Turn this role into an interview — a resume and cover letter built around what this employer wants.
VirtusLab is partnering on a UK insurance sector security engagement to harden a hybrid Microsoft environment and unify security tooling across multiple entities.
You will help implement a Zero Trust architecture, strengthen detection and response, and coordinate with MDR providers to improve incident handling and policy standardization across global operations.
VirtusLab is a leading European software consulting and engineering company. Our mission is to craft clean code and practical solutions with precision and purpose. We foster a dynamic culture rooted in strong engineering, a sense of ownership, and transparency, empowering professionals to make a substantial impact in the software industry.
Shape the future of a rapidly scaling UK insurance leader. The scope of cooperation encompasses supporting security operations within a modern security stack and streamlining integration capabilities to unify a high-growth MGA and brokerage ecosystem. Core deliverables include contributing to incident response operations, managing AV/EDR mechanisms, developing and updating security policy frameworks, optimizing SIEM operations, and driving IAM hardening initiative.
Networking Security Regular
Azure Security Regular
Zero Trust Concepts Regular
Infrastructure as a Code Regular
Entra Internet Access & Private Access Nice to have
Project
Enterprise Security E2E
Establishing a modern, enterprise-grade security function for one of the UK’s fastest-growing Managing General Agents and brokerage groups. The end-client operates across three continents with entities spanning the UK, Europe, and Asia-Pacific, expanding dynamically through M&A operations.
The scope focuses on hardening a complex hybrid Microsoft environment, unifying fragmented security tooling across a multi-entity ecosystem, and driving a consistent, governed, and resilient security baseline across the entire Group.
Legacy, reactive security practices are being replaced with a Zero Trust architecture – deploying Microsoft’s full security stack across identity, endpoints, cloud apps, data, and network. The project aims at strengthening detection and response capabilities to protect a high-growth insurance business operating under Lloyd’s, UK GDPR, and MAS regulatory frameworks.
The primary objective is hardening the Group’s security posture across a multi-entity structure and building operational capabilities to detect, respond to, and recover from security events. Main areas of engagement:
Deploying and Optimizing Microsoft Defender XDR: Onboarding entities to Defender for Endpoint, Defender for Identity, and Defender for Cloud Apps, alongside integrating operational signals into Microsoft Sentinel as the central SIEM/SOAR platform.
Identity and Access Hardening: Implementing Zero Trust identity controls including phishing-resistant MFA, Privileged Identity Management (PIM), Conditional Access policies, and Active Directory security hardening across hybrid on-premises and Entra ID environments.
Security Operations & Incident Response: Co-operating with external MDR providers to optimize operational response workflows.
Security Policy Standardization: Developing, documenting, and monitoring compliance with security baselines, configuration standards, and control frameworks across all Group entities worldwide.
Cloud and SaaS Security Governance: Securing M365, Azure, and the broader SaaS ecosystem through Purview data classification, DLP policies, MDCA session controls, and continuous posture management.
M&A Security Integration: Execution of a repeatable security onboarding framework for newly acquired entities during continuous business expansion.
The engagement takes place within a lean, agile project environment delivering complete security stack coverage across DevOps, Infrastructure Engineering, Security Engineering, and Business Analysis domains, requiring close cross-functional alignment with business stakeholders to facilitate effective knowledge transfer and strict integration with strategic goals.