{"id":1352081,"url":"https://alion.io/job/teamlyzer-azure-cloud-security-engineer","title":"Azure Cloud Security Engineer","company":{"id":701663,"name":"Teamlyzer","domain":"teamlyzer.com","url":"https://alion.io/company/teamlyzer","size_band":"5000+","is_staffing_agency":false,"employer_type":"direct","is_intermediary":true,"listed_via":"teamlyzer.com","ats_vendor":"Schema","truth_index":{"grade":"B","score":76,"open_postings":20,"ghost_share":0,"stale_share":0.95,"repost_share":0,"time_to_fill_p50_days":31,"computed_at":"2026-09-28T05:45:00Z"}},"role":"Security","role_family":"Security","seniority":"junior","employment_type":"full_time","work_mode":"on_site","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Lisbon, Portugal"],"countries":["PT"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":20000,"max_usd":57000,"period":"year","method":"global_role_cell_scaled_by_country","sample_n":309},"experience_years_min":1,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"Azure","optional":false},{"name":"Bicep","optional":false},{"name":"CI/CD","optional":false},{"name":"DNS","optional":false},{"name":"Kubernetes","optional":false},{"name":"Least Privilege","optional":false},{"name":"Terraform","optional":false}],"status":"live","first_seen_at":"2026-09-24T00:00:00Z","employer_posted_date":"2026-09-24","last_verified_at":"2026-09-24T00:00:00Z","board_verified":false,"closed_at":null,"days_open":5,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":5},"description":"Sobre a vaga\nWe are seeking an Azure Cloud Infrastructure Security Engineer to join our Porto Cybersecurity CoE team. This role is based in Lisbon and will support the design, implementation and secure operation of Azure landing zones and the IaaS and PaaS services deployed within them.\nO que vais fazer\nSupport business and technology projects by providing cloud security expertise throughout the project lifecycle\nSupport the secure design, implementation and continuous improvement of Azure landing zones\nImplement and validate security controls for Azure IaaS and PaaS resources\nDefine, maintain and promote baselines and hardening standards to Azure subscriptions, virtual machines, storage, databases, application services and other cloud resources\nSupport the implementation of Azure identity and access controls, including role-based access control, managed identities, privileged access and least-privilege permissions\nImplement and troubleshoot network security controls, including network security groups, Azure Firewall, private endpoints, service endpoints, routing and network segmentation\nReview cloud architectures and validate security requirements through security assessments and architecture reviews\nContribute to the design, implementation and continuous improvement of secure Azure cloud architectures\nAssess cloud-native services and workloads to identify security risks and recommend mitigation measures\nSecure CI/CD pipelines by defining and promoting security controls across development, building, testing and deployment processes\nCollaborate with infrastructure, development and DevOps teams to integrate security controls into cloud environments\nMonitor cloud security posture and support remediation activities identified through CSPM findings\nAssist in the enforcement of cloud governance and security policies across Azure environments\nConfigure and maintain Azure Policies to implement and enforce cloud security controls\nStay informed about emerging cloud security threats, vulnerabilities and industry best practices\nO que é pedido\nBachelor's degree in Information Technology, Computer Science, Cybersecurity, Engineering, or a related field, or equivalent professional experience\nMinimum of 1 years of experience in Azure Cloud engineering and cloud security, infrastructure, or related technical roles\nHands-on experience deploying, configuring or supporting Azure IaaS and PaaS resources\nWorking knowledge of Azure landing-zone concepts, including management groups, subscriptions, resource organization, policy and access control\nPractical understanding of Azure networking, including virtual networks, subnets, routing, network security groups, firewalls, private connectivity and DNS\nUnderstanding of Azure identity and access management, including role-based access control, managed identities and least-privilege access\nExperience implementing or validating cloud security baselines and resource hardening requirements\nFamiliarity with Azure Policy and policy-driven cloud governance\nBasic experience with Terraform, Bicep, ARM templates or another infrastructure-as-code technology\nUnderstanding of encryption, key management, secrets management, logging and monitoring in Azure\nAbility to analyse cloud configurations, identify security weaknesses and support their remediation\nUnderstanding of cloud security principles, risk assessment methodologies, and security control validation\nKnowledge of cloud compliance, risk assessment, and security governance concepts\nFamiliarity with cloud security posture management (CSPM) solutions\nBasic understanding of CI/CD processes and associated security considerations\nStrong analytical, problem-solving, and communication skills\nAbility to collaborate effectively with cloud platform, networking, infrastructure and DevOps engineers\nFluent English, with clear written and verbal communication skills\nMinimum of 3 days per week onsite in Alfragide\nFlexibility to travel within Europe for project activities and stakeholder engagements\nValorizado\nExperience supporting or implementing an Azure landing zone and network security components\nHands-on experience with Azure Policy and CSPM tools\nExperience securing Azure virtual machines, storage accounts, databases, application services, containers or Kubernetes services\nExperience performing cloud security assessments and secure cloud architecture reviews\nExposure to security baseline development and cloud hardening practices\nUnderstanding of cloud risk management and remediation processes\nKnowledge of CI/CD security controls and secure deployment practices\nRelevant Azure, cloud, or cybersecurity certifications are considered an advantage, including\nMicrosoft Certified: Azure Fundamentals (AZ-900)\nMicrosoft Certified: Azure Administrator Associate (AZ-104)\nMicrosoft Certified: Azure Security Engineer Associate (AZ-500)\nO que é oferecido\nopportunities to keep skills relevant through certifications, learning, and diverse work experiences\nResumo organizado por IA a partir do anúncio original. Confirma os detalhes no site da empresa.","description_format":"text","description_chars":5083,"description_truncated":false,"requirements":{"experience_years_min":1,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":{"level":"bachelor","optional":false},"security_clearance":false,"languages":[{"language":"English","level":"Advanced (C1)","optional":false}]},"benefits":[],"hiring_locations":[],"hiring_excludes":[],"relocation_offered":false,"industries":["Cloud Security","Career Services","Job Boards & Aggregators","Online Reviews & Ratings"],"lifecycle":[{"event":"open","at":"2026-09-27T19:32:22Z"}],"liveness":{"score":63,"band":"ok","label":"Likely open","p_open":1,"p_active":0.632,"p_room":1,"age_days":4,"expected_fill_days":31,"reasons":["seen:4","stale_co","velocity","win:early","comp:junior,brand"],"computed_at":"2026-09-28T05:45:00Z"},"pay":null,"html_url":"https://alion.io/job/teamlyzer-azure-cloud-security-engineer","json_url":"https://alion.io/job/teamlyzer-azure-cloud-security-engineer.json","meta":{"generated_at":"2026-09-29T03:33:24Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":3263,"day_limit":5000,"remaining_today":1737,"minute_limit":60,"resets_at":"2026-09-30T00:00:00Z"}}}