Security Engineer Poland
Zapisz tę ofertę pracy i uporządkuj wyszukiwanie
Utwórz bezpłatne konto, aby zapisywać oferty pracy, tworzyć alerty i wracać do tego ogłoszenia ze swojego pulpitu nawigacyjnego.
VirtusLab is a leading European software consulting and engineering company. Our mission is to craft clean code and practical solutions with precision and purpose. We foster a dynamic culture rooted in strong engineering, a sense of ownership, and transparency, empowering professionals to make a substantial impact in the software industry.
About the Engagement
Shape the future of a rapidly scaling UK insurance leader. The scope of cooperation encompasses supporting security operations within a modern security stack and streamlining integration capabilities to unify a high-growth MGA and brokerage ecosystem. Core deliverables include contributing to incident response operations, managing AV/EDR mechanisms, developing and updating security policy frameworks, optimizing SIEM operations, and driving IAM hardening initiative.
Networking Security Regular
Azure Security Regular
Zero Trust Concepts Regular
Infrastructure as a Code Regular
Entra Internet Access & Private Access Nice to have
Project
Enterprise Security E2E
Project Scope
Establishing a modern, enterprise-grade security function for one of the UK’s fastest-growing Managing General Agents and brokerage groups. The end-client operates across three continents with entities spanning the UK, Europe, and Asia-Pacific, expanding dynamically through M&A operations.
The scope focuses on hardening a complex hybrid Microsoft environment, unifying fragmented security tooling across a multi-entity ecosystem, and driving a consistent, governed, and resilient security baseline across the entire Group.
Legacy, reactive security practices are being replaced with a Zero Trust architecture – deploying Microsoft’s full security stack across identity, endpoints, cloud apps, data, and network. The project aims at strengthening detection and response capabilities to protect a high-growth insurance business operating under Lloyd’s, UK GDPR, and MAS regulatory frameworks.
Key Deliverables & Challenges
The primary objective is hardening the Group’s security posture across a multi-entity structure and building operational capabilities to detect, respond to, and recover from security events. Main areas of engagement:
Deploying and Optimizing Microsoft Defender XDR: Onboarding entities to Defender for Endpoint, Defender for Identity, and Defender for Cloud Apps, alongside integrating operational signals into Microsoft Sentinel as the central SIEM/SOAR platform.
Identity and Access Hardening: Implementing Zero Trust identity controls including phishing-resistant MFA, Privileged Identity Management (PIM), Conditional Access policies, and Active Directory security hardening across hybrid on-premises and Entra ID environments.
Security Operations & Incident Response: Co-operating with external MDR providers to optimize operational response workflows.
Security Policy Standardization: Developing, documenting, and monitoring compliance with security baselines, configuration standards, and control frameworks across all Group entities worldwide.
Cloud and SaaS Security Governance: Securing M365, Azure, and the broader SaaS ecosystem through Purview data classification, DLP policies, MDCA session controls, and continuous posture management.
M&A Security Integration: Execution of a repeatable security onboarding framework for newly acquired entities during continuous business expansion.
The engagement takes place within a lean, agile project environment delivering complete security stack coverage across DevOps, Infrastructure Engineering, Security Engineering, and Business Analysis domains, requiring close cross-functional alignment with business stakeholders to facilitate effective knowledge transfer and strict integration with strategic goals.
Required Technical Expertise & Capabilities
- 5+ years of track record in Cloud/SaaS Infrastructure Security consulting or engineering engagements.
- Hands-on expertise with Microsoft Security Stack including Entra ID, Microsoft Defender, Intune, Network Security, and Cloud Security.
- Proficiency in security practices: incident response, security analysis, and posture hardening.
- Demonstrated experience in securing and maintaining Microsoft Stack services.
- Experience with insurance infrastructure ecosystems is a plus.
- Formal background in Computer Science, STEM, or equivalent practical industry expertise.
- English communication skills at B2+ level or higher.
- Familiarity with security standards and compliance frameworks such as ISO 27001 / SOC-2 is advantageous.
A few perks of being with us
- Building tech community
- Home office reimbur