Sr. Azure Security Engineer
Job Description
Design and implement Azure security architectures aligned with FSI regulatory requirements including SOX, PCI-DSS, GLBA, and FFIEC guidelinesLead Azure Security Center / Microsoft Defender for Cloud configuration, policy management, and continuous monitoringOwn and mature Azure Active Directory (Entra ID) security posture — PIM, Conditional Access, MFA, identity governance, and privileged identity managementArchitect and enforce Azure Policy, Blueprints, and Management Group structures to ensure least-privilege and compliant deploymentsLead implementation and management of Azure Sentinel SIEM/SOAR — develop custom detection rules, playbooks, and automation workflowsDrive network security design: NSGs, Azure Firewall, DDoS protection, Private Endpoints, and hub-spoke architecturesPerform threat modeling, risk assessments, and security reviews for new Azure workloads and platform changesManage secrets, keys, and certificate lifecycle via Azure Key Vault; ensure HSM integration for regulated workloadsLead response to cloud-native security incidents, conducting root cause analysis and driving remediationCollaborate with DevSecOps teams to embed security into CI/CD pipelines (GitHub Actions, Azure DevOps)Produce executive-level reporting on cloud security KPIs, control effectiveness, and risk postureMentor junior engineers and contribute to team capability building and knowledge sharing
Qualification
7+ years of information security experience, with 4+ years focused on Azure cloud security in a regulated industryDeep technical expertise across core Azure security services: Defender for Cloud, Sentinel, Entra ID, Key Vault, Firewall, NSGs, PolicyStrong understanding of financial services compliance frameworks: PCI-DSS, SOX, GLBA, FFIEC, NIST CSFProficiency in scripting and automation: PowerShell, Python, Bicep/ARM templates, TerraformExperience with zero-trust architecture implementation in enterprise Azure environmentsSolid understanding of PKI, cryptographic standards, and secrets managementBachelor's degree in Computer Science, Information Security, or equivalent practical experience Preferred QualificationsMicrosoft Certified: Azure Security Engineer Associate (AZ-500) — requiredMicrosoft Certified: Security Operations Analyst (SC-200) — strongly preferredAdditional certifications: CISSP, CISM, CCSP, CEHExperience with DORA, MAS TRM, or OCC guidelinesFamiliarity with multi-cloud security strategies and cross-cloud SIEM integrationsPrior experience in investment banking, retail banking, or insurance environments
About The Global Business Services
A dynamic offshore hub based in the Philippines, serving as a vital extension of its parent organization’s operations. As an internal support center, it delivers high-impact services across multiple departments, including technology, compliance, finance, and operations, supporting various lines of business.