Staff Platform Engineer - Azure

Shine

Madrid

Híbrido

EUR 90.000 - 130.000

Jornada completa

hace 18 horas
Sé de los primeros/as/es en solicitar esta vacante
Generador de candidaturas

Consigue una respuesta de este empleador — un currículum y una carta de presentación adaptados exactamente a lo que busca para contratar.

Supera los filtros ATS

Descripción de la vacante

Shine's Infrastructure & IT unit seeks a Staff Platform Engineer to own Azure cloud security and contribute to multi-cloud strategy. You’ll define architecture, implement controls as code, and partner with platform teams to enforce secure defaults.

You will collaborate with AWS/GCP security and drive CNAPP onboarding, threat modelling, and compliance automation across Europe, with remote/hub options including Madrid.

Formación

  • 8+ years of infrastructure or security engineering experience, with deep hands‑on Azure security expertise at production scale.
  • Ability to operate at staff level — technical authority, cross‑team influence, and sound judgment.
  • Strong Entra ID security expertise: conditional access, PIM, workload identity, federation hardening.
  • Proven experience implementing Azure security controls: Defender for Cloud, Sentinel, Azure Policy, network security, Key Vault.
  • Infrastructure‑as‑code for security (Terraform) — policy‑as‑code, security modules, CI/CD integration.
  • Threat modelling capability — reasoning about cloud attack paths, privilege escalation, and lateral movement.
  • Practical compliance framework implementation (ISO 27001, GDPR, DORA, or similar).
  • CNAPP/CSPM tooling experience (Wiz, Cortex Cloud, Orca, Prisma Cloud, Defender CSPM).
  • Familiarity with observability platforms.
  • Working knowledge of at least one other CSP (AWS or GCP) from a security perspective.
  • Security detection experience with a SIEM (CrowdStrike, Splunk, Elastic, Sentinel).
  • Ability to influence without authority — setting standards across teams.
  • Excellent technical communication in English.

Responsabilidades

  • Define security architecture for Azure estate — policy guardrails, network security, encryption, identity hardening, and secure defaults.
  • Own the security of our Azure landing zone — secure platform, migration readiness and posture validation.
  • Own Entra ID security — conditional access, PIM, workload identity governance, federation hardening with Okta.
  • Co‑own CNAPP onboarding — posture management policies, prioritisation, and workflow integration.
  • Build and maintain security controls as code using Terraform and Azure Policy — CIS baselines, automated remediation, CI/CD integration.
  • Ensure on‑prem → Azure migrations happen securely — risk assessment, controls during, posture validation post.
  • Threat modelling for Azure infrastructure designs to identify attack paths and prioritise controls.
  • Automate compliance evidence collection for ISO 27001, GDPR, and DORA.
  • Align Azure security patterns with AWS and GCP for cohesive multi‑cloud posture.
  • Enable teams: security design reviews, paved‑road patterns, documentation, and office hours.

Conocimientos

Azure security
Staff leadership
Entra ID
Defender for Cloud
Sentinel
Azure Policy
Key Vault
Terraform
CI/CD
Threat modelling
ISO 27001
GDPR
DORA
CNAPP/CSPM
AWS/GCP security
SIEM
Communication in English

Herramientas

Wiz
Cortex Cloud
Orca
Prisma Cloud
Defender CSPM

Descripción del empleo

Shine is the financial copilot for entrepreneurs and small business owners.

Founded by serial entrepreneurs Rico Andersen and Martin Hegelund, Shine is a leading European fintech unicorn on a mission to restore the joy of running a business, by ending wasted time on financial admin. Shine offers a connected solution for invoicing, accounting, payroll, business accounts, payments, and financing, meaning business owners can focus their energy on growing a healthy business, not held back by manual admin.

Part of something bigger

Today we’re part of Cegid, a European leader in cloud software for finance and accounting. Together we’re building Europe’s leading financial copilot for small businesses and their accountants.

Shine already supports more than 400,000 small businesses. As part of Cegid, we now reach over one million small businesses and 15,000 accountants across Europe.

We’re a multicultural team working from France, Germany, Denmark and the Netherlands, Spain,Portugal

Your Hiring Experience Matters

Just as we respect our customers’ time, we respect yours. Your experience with Shine and Cegid should feel simple, transparent and genuinely supportive.

If this sounds like somewhere you want to grow, we’d love to hear from you.

The Infrastructure & IT unit at Shine

Our Infrastructure & IT unit builds and operates the cloud platforms, developer tooling, and IT services that underpin every product Shine ships. We run multiple cloud teams (AWS, GCP, Azure), Engineering Efficiency, and IT operations. Infrastructure security is a dedicated function within this unit — senior engineers who own the security posture of our cloud estate as a traversal role across all teams.

Your role as a Staff Platform Engineer (Infrastructure Security)

We’re looking for a Staff Platform Engineer to own the security of our Azure cloud environment and contribute to multi-cloud security strategy. Azure is a strategic platform for the group, driven by recent acquisitions, and it needs the same security depth we are already building on AWS.

This is a hands‑on, senior IC role. You will define security architecture, build controls as code, harden identity, implement detection, and partner with platform teams to make secure defaults the path of least resistance. You work alongside a peer Staff Platform Engineer who covers AWS and IT, sharing cross‑cloud strategy while owning separate execution domains.

Your Responsibilities Will Include
  • Define and implement the security architecture for our Azure estate — policy guardrails, network security, encryption, identity hardening, and secure defaults.
  • Own the security of our Azure landing zone — the platform teams build it, you ensure it’s built securely and that workloads migrate onto a secure foundation.
  • Own Entra ID security — conditional access, Privileged Identity Management, workload identity governance, federation hardening with Okta, and tenant security.
  • Co‑own the onboarding and configuration of our CNAPP platform (e.g. Wiz, Cortex Cloud, Orca, or FortiCNAPP) — posture management policies, finding prioritisation, and workflow integration.
  • Build and maintain security controls as code using Terraform and Azure Policy — CIS baselines, automated remediation, integrated into CI/CD.
  • Ensure on‑prem → Azure migrations happen securely — risk assessment pre‑migration, controls during, posture validation post.
  • Conduct threat modelling for Azure infrastructure designs. Identify attack paths and prioritise controls based on actual risk.
  • Automate compliance evidence collection for ISO 27001, GDPR, and DORA.
  • Align Azure security patterns with AWS and GCP to maintain a coherent multi‑cloud security posture. GCP security coverage will be shared with your peer as it matures.
  • Enable teams: security design reviews, paved‑road patterns, documentation, and office hours so cloud teams can self‑serve securely.

Full remote in one of our European hubs (Germany, Netherlands, Denmark, Spain, Protugal), or Hybrid in one of our Hubs (Berlin, Amsterdam, Copenhagen, Madrid, Porto)

Required
About you
  • 8+ years of infrastructure or security engineering experience, with deep hands‑on Azure security expertise at production scale.
  • Ability to operate at staff level — technical authority, cross‑team influence, and sound judgment. Prior staff/principal title not required, but you must demonstrate this level of impact.
  • Strong Entra ID security expertise: conditional access, PIM, workload identity, federation hardening.
  • Proven experience implementing Azure security controls: Defender for Cloud, Sentinel, Azure Policy, network security, Key Vault.
  • Infrastructure‑as‑code for security (Terraform) — policy‑as‑code, security modules, CI/CD integration.
  • Threat modelling capability — reasoning about cloud attack paths, privilege escalation, and lateral movement.
  • Practical compliance framework implementation (ISO 27001, GDPR, DORA, or similar) — actual control automation, not just awareness.
  • CNAPP/CSPM tooling experience (Wiz, Cortex Cloud, Orca, Prisma Cloud, Defender CSPM, or similar).
  • Familiarity with observability platforms.
  • Working knowledge of at least one other CSP (AWS or GCP) from a security perspective.
  • Security detection experience with a SIEM (e.g. CrowdStrike, Splunk, Elastic, or native solutions like Sentinel or Google Security Operations).
  • Ability to influence without authority — setting standards across teams.
  • Excellent technical communication in English.
Preferred
  • Experience in fintech, banking, or regulated financial services.
  • Okta + Entra ID federation security and cross‑IdP governance.
  • Post‑acquisition security integration experience (tenant consolidation, inherited risk).
  • DORA implementation experience.
  • GCP security experience (future expansion area).
  • On‑prem / hybrid security experience.
  • Supply chain security / CI/CD pipeline security.
  • Relevant certifications: AZ-500, SC-300, AZ-305.
Ways of Working
  • Senior IC who leads through code, designs, reviews, and enablement — not standalone documents.
  • Traversal role across all cloud teams — you partner with them, not sit above them.
  • Tight collaboration with the Azure platform teams: you build a secure platform with them.
  • Pragmatic: the secure path should be the easy path. Controls that teams bypass are not controls.
  • Peer relationship with the AWS/IT Staff Engineer: shared strategy, separate domains.
  • Success is measured by teams making good security decisions without you — build capability, not dependency.
What Success Looks Like

90 Days: Assessed the current Azure security posture across all subscriptions. Defined the security architecture for the landing zone. Started CNAPP onboarding and initial policy configuration. First security controls deployed. Relationships built with all cloud teams.

6 Months: Landing zone security live — workloads migrating securely. CNAPP operationalised. Entra ID hardened. Security detection covering critical attack paths. Cross‑cloud security standards aligned with AWS. Cloud teams self‑serving on T2/T3 security decisions.

12 Months: Azure security at parity with AWS. Multiple workloads migrated securely. CNAPP providing continuous posture management. Compliance evidence automated. Teams making fewer security decisions that need your involvement. Contributing to GCP security expansion.

Equal Opportunity Employer

We follow the principle of equal treatment to consider all job applicants and do not discriminate based on their gender, sexual orientation, color, racial or ethnic origin, religion, disability, etc. as per applicable law.

Our recruitment process
  • Recruiter screen, have a initial conversation with Talent Acquisition
  • Hiring manager interview, dive deeper into the technical challenges of the team
  • Case interview, show your skills to one of your peers
  • Stakeholder interview, get a better idea of the collaborative environment
  • A personality assessment to round things off.
Consigue la evaluación confidencial y gratuita de tu currículum.
o arrastra y suelta tu archivo aquí
Similar jobs

Puestos de trabajo similares que vale la pena comparar

(Senior) Cloud Infrastructure Engineer - AWS · GCP · Azure
(Senior) Cloud Infrastructure Engineer - AWS · GCP · Azure

Shine • Madrid

Híbrido
EUR 55.000 - 75.000
Cyber Security Manager (Incident Response)
Cyber Security Manager (Incident Response)

Shine • Las Rozas de Madrid

Híbrido
EUR 90.000 - 120.000
Staff Software Engineer Product & Technology · Porto, Madrid
Staff Software Engineer Product & Technology · Porto, Madrid

Nabla • Madrid

Presencial
EUR 90.000 - 130.000
Staff Azure Platform Security Engineer
Staff Azure Platform Security Engineer

Shine • Madrid

Híbrido
EUR 90.000 - 130.000
Staff Software Engineer
Staff Software Engineer

Shine • Madrid

Presencial
EUR 90.000 - 120.000
Senior Tech Recruiter – Iberian Markets (m/f/d)
Senior Tech Recruiter – Iberian Markets (m/f/d)

Shine • Madrid

Presencial
EUR 70.000 - 110.000
Business Unit Lead - ERP, Spain
Business Unit Lead - ERP, Spain

Shine • Las Rozas de Madrid

Presencial
EUR 90.000 - 130.000
Cloud Security Engineer
Cloud Security Engineer

Montash • Barcelona

Híbrido
EUR 70.000 - 95.000
Health insurance
Learning budget
Flexible working
Business Unit Lead - ERP, Spain
Business Unit Lead - ERP, Spain

Shine • Madrid

Presencial
EUR 120.000 - 160.000
Senior People Programs Manager (m/f/d)
Senior People Programs Manager (m/f/d)

Shine • Madrid

Híbrido
EUR 90.000 - 130.000