security team as a Cloud Security (Sr.) Consultant. The ideal candidate has knowledge in Azure or Microsoft 365 cloud services, with a particular focus on security. We are aware that cloud security features and products are abundant; the following list apply to the ones of interest to us. If you have experience or feel capable of conducting only some of them (not the full list), please reach out! Strategy and Governance * Assess cloud security posture against frameworks (e.g., CIS, NIST, ISO 27001) and Microsoft benchmarks (Azure Security Benchmark, M365 baseline). * Define cloud security strategy, target operating model, and roadmap aligned to business and regulatory requirements. * Develop and maintain cloud security policies, standards, and guardrails for Azure and M365. Identity and Access Management (IAM) * Design and implement Microsoft Entra tenant architecture, including identity lifecycle, conditional access, and MFA. * Implement and tune Conditional Access policies, risk-based access, and device compliance integrations with Intune/Endpoint Manager. * Deploy and operate Privileged Access Management (PAM), including PIM for Azure and M365 roles, just-in-time access, and break-glass accounts. * Integrate on-premises identities (hybrid) with secure synchronization and hardening of federation where used. Platform Security and Hardening (Azure) * Build secure landing zones using Azure Policy, Blueprints/Bicep/Terraform, and management groups. * Enforce baseline controls for networking (NSGs, Azure Firewall, Private Link), compute (secure images, patching), and storage (encryption, private endpoints). * Configure Azure Key Vault for secrets, keys, and certificates management with RBAC and purge protection. * Implement workload isolation, tagging, and resource locks; manage identity-based access (managed identities). Threat Protection and Monitoring * Deploy and tune Microsoft Defender for Cloud, Defender for Cloud Apps (MCAS), Defender for Endpoint, and Defender for Identity. * Configure Microsoft Sentinel: data connectors, analytics rules, UEBA, watchlists, workbooks, and SOAR playbooks (Logic Apps). * Develop detection use cases, threat hunting queries (KQL), and incident response runbooks specific to Azure and M365 threats. * Establish alert triage, escalation paths, and continuous tuning to reduce noise and improve mean time to detect/respond. Microsoft 365 Security * Configure and manage Microsoft Purview (Compliance portal) for DLP, information protection labels, data lifecycle, and insider risk. * Implement Exchange Online, SharePoint, OneDrive, and Teams security baselines, safe links/attachments, and anti-phishing policies. * Enforce device compliance via Intune, app protection policies, and conditional access for BYOD and corporate devices. * Secure collaboration and external sharing with sensitivity labels, access reviews, and entitlement management. Data Protection and Encryption * Design data classification and labelling strategies with Microsoft Purview; enforce DLP across endpoints, Exchange, SharePoint, and Teams. * Ensure encryption at rest and in transit, customer-managed keys (CMK), and double encryption where required. * Implement eDiscovery, legal hold, and audit configurations for regulatory needs., Please be aware that the creation and submission of application documents (e.g. CV, cover letter, case studies, etc.) using AI-powered tools is only permitted to a limited extent. Our expectations: Application documents must authentically reflect your own qualifications, personality, and motivation. The use of AI for supportive purposes (e.g. spell-checking, improving wording) is acceptable. Fully generated application documents created by AI without personal adaptation or review are not permitted. Under no circumstances may NVISO information, data, or documents be uploaded to or processed by external AI tools. We reserve the right to exclude applications from the selection and interview process that are clearly created primarily or exclusively by AI and show no recognizable personal input. The purpose of this policy is to ensure a fair and transparent recruitment process and to obtain an authentic impression of our applicants. NVISO We are a young team of cyber security professionals who decided to do things differently. With innovation rooted in our foundations, we offer services that are up against the modern adversary and that help you Prevent, Detect & Respond to cyber attacks. Curious for more? Say hello and meet the team! ## Related Videos - [Hacking MSSQL on Cloud. All of them. How I became sysadmin on Azure, AWS, GCP and Alibaba.](https://www.wearedevelopers.com/videos/100339-hacking-mssql-on-cloud-all-of-them-how-i-became-sysadmin-on-azure-aws-gcp-and-alibaba) - [Infrastructure as Code: The Developer's Secret Weapon](https://www.wearedevelopers.com/videos/1221-infrastructure-as-code-the-developer-s-secret-weapon) - [Back(end) to the Future: Embracing the continuous Evolution of Infrastructure and Code](https://www.wearedevelopers.com/videos/440-back-end-to-the-future-embracing-the-continuous-evolution-of-infrastructure-and-code) - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Implementing Feature Environments with AWS and Terraform](https://www.wearedevelopers.com/videos/531-implementing-feature-environments-with-aws-and-terraform) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [7 Cloud Computing Trends Coming in 2025 for Developers](https://www.wearedevelopers.com/magazine/412-7-cloud-computing-trends-coming-in-2025-for-developers) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)