368,530open jobs
9,432companies
50,439added this week
Browse all
Salary
$48k – $118k per year (Estimated)
Location
Remote/Hybrid (Lisbon, Portugal)
Seniority
Senior · 5+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match
Devoteam is a French technology consulting firm that specializes in digital transformation, with a strong focus on cloud platforms, artificial intelligence, data analytics, and cybersecurity. Founded in 1995, the company operates across Europe, the Middle East, and Africa, helping both private and public sector organizations modernize their IT infrastructure. By partnering with major tech leaders like Google Cloud, AWS, Microsoft, and ServiceNow, it delivers tailored AI-driven solutions to help businesses innovate and scale efficiently.

Devoteam Cyber Trust is the Cybersecurity specialist arm of the Devoteam Group. With our 800+ experts located across EMEA, we aim to establish cybersecurity as an enabler of business success rather than a gatekeeper. We leverage an end-to-end approach to Cyber Resilience, Applied Security, and Managed Security services to secure the tech journey of large and medium-sized companies from all sectors and industries.

Since 2009, previously known as INTEGRITY, our team based in Portugal is specialised in providing cutting-edge Managed Security Services that combine its expertise and proprietary technology to consistently and effectively reduce the cyber risk of our clients.

The comprehensive service range includes Persistent Intrusion Testing, ISO 27001, PCI-DSS, GRC Consulting and Solutions, and Third-Party Risk Management. ISO 27001 (Information Security) and ISO 9001 (Quality) certified, PCI-QSA, and member of CREST and CIS - Centre for Internet Security, we provide services to a considerable number of clients, operating in more than 20 countries.

We're building a new Cloud Security Practice that delivers outcome-driven security engagements across Microsoft Azure, Microsoft 365, Google Cloud, AWS, and partner CNAPP platforms.

We're hiring a Lead Cloud Security Consultant - Microsoft Focus as a hands-on cyber security expert. You'll help design how we deliver engagements, execute them in the consoles, and build the reusable assets the practice will scale on.

This is a cyber-first role with Microsoft as the primary stack. Microsoft Sentinel, Defender XDR, Defender for Cloud, and Entra ID are the core of the work, but you should be comfortable operating in broader cloud security contexts - multi-cloud posture, CNAPP findings, exposure reduction - when engagements call for it. You don't need to be a pure infrastructure engineer, but you should understand cloud environments well enough to identify security gaps, implement controls, and help customers improve their posture.

What you'll do

  • Deliver cloud security engagements end-to-end with a Microsoft focus: Sentinel deployments, Defender XDR rollouts, Defender for Cloud implementations, detection engineering, threat hunting, incident response support, posture assessments, Azure security reviews, identity security improvements, cloud hardening.

  • Write KQL, tune analytics rules, build connectors, configure Defender XDR policies, and walk customers through what their telemetry, posture, exposure, and risks mean.

  • Assess and improve security controls across Sentinel, Defender XDR, Defender for Cloud, Entra ID, Azure workloads, logging/monitoring, and privileged access.

  • Translate cyber security requirements into practical configurations, remediation actions, detection use cases, and operational improvements.

  • Support multi-cloud engagements (Google Cloud, AWS) and CNAPP-related work where the customer needs posture improvement, exposure reduction, or detection coverage.

  • Run customer-facing workshops and build the reusable assets the practice will scale on: playbooks, deliverable templates, KQL libraries, detection rule packs, configuration baselines, hardening guides, remediation roadmaps.

Microsoft Sentinel:

  • Deployed or supported Sentinel in production for at least one enterprise customer.

  • Writes KQL from scratch for analytics rules, hunting queries, investigations, and workbooks.

  • Has built, tuned, or maintained analytics rules, scheduled queries, hunting queries, or incident workflows.

  • Has worked with data connectors, including Microsoft and non-Microsoft sources.

  • Has experience with automation rules, Logic Apps playbooks, or response workflows.

  • Understands alert fatigue and has experience improving signal-to-noise in a SOC or monitoring environment.

Defender XDR cross-pillar:

  • Configured and operated Defender for Endpoint, Identity, Office 365, and Cloud Apps.

  • Investigated incidents spanning multiple pillars using the unified incident model.

  • Comfortable with advanced hunting across the Defender XDR schema.

  • Understands how Defender XDR and Sentinel complement each other in detection and response.

Azure and cloud security:

  • Solid Azure security understanding from a cyber perspective, not just infrastructure.

  • Has delivered Azure security assessments, posture improvement, hardening, or secure configuration reviews.

  • Hands-on with Microsoft Defender for Cloud - recommendations, regulatory compliance, workload protection, posture management.

  • Understands subscriptions/management groups, Azure Policy, RBAC, logging/monitoring, network exposure, and workload protection.

  • Comfortable working in broader cloud security contexts: posture management, workload protection, misconfiguration review, exposure reduction.

Identity and access:

  • Strong Microsoft Entra ID security - MFA, Conditional Access, Identity Protection, access reviews, enterprise applications, service principals.

  • Familiarity with PIM, RBAC, least privilege, break-glass accounts, access governance.

  • Understands identity as a core cloud security control.

Cloud security and CNAPP awareness:

  • Understands CSPM, CWPP, attack paths, misconfiguration abuse, and cloud-specific attack patterns.

  • Familiar with CNAPP concepts and tools.

  • Can turn cloud security findings into practical remediation plans for security, cloud, and engineering teams.

Delivery experience:

  • 5+ years cybersecurity experience, including relevant experience with the Microsoft security stack in a delivery, consulting, cloud security, detection engineering, or senior SOC role.

  • Experience delivering client-facing cyber security work, including assessments, implementations, workshops, remediation planning, or technical documentation.

  • Able to produce clear technical deliverables: assessment reports, implementation plans, remediation roadmaps, configuration baselines, runbooks, and executive-level summaries.

  • Portuguese and English.

Nice to have

  • Microsoft Purview - DLP, information protection, insider risk.

  • Google Cloud or AWS security background.

  • Exposure to Wiz or another CNAPP platform.

  • Experience with Infrastructure-as-Code security, ideally Terraform, Bicep, ARM templates, or CI/CD security reviews.

  • Experience with DevSecOps, secure cloud deployment patterns, or security guardrails.

  • Knowledge of Microsoft Cloud Security Benchmark, CIS Benchmarks, NIST, ISO 27001, MITRE ATT&CK, or cloud security reference architectures.

  • Experience building reusable consulting assets, such as KQL packs, Sentinel deployment kits, Defender configuration guides, cloud security baselines, assessment methodologies, or remediation playbooks.

Certifications

Strongly valued: SC-100.

Also valued: SC-200, AZ-500, SC-300, SC-400, CISSP, CCSP, Google Cloud Professional Cloud Security Engineer, AWS Security Specialty.

Real operational and delivery experience matters more than certification recall.

Working style

  • Hands-on by default, in consoles weekly.

  • Cyber-first mindset - you look at Azure, Microsoft 365, identity, endpoints, SaaS, and cloud workloads through risk, threat, control effectiveness, and operational security.

  • Microsoft-focused, cloud-aware - Microsoft is your strongest stack, but you can operate in multi-cloud conversations and broader cloud security engagements.

  • Delivery-focused - you can assess, implement, document, and hand over.

  • Iterative - you'd rather ship a working v1 in two weeks than a perfect v1 in four months.

  • Plain-language translator - you explain a detection, a risky identity configuration, a Defender recommendation, or a CNAPP finding to a SOC analyst and a CFO using different words and the same accuracy.

  • Builder - you leave behind reusable assets, not just closed tickets.

  • Pragmatic - you know the difference between an ideal target state and a workable next step for a real customer environment.

Devoteam Group works for equal opportunities, promoting its employees based on merit and actively fights against all forms of discrimination. We are convinced that diversity contributes to the creativity, dynamism and excellence of our organization. All of our vacancies are open to people with disabilities.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
368,530 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Lisbon
$120k – $268k per year (Estimated) • Equity • Remote • Full-Time • Bachelor's Degree
C#
Go
JavaScript
Python
TypeScript
AI/ML
AI Agents
AutoGen
AWS Bedrock
Copilot
Function Calling
LangChain
LLM
Prompt Engineering
RAG
Human-in-the-Loop
LLM Guardrails
OpenAI
DevOps
AWS
Azure
Bicep
CI/CD
GCP
Kubernetes
Platform Engineering
Shift-Left
Terraform
GitHub
Cybersecurity
Burp Suite
Checkmarx
Checkov
CIS Benchmarks
HashiCorp Vault
HIPAA
ISO 27001
OWASP Top 10
OWASP ZAP
PCI DSS
SBOM
Semgrep
Shift-Left Security
Sigstore
SLSA
Snyk
SOC 2
SonarQube
Threat Modeling
Trivy
Veracode
Least Privilege
Cryptography
Vault
Apply
$20k – $48k per year (Estimated) • Remote • Saint Petersburg
Python
SQL
Databases
ClickHouse
MySQL
DevOps
AWS
Azure
Docker
GCP
Kubernetes
Analytics
ETL/ELT
Apply
$68k – $114k per year (Estimated) • Equity • Remote • Full-Time • 8+ years exp • Warsaw
Java
Python
Databases
Db2
AI/ML
Claude
Copilot
Anthropic
DevOps
AWS
Azure
GCP
Platform Engineering
GitHub
Apply
$105k – $227k per year (Estimated) • Equity • Remote • Full-Time • 7+ years exp
Bash
Perl
Python
SQL
Databases
Amazon Aurora
DynamoDB
ElasticSearch
AI/ML
Anthropic
DevOps
Amazon EC2
Ansible
AWS
AWS Lambda
Azure
CI/CD
CloudFormation
Datadog
Docker
GCP
Git
GitLab CI
Jenkins
Kubernetes
Platform Engineering
Puppet
Splunk
Terraform
Amazon CloudWatch
Amazon ECS
GitLab
IAM
Cybersecurity
Sumo Logic
Apply
Senior DevSecOps 4 days ago
$24k – $54k per year (Estimated) • Remote • 5+ years exp • Moscow
Node JS
Python
JavaScript
Databases
ElasticSearch
DevOps
CI/CD
GCP
GitLab CI
Grafana
Kubernetes
Terraform
Terragrunt
VictoriaMetrics
Yandex Cloud
GitLab
Cybersecurity
Checkov
CIS Benchmarks
Grype
Keycloak
OWASP Top 10
SonarQube
Terrascan
Trivy
Apply
$31k – $78k per year (Estimated) • Remote/Hybrid • Full-Time • 4+ years exp • Master's Degree • Lisbon
C#
PowerShell
Python
SQL
C#
.NET
Databases
MS SQL
DevOps
Git
Windows Server
Apply
$33k – $84k per year (Estimated) • Remote/Hybrid • Full-Time • 4+ years exp • Master's Degree • Porto
C#
PowerShell
Python
SQL
C#
.NET
Databases
MS SQL
DevOps
Git
Windows Server
Apply
Remote/Hybrid • Full-Time • Lisbon
Assembly
Databases
Oracle
Cybersecurity
GDPR
Apply
Remote/Hybrid • Full-Time • Porto
Assembly
Databases
Oracle
Cybersecurity
GDPR
Apply
$78k – $236k per year (Estimated) • Remote/Hybrid • Full-Time • Amsterdam
Python
DevOps
Ansible
AWS
CI/CD
Docker
Jenkins
Kubernetes
OpenShift
Podman
Terraform
GitLab
Management
ServiceNow
Marketing
Salesforce
Apply
$41k – $97k per year (Estimated) • Remote/Hybrid • Full-Time • 5+ years exp • Lisbon
DevOps
Ansible
AWS
Azure
CI/CD
Docker
FinOps
GCP
Kubernetes
OpenShift
Terraform
Apply
$26k – $63k per year (Estimated) • In office • Full-Time • 5+ years exp • Lisbon
Java
DevOps
CI/CD
Git
GitLab
GitLab CI
Jenkins
Management
Jira
QA
Appium
Cucumber
Postman
Rest-Assured
Selenium
Apply
$36k – $81k per year (Estimated) • In office • Full-Time • 5+ years exp • Bachelor's Degree • Lisbon
DevOps
IAM
Apply
$39k – $98k per year (Estimated) • In office • Full-Time • 2+ years exp • Lisbon
Bash
PowerShell
Python
SQL
Databases
ElasticSearch
DevOps
CI/CD
Kibana
Apply
$36k – $84k per year (Estimated) • In office • Full-Time • 5+ years exp • Lisbon
Python
SQL
AI/ML
NumPy
Time Series Forecasting
Apply
See all jobs
This is one of many
368,530 more open roles from verified company boards, updated every day.