Security Operations Engineer

BIMCO

København

Hybrid

DKK 647,000 - 759,000

Full time

13 days ago
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

BIMCO is seeking a hands-on Security Operations Engineer to strengthen cybersecurity, cloud operations and operational resilience. You will work across Microsoft 365, Azure, identity, endpoints and secure software delivery to implement concrete controls and measurable improvements.

This role emphasizes investigation, configuration improvement, automation and production readiness to keep systems secure and resilient for a global maritime audience.

Qualifications

  • Five+ years in security engineering, cloud/infra operations or both.
  • Strong production experience with Microsoft Defender, Intune, Entra ID and Microsoft 365 security.
  • Experience with identity security, Conditional Access and privileged access.
  • Involvement in security investigations or incident response.
  • Knowledge of Azure networking, logging, monitoring and workload security.
  • Ability to create runbooks and repeatable operational processes.
  • Scripting/automation, preferably PowerShell.

Responsibilities

  • Monitor and respond to security alerts and incidents.
  • Operate and improve controls across Defender, Intune, Entra ID, 365 and Azure.
  • Support Conditional Access and privileged access controls.
  • Use KQL and Log Analytics for investigation and reporting.
  • Develop and maintain incident response playbooks and runbooks.
  • Automate recurring security and operational tasks via PowerShell or APIs.
  • Collaborate with IT, Cloud Architecture, Compliance and Dev teams.

Skills

Security engineering
Cloud operations
Microsoft Defender
Intune
Entra ID
Microsoft 365 security
Incident response
PowerShell
Automation

Tools

Terraform
GitHub Actions
Azure

Job description

PLEASE NOTE: CV + motivation letter are required!

Who are we

BIMCO is the world's largest international shipping association, representing shipowners, operators, managers, brokers and agents across the globe. For more than a century, we have helped shape the maritime industry by developing standards, contracts, insights and, more recently, digital solutions that support global trade.

In an industry where technology, AI and digital innovation are continuously reshaping how organisations operate, staying secure, adaptable and resilient is more important than ever. At BIMCO, we embrace modern technologies and emerging digital capabilities to deliver better services to our global workforce, members and customers.

Our IT team develops and maintains the systems, cloud platforms and digital products that support key business operations across the organisation. Security is a fundamental part of everything we do. As our technology landscape continues to evolve, we are investing in stronger cybersecurity, operational resilience and cloud security capabilities to protect our people, systems and data.

We are a collaborative, international workplace where expertise is valued, ideas are encouraged and people are trusted to take ownership. Working in a lean and highly skilled team, you will have the opportunity to influence security operations, improve processes and make a visible impact across the organisation. If you enjoy solving complex challenges, working with modern Microsoft technologies and helping build a secure and resilient digital environment, we would love to hear from you.

The role

BIMCO is looking for a hands-on Security Operations Engineer to strengthen our cybersecurity, cloud operations and operational resilience capability.

You will work across Microsoft 365, Azure, identity, endpoints and secure software delivery. You will turn security and architecture requirements into working controls, reliable operational processes and measurable improvements.

This is not a policy-only or monitoring-only role. You will investigate incidents, improve configurations, automate recurring work, create runbooks and help ensure that technology is secure, supportable and ready for production.

Key responsibilities
  • Monitor, investigate and respond to security alerts and operational incidents.
  • Operate and improve controls across Microsoft Defender, Intune, Entra ID, Microsoft 365 and Azure.
  • Support Conditional Access, privileged access, endpoint compliance and identity governance.
  • Use KQL, Defender XDR and Log Analytics for investigation, threat hunting and reporting.
  • Support vulnerability management, configuration reviews and verified remediation.
  • Maintain incident-response playbooks, operational runbooks and recovery procedures.
  • Automate recurring security and operational activities using PowerShell, APIs or similar tooling.
  • Support Azure networking, Front Door, web application firewall, logging and workload security.
  • Help integrate security and operational controls into GitHub workflows and delivery pipelines.
  • Contribute to technical production readiness, business continuity and disaster recovery testing.
  • Produce reliable technical evidence for ISO 27001 and SOC 2 controls.
  • Work closely with IT Operations, Cloud Architecture, Compliance, Development and specialist partners.
Your experience

You should have:

  • At least five years of hands-on experience in security engineering, cloud operations, infrastructure operations or a combination of these.
  • Strong production experience with Microsoft Defender, Intune, Entra ID and Microsoft 365 security.
  • Practical experience with identity security, Conditional Access and privileged access.
  • Direct involvement in security investigations or operational incident response.
  • Working knowledge of Azure networking, logging, monitoring and workload security.
  • Experience creating runbooks, technical documentation and repeatable operational processes.
  • Scripting or automation experience, preferably PowerShell.
  • The ability to troubleshoot across identity, endpoint, cloud, application and network layers.
  • Clear judgement about when to act independently and when to expand material risk.

Experience with Microsoft Sentinel, KQL, Azure Front Door, GitHub Enterprise, GitHub Actions, Terraform, DevSecOps, vulnerability management, ISO 27001 or SOC 2 would be valuable.

Certifications are welcome, but they do not substitute for practical experience and sound technical judgement.

The person we are looking for

You are a pragmatic engineer who can investigate an alert, correct a configuration, review a deployment, write a runbook and explain the resulting risk in plain language.

You follow issues through to verified closure, look beyond immediate symptoms and leave systems easier for others to operate. You are comfortable working across technical disciplines but are clear about the limits of your expertise and when specialist input is required.

What success looks like

During your first year:

  • Security events have clear triage, ownership and escalation.
  • Identity, endpoint and cloud controls are operated consistently.
  • Material vulnerabilities and configuration findings are tracked to verified closure.
  • Critical incident and recovery procedures are documented and tested.
  • Security and operational requirements are included earlier in technology delivery.
  • Recurring work is increasingly supported by automation and reliable runbooks.
  • Technical audit evidence can be produced without last-minute reconstruction.
  • Routine security operations no longer depend on a small number of senior specialists.
Practical information

Location: Bagsværd, Denmark

Working model: Hybrid

Employment type: Full-time

Reporting to: Chief Information Officer

Start Date: As soon as possible

Indicative salary: DKK 58,000 to 68,000 per month, including employer pension and benefits

Language: English

Deadline for applying: 11th Oct 2026

Please note that we process your personal data in accordance with our Privacy Notice for job applicants, which outlines how we collect, use, and protect your information (please see our website: About us – Working at BIMCO)

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

IT Operations Technician
IT Operations Technician

Dansk Sprogskole • Frederiksberg

On-site
DKK 450,000 - 600,000
Medical cover
Company pension
Senior Microsoft 365 Specialist
Senior Microsoft 365 Specialist

Kamstrup • Denmark

On-site
DKK 600,000 - 900,000
Flexible hours
Canteen
Fitness facilities
+5
Senior M365 Security Engineer
Senior M365 Security Engineer

Truesec • Region Hovedstaden

On-site
DKK 800,000 - 1,000,000
Information Security & Compliance Manager
Information Security & Compliance Manager

loyaltykey • København

On-site
DKK 900,000 - 1,100,000
Health insurance
Attractive benefits
Chief Consultant Cybersecurity New København, Capital Region of Denmark, Denmark
Chief Consultant Cybersecurity New København, Capital Region of Denmark, Denmark

Greenhouse Software, Inc. • København

On-site
DKK 900,000 - 1,200,000
Bonus
Lunch program
Office snacks
+4
Chief Consultant Cybersecurity
Chief Consultant Cybersecurity

Swiss IT Security Group AG • København

On-site
DKK 1,100,000 - 1,700,000
Bonus scheme
Cantine with fresh lunch
Fresh bread and pastries at the office
+6
Chief Consultant Cybersecurity
Chief Consultant Cybersecurity

SITS Group • Københavns Kommune

On-site
DKK 900,000 - 1,200,000
Bonus scheme
Cantine with daily lunch
Bread & pastries on office days
+5
Microsoft Operations Engineer
Microsoft Operations Engineer

Netcompany • Aarhus, Aalborg, København

On-site
DKK 650,000 - 850,000
Senior Manager, Software Cyber Security
Senior Manager, Software Cyber Security

Worklane GmbH • Aarhus

On-site
DKK 1,200,000 - 1,800,000
Flex Abroad Program
Extensive onboarding
Team-oriented work culture
+9
Senior Manager, Software Cyber Security
Senior Manager, Software Cyber Security

BEUMER Group A/S • Aarhus

On-site
DKK 850,000 - 1,200,000