At a Glance
- Tasks: Design and implement security controls for Azure cloud platforms while monitoring threats.
- Company: Simpson Associates, a Microsoft Solutions Partner dedicated to positive change through data.
- Benefits: Competitive salary, flexible working, and opportunities for professional growth.
- Why this job: Join a team recognised for innovation and make a real impact in cloud security.
- Qualifications: Experience with Microsoft Sentinel, KQL, and Azure security services required.
- Other info: Dynamic work environment with a focus on creativity and collaboration.
The predicted salary is between 36000 - 60000 £ per year.
Simpson Associates transforms raw data into actionable insights that drive positive change. Our Microsoft data expertise, specialist sector knowledge, and innovative advice are some of the reasons clients choose to work with us. Our mission is to help purpose-led organisations from both the public and private sectors harness data as a lever for change and enable them to realise business value more quickly. We provide a full range of services to support organisations on their data transformation journey, from advisory support and data strategy to developing Data & AI solutions and providing managed services.
We are a Microsoft Solutions Partner, holding specialisations in AI Platform on Microsoft Azure, Analytics on Microsoft Azure, Data Warehouse Migration to Microsoft Azure, and Migrate Enterprise Applications to Microsoft Azure. We also hold Solutions Partner designations in Data & AI (Azure), Digital & App Innovation (Azure), Infrastructure (Azure), and Security. We are proud to be recognised as the winner of the 2024 Microsoft Community Response Partner of the Year award, reflecting our dedication to using technology for positive change. Additionally, we are a Databricks partner and an IBM Gold Partner, specialising in Cognos Analytics and Planning Analytics.
With offices in York and Sheffield, and a team based throughout the UK, we champion creativity, innovation, and collaboration in the workplace.
The Role
A Cloud Platform Security Consultant to partner with our clients in designing, implementing, and maintaining security controls across their Azure cloud platforms.
Key Responsibilities
- Security Monitoring & Threat Detection
- Design and maintain security monitoring solutions using Microsoft Sentinel and other SIEM tools
- Develop and optimise KQL queries for threat hunting, detection rules, and analytics
- Investigate security incidents and coordinate response activities
- Map threats and detections to the MITRE ATT&CK framework
- Perform continuous threat intelligence analysis and proactive threat hunting
- Cloud Security Architecture
- Implement and maintain security controls across Azure landing zones and workloads
- Secure AI and machine learning workloads, including Azure OpenAI, Azure ML, and Cognitive Services
- Design and enforce network security policies using Azure Firewall, NSGs, and Private Link
- Implement identity and access management controls using Entra ID and conditional access
- Ensure compliance with relevant cyber security legislation (GDPR, NIS Directive, UK Cyber Essentials, etc.)
- Develop security automation workflows using Azure Logic Apps, Functions, and Sentinel playbooks
- Implement security controls as code (policy as code, infrastructure as code)
- Build automated security testing and validation pipelines
- Create custom connectors and integrations for security tooling
- Governance & Compliance
- Maintain security policies and standards aligned to industry frameworks
- Conduct security assessments and gap analyses
- Support audit and compliance activities for public sector clients
- Produce security documentation, reports, and technical guidance
Skills and Attributes Required
- Strong hands-on experience with Microsoft Sentinel including workbook creation, analytics rules, and automation
- Advanced Search Query Language proficiency, ideally KQL, for log analysis and threat hunting
- Deep knowledge of Azure security services (Defender for Cloud, Key Vault, Managed Identity, etc.)
- Experience with SIEM tools and security information management
- Understanding of the MITRE ATT&CK framework and its practical application
- Strong analytical skills with the ability to investigate complex security incidents
- Proven ability to develop automation solutions for security operations
- Knowledge of cyber security legislation and regulatory requirements (UK public sector experience advantageous)
- Experience with Azure DevOps, Infrastructure as Code (Terraform/Bicep)
- Experience securing AI workloads and understanding AI-specific threat vectors
- Experience in stakeholder management
- Experience in Project Management – Prince 2 or Agile Methodologies
Advantageous Qualifications and Skills
- Degree in Computer Science, Cyber Security, or related field (or equivalent experience)
- Industry certifications such as CISSP, CEH, GIAC, or Microsoft security certifications
- Microsoft security certifications (SC-200, SC-300, AZ-500)
- Knowledge of data platform security (Databricks, Synapse, Fabric)
- Experience with Microsoft Purview for data security, including Sensitive Information Types, DLP policies, and DSPM
- Familiarity with penetration testing and vulnerability management tools
- Experience working with NHS, police, or local government clients
- Understanding of FinOps and cloud cost optimisation
Simpson Associates reserves the right to close the recruitment process at any time.
Cloud Platform Security Consultant in Sheffield employer: Simpson Associates
Contact Detail:
Simpson Associates Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Cloud Platform Security Consultant in Sheffield
✨Tip Number 1
Network like a pro! Reach out to folks in the industry, attend meetups, and connect with people on LinkedIn. You never know who might have the inside scoop on job openings or can refer you directly.
✨Tip Number 2
Show off your skills! Create a portfolio or GitHub repository showcasing your projects, especially those related to Azure security. This gives potential employers a taste of what you can do beyond just a CV.
✨Tip Number 3
Prepare for interviews by practising common questions and scenarios specific to cloud security. Think about how you’d tackle real-world problems and be ready to discuss your thought process.
✨Tip Number 4
Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, we love seeing candidates who are genuinely interested in joining our team.
We think you need these skills to ace Cloud Platform Security Consultant in Sheffield
Some tips for your application 🫡
Tailor Your CV: Make sure your CV is tailored to the Cloud Platform Security Consultant role. Highlight your experience with Microsoft Sentinel, KQL, and Azure security services. We want to see how your skills align with what we do!
Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Share your passion for cloud security and how you can contribute to our mission at Simpson Associates. Let us know why you're excited about this opportunity!
Showcase Relevant Experience: When detailing your experience, focus on projects that involved security monitoring, threat detection, and compliance. We love seeing real-world examples of how you've tackled challenges in the past.
Apply Through Our Website: We encourage you to apply through our website for a smoother application process. It helps us keep everything organised and ensures your application gets the attention it deserves!
How to prepare for a job interview at Simpson Associates
✨Know Your Azure Security Inside Out
Make sure you brush up on your knowledge of Azure security services, especially Microsoft Sentinel and KQL. Be ready to discuss how you've used these tools in past projects, as well as any specific challenges you've faced and how you overcame them.
✨Understand the MITRE ATT&CK Framework
Familiarise yourself with the MITRE ATT&CK framework and be prepared to explain how it applies to threat detection and incident response. You might even want to bring examples of how you've mapped threats to this framework in your previous roles.
✨Showcase Your Automation Skills
Since automation is key in security operations, be ready to talk about any automation solutions you've developed. Highlight your experience with Azure Logic Apps and Infrastructure as Code, and think of specific instances where your automation efforts improved security processes.
✨Prepare for Scenario-Based Questions
Expect scenario-based questions that test your analytical skills and problem-solving abilities. Think through potential security incidents and how you would handle them, including the steps you'd take for investigation and response. This will show your practical understanding of the role.