About the Role
We are looking for a Staff Platform Engineer to own the security of our Azure cloud environment and contribute to multi-cloud security strategy. This is a hands-on, senior individual contributor role where you will define security architecture, build controls as code, harden identity, implement detection, and partner with platform teams to make secure defaults the path of least resistance.
Responsibilities
- Define and implement the security architecture for our Azure estate, including policy guardrails, network security, encryption, identity hardening, and secure defaults.
- Own the security of our Azure landing zone, ensuring workloads migrate onto a secure foundation.
- Own Entra ID security, including conditional access, Privileged Identity Management, workload identity governance, federation hardening with Okta, and tenant security.
- Co-own the onboarding and configuration of our CNAPP platform, focusing on posture management policies, finding prioritization, and workflow integration.
- Build and maintain security controls as code using Terraform and Azure Policy, including CIS baselines and automated remediation integrated into CI/CD.
- Ensure on-prem to Azure migrations happen securely, including risk assessment, control implementation, and posture validation.
- Conduct threat modeling for Azure infrastructure designs, identifying attack paths and prioritizing controls based on actual risk.
- Automate compliance evidence collection for ISO 27001, GDPR, and DORA.
- Align Azure security patterns with AWS and GCP to maintain a coherent multi-cloud security posture.
- Enable teams through security design reviews, paved-road patterns, documentation, and office hours for secure self-service.
Requirements
- 8+ years of infrastructure or security engineering experience, with deep hands-on Azure security expertise at production scale.
- Ability to operate at staff level, demonstrating technical authority, cross-team influence, and sound judgment.
- Strong Entra ID security expertise: conditional access, PIM, workload identity, federation hardening.
- Proven experience implementing Azure security controls: Defender for Cloud, Sentinel, Azure Policy, network security, Key Vault.
- Infrastructure-as-code for security (Terraform), including policy-as-code, security modules, and CI/CD integration.
- Threat modeling capability to reason about cloud attack paths, privilege escalation, and lateral movement.
- Practical compliance framework implementation (ISO 27001, GDPR, DORA, or similar) with actual control automation.
- CNAPP/CSPM tooling experience (Wiz, Cortex Cloud, Orca, Prisma Cloud, Defender CSPM, or similar).
- Familiarity with observability platforms.
- Working knowledge of at least one other CSP (AWS or GCP) from a security perspective.
- Security detection experience with a SIEM (e.g. CrowdStrike, Splunk, Elastic, or native solutions like Sentinel or Google Security Operations).
- Ability to influence without authority and set standards across teams.
- Excellent technical communication in English.
Skills
- Azure Security
- Entra ID Security
- Conditional Access
- Privileged Identity Management (PIM)
- Workload Identity Governance
- Okta Federation
- Terraform
- Azure Policy
- Threat Modeling
- ISO 27001
- GDPR
- DORA
- CNAPP
- CSPM
- Observability Platforms
- AWS Security
- GCP Security
- SIEM
- CrowdStrike
- Splunk
- Elastic
- Sentinel
- Google Security Operations
- CI/CD
- Infrastructure as Code
Location
- Germany
- Netherlands
- Denmark
- Spain
- Portugal
- Berlin
- Amsterdam
- Copenhagen
- Madrid
- Porto
Work Type
- Full remote
- Hybrid
Experience Level
- Staff Level
- 8+ years of infrastructure or security engineering experience
Education Level
- AZ-500 certification
- SC-300 certification
- AZ-305 certification
About the Company
- Shine is the financial copilot for entrepreneurs and small business owners, aiming to restore the joy of running a business by ending wasted time on financial admin.
- Shine offers a connected solution for invoicing, accounting, payroll, business accounts, payments, and financing.
- Shine is part of Cegid, a European leader in cloud software for finance and accounting, together building Europe's leading financial copilot for small businesses and their accountants.
- Shine already supports more than 400,000 small businesses and as part of Cegid, reaches over one million small businesses and 15,000 accountants across Europe.
- We're a multicultural team working from France, Germany, Denmark and the Netherlands, Spain, Portugal.
Equal Opportunity
- We follow the principle of equal treatment to consider all job applicants and do not discriminate based on their gender, sexual orientation, color, racial or ethnic origin, religion, disability, etc. as per applicable law.
