Skip to content
Experis Manpower Group

Cloud Security Engineer (DED)

Experis Manpower Group Show all offers
Kraków
1 day ago

In short

Cloud Security Engineer in Kraków, Poland. Build Azure security controls, centralize logging in Sentinel, develop KQL detections for data exfiltration, and work with M365/AWS security. Requires 5+ years cloud security, 3+ years Azure, Sentinel, KQL, and Azure Policy/CI/CD.

AI-written summary based on the listing content.

The ideal candidate is a Cloud Security Engineer with deep Azure, Sentinel, Defender for Cloud, and KQL expertise who has specifically built data exfiltration detection capabilities and implemented cloud security controls at an enterprise scale.

What you'll doDeploy Microsoft Defender for Cloud protections (Key Vault, Storage, Databases, AI, API) across several Azure tenants using Azure Policy and Policy-as-Code pipelines.

Centralize logging in Microsoft Sentinel by turning on audit and resource logs and connecting Azure, M365 and AWS.

Build and tune exfiltration detections in KQL that flag unusual data volumes, rate changes and abnormal access patterns across M365, PaaS and SaaS services.

Detect exfiltration from Azure IaaS workloads by:enabling Defender for Servers and VNet/NSG flow logs with Traffic Analytics; using Firewall logs to baseline normal outbound traffic; alerting on large or unusual transfers to the internet or unknown destinations.

Map exfiltration paths to controls and document coverage gaps and recommendations.

Create triage playbooks and runbooks with clear escalation paths, then hand them over to the InfoSec/SOE team.

Required Skills5+ years in cloud security engineering, including at least 3 years of hands-on Azure work.

Being able to map exfiltration points to controls and document coverage gaps, such as exfiltration through legitimate native features.

To be able to build and test custom Sentinel exfiltration detections in KQL. These should cover unusual volumes, rate changes and abnormal patterns, including Exchange and Microsoft Graph API activity spikes.

Has deployed Microsoft Defender for Cloud plans at enterprise scale in more than one tenant.

Strong Microsoft Sentinel skills: data connectors, analytics rules, KQL, workbooks and automation rules.

Azure Policy / Policy-as-Code and deployment through CI/CD (Azure DevOps or GitHub).

Good understanding of M365 audit logs, Entra ID and Defender XDR / Cloud Apps.

Works within a formal change process (ServiceNow CRQ) and can document clearly.

AWS GuardDuty, CloudTrail and Organizations-level security setup.

Microsoft Purview: DLP, Insider Risk Management and audit.

Background in detection engineering or threat hunting focused on data exfiltration.

Experience after an incident or in a remediation program.

Certifications such as SC-200, AZ-500 or SC-100.

AWS Security Specialty is a plus.

Published 2026-10-09
Expires 2026-11-12
Source