Microsoft Cloud Engineer - Contract - FS or Insurance - Min 6 months
We are seeking a Microsoft Cloud Engineer - Contract
SC-300 IAM Administrator
SC-200 Security Operations Analyst
3 Yrs Entra ID Defender Sentinel exp
KQL skills
MS Purview & Endpoint DLP skills
SC-100 MS Cybersecurity Architecture Design (Desirable)
Key responsibilities
- Own the security architecture across the group estate - current and target state across identity, endpoint, network, and data layers
- Configure and tune the Microsoft Defender XDR suite - Defender for Endpoint, Identity, Cloud Apps, and Office 365 - across all group entities
- Design and deploy Conditional Access policies including Token Protection, tiered device posture, and Legacy authentication blocking
- Build and operate Microsoft Sentinel - workspace design, data connector coverage, KQL detection rules, SOAR playbooks, and alert triage procedures
- Own the Entra ID estate - life cycle management, service principal hygiene, break-glass accounts, and cross-tenant consolidation across acquired entities
- Deploy Privileged Identity Management - approval workflows, just-in-time access, session limits, and quarterly access reviews
- Drive the passkey and phishing-resistant authentication rollout - FIDO2/platform passkey deployment across the organisation
- Act as internal technical counterpart to the MDR provider - validate detections, manage scope and SLAs, fill coverage gaps, and ensure no ongoing dependency on external resource for routine decisions
- Review and approve security designs produced by third-party delivery partners - ensure controls are built to the required architecture standard, not just minimum viable
- Transfer operational ownership of activated controls to the internal security team at each delivery milestone
- Implement PAM for privileged and service accounts - just-in-time access, vaulting, and PIM alert routing to the MDR provider
- Build the zero trust M&A onboarding playbook - a step-by-step integration approach from acquisition close to SRG security baseline, covering identity federation, device posture, app access, Defender deployment, and Sentinel ingestion; owned by the CTO, co-contributed with the Platform and Workspace Engineer
Long run of contract work
Reference: 3117882897
Microsoft Cloud Engineer - Contract - FS or Insurance - Min 6 months
Posted on Jun 4, 2026 by Michael James Associates
We are seeking a Microsoft Cloud Engineer - Contract
SC-300 IAM Administrator
SC-200 Security Operations Analyst
3 Yrs Entra ID Defender Sentinel exp
KQL skills
MS Purview & Endpoint DLP skills
SC-100 MS Cybersecurity Architecture Design (Desirable)
Key responsibilities
- Own the security architecture across the group estate - current and target state across identity, endpoint, network, and data layers
- Configure and tune the Microsoft Defender XDR suite - Defender for Endpoint, Identity, Cloud Apps, and Office 365 - across all group entities
- Design and deploy Conditional Access policies including Token Protection, tiered device posture, and Legacy authentication blocking
- Build and operate Microsoft Sentinel - workspace design, data connector coverage, KQL detection rules, SOAR playbooks, and alert triage procedures
- Own the Entra ID estate - life cycle management, service principal hygiene, break-glass accounts, and cross-tenant consolidation across acquired entities
- Deploy Privileged Identity Management - approval workflows, just-in-time access, session limits, and quarterly access reviews
- Drive the passkey and phishing-resistant authentication rollout - FIDO2/platform passkey deployment across the organisation
- Act as internal technical counterpart to the MDR provider - validate detections, manage scope and SLAs, fill coverage gaps, and ensure no ongoing dependency on external resource for routine decisions
- Review and approve security designs produced by third-party delivery partners - ensure controls are built to the required architecture standard, not just minimum viable
- Transfer operational ownership of activated controls to the internal security team at each delivery milestone
- Implement PAM for privileged and service accounts - just-in-time access, vaulting, and PIM alert routing to the MDR provider
- Build the zero trust M&A onboarding playbook - a step-by-step integration approach from acquisition close to SRG security baseline, covering identity federation, device posture, app access, Defender deployment, and Sentinel ingestion; owned by the CTO, co-contributed with the Platform and Workspace Engineer
Long run of contract work
Reference: 3117882897
Alert me to jobs like this:
Amplify your job search:
Expert career advice
Increase interview chances with our downloads and specialist services.
Visit Blog