Lead Cloud Security - Azure
Responsibilities
Job Summary: We are seeking a skilled Cloud Security Analyst to join our team. The ideal candidate will have extensive experience in cloud security, particularly with Azure, AWS, and Microsoft 365 (M365). This role involves ensuring the security of our cloud infrastructure, identifying and mitigating risks, and implementing best practices to protect our data and systems.
Key Responsibilities:
- Design, implement, and manage security measures for cloud environments (Azure) in the respect of Group standards & policies[GH1]
- Monitor cloud infrastructure for security breaches and respond to incidents.
- Conduct regular security assessments and audits.
- Develop and enforce security policies and procedures.
- Collaborate with IT and development teams to ensure secure deployment of applications.
- Stay updated with the latest security trends and threats.
- Responsible to managed cloud operational security
- Provide training and guidance to staff on cloud security best practices.
- Review users’ request on Azure and provide approval or implement required configuration (ex : admin consent (permissions to internal or external applications to access Cloud Tenant with the user account))
- Azure access reviews configuration and follow-up (report on non-completed reviews, send reminder to reviewers and reschedule access reviews)
- Monitor and provide report on Conditional access group exception groups
- Monitor and report on security alerts (Defender for Cloud) not managed by SG SOC.
Profile required
Qualifications:
- 4+ years of experience in managing cloud security expertise.
- Bachelor’s degree in computer science, Information Technology, or a related field.
- Professional certifications such as Microsoft Certified: Azure Security Engineer Associate, or similar.
- Proven experience in cloud security, with a focus on Azure.
- Strong understanding of security frameworks and compliance standards (e.g., ISO 27001, NIST).
- Excellent problem-solving skills and attention to detail.
- Strong communication and teamwork abilities.
Preferred Skills:
- Strong organizational, analytical and reporting as well as determination skills
- Previous experience of network security components administration
- Experience with security tools and technologies (e.g., SIEM, IDS/IPS, firewalls).
- Familiarity with DevSecOps practices.
Benefits:
- Opportunities for professional development and certification.
- Flexible working hours and remote work options.
Why join us
“We are committed to creating a diverse environment and are proud to be an equal opportunity employer. All qualified applicants receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability, age, or veteran status”
Business insight
At Societe Generale, we are convinced that people are drivers of change, and that the world of tomorrow will be shaped by all their initiatives, from the smallest to the most ambitious.
Whether you’re joining us for a period of months, years or your entire career, together we can have a positive impact on the future. Creating, daring, innovating and taking action are part of our DNA.
If you too want to be directly involved, grow in a stimulating and caring environment, feel useful on a daily basis and develop or strengthen your expertise, you will feel right at home with us!
Still hesitating?
You should know that our employees can dedicate several days per year to solidarity actions during their working hours, including sponsoring people struggling with their orientation or professional integration, participating in the financial education of young apprentices, and sharing their skills with charities. There are many ways to get involved.
We are committed to support accelerating our Group’s ESG strategy by implementing ESG principles in all our activities and policies. They are translated in our business activity (ESG assessment, reporting, project management or IT activities), our work environment and in our responsible practices for environment protection.