Cloud Security Engineer
BH-56271
Posted: 28/07/2026
- Competitive
- Brussels, Belgium
- Contract/Freelance
Freelance Cloud Security Engineer – Brussels (Hybrid) Location Brussels, Belgium (Hybrid)
Contract Type Freelance / Contractor
Duration 12 months (with possible extensions)
Start Date ASAP
Overview We are looking for an experienced Cloud Security Engineer to support the design, implementation, and continuous improvement of cloud security across a modern Microsoft Azure environment. You will play a key role in securing cloud infrastructure, strengthening identity and access management, implementing security best practices, and supporting compliance initiatives.
This role requires strong technical expertise in Microsoft security technologies, cloud security architecture, and enterprise identity management.
Key Responsibilities
Contract Type Freelance / Contractor
Duration 12 months (with possible extensions)
Start Date ASAP
Overview We are looking for an experienced Cloud Security Engineer to support the design, implementation, and continuous improvement of cloud security across a modern Microsoft Azure environment. You will play a key role in securing cloud infrastructure, strengthening identity and access management, implementing security best practices, and supporting compliance initiatives.
This role requires strong technical expertise in Microsoft security technologies, cloud security architecture, and enterprise identity management.
Key Responsibilities
- Design, implement, and maintain cloud security solutions within Microsoft Azure.
- Configure and manage Microsoft Entra ID (Azure Active Directory) to support secure authentication and identity governance.
- Develop and maintain robust Identity and Access Management (IAM) policies using least privilege and Zero Trust principles.
- Implement Role-Based Access Control (RBAC) and Privileged Identity Management (PIM).
- Secure Azure resources including subscriptions, networking, storage, compute, and platform services.
- Deploy and manage cloud security controls using Microsoft Defender for Cloud.
- Configure Conditional Access, Multi-Factor Authentication (MFA), Identity Protection, and access reviews.
- Support security monitoring, threat detection, and incident response activities.
- Work closely with infrastructure, DevOps, and application teams to embed security into cloud deployments.
- Perform security assessments, risk analysis, and vulnerability remediation.
- Develop and maintain security documentation, standards, and operational procedures.
- Support compliance with industry standards and regulatory requirements.
- Strong experience securing Microsoft Azure environments.
- Deep understanding of Azure security architecture and native security services.
- Experience implementing Zero Trust security principles.
- Knowledge of cloud governance, landing zones, and security baselines.
- Experience with Infrastructure as Code (Terraform, ARM, or Bicep) is highly desirable.
- Extensive experience with Microsoft Entra ID.
- Strong knowledge of Identity and Access Management (IAM).
- Experience with:
- Azure AD Connect / Entra Connect
- Conditional Access
- Multi-Factor Authentication (MFA)
- Single Sign-On (SSO)
- Identity Protection
- Privileged Identity Management (PIM)
- Access Reviews
- Entitlement Management
- Identity Governance
- Role-Based Access Control (RBAC)
- Azure AD Connect / Entra Connect
- Microsoft Defender for Cloud
- Microsoft Defender for Endpoint
- Microsoft Defender for Identity
- Microsoft Defender for Office 365
- Microsoft Sentinel (SIEM/SOAR)
- Microsoft Purview
- Microsoft Intune
- Microsoft Security Copilot (desirable)
- Cloud security posture management (CSPM)
- Cloud workload protection (CWPP)
- Key Vault
- Managed Identities
- Azure Firewall
- Web Application Firewall (WAF)
- Azure Front Door
- Azure Application Gateway
- Network Security Groups (NSGs)
- Private Link
- Virtual Networks (VNets)
- Azure DDoS Protection
- Secure networking principles
- Secrets and certificate management
- Encryption at rest and in transit
- ISO 27001
- NIST Cybersecurity Framework
- CIS Benchmarks
- Zero Trust Architecture
- GDPR
- Microsoft Cloud Security Benchmark
- Azure DevOps
- GitHub Actions
- CI/CD security
- SAST / DAST
- Container security
- Kubernetes (AKS)
- Docker
- Terraform
- PowerShell
- Azure CLI
- 8+ years of experience in Cloud Security or Cyber Security Engineering.
- 5+ years of hands-on experience with Microsoft Azure.
- Proven experience implementing enterprise IAM solutions.
- Experience working in complex enterprise environments.
- Strong troubleshooting and analytical skills.
- Excellent communication and stakeholder management skills.
- Microsoft Certified: Azure Security Engineer Associate (AZ-500)
- Microsoft Certified: Identity and Access Administrator Associate (SC-300)
- Microsoft Certified: Cybersecurity Architect Expert (SC-100)
- Microsoft Certified: Security Operations Analyst (SC-200)
- Microsoft Certified: Azure Administrator (AZ-104)
- CISSP
- CCSP
- CISM
- CompTIA Security+
- English and Dutch or French (mandatory)
- Strong problem-solving mindset.
- Excellent communication and collaboration skills.
- Ability to work independently in a fast-paced environment.
- Proactive approach to identifying and mitigating security risks.
- Passion for cloud security and emerging technologies.
- Experience in regulated sectors such as financial services, public sector, healthcare, or telecommunications.
- Experience with Microsoft 365 security and compliance.
- Experience with hybrid cloud environments.
- Knowledge of AWS or Google Cloud Platform (GCP).
- Experience with SOC operations or incident response.