We're hiring a Cloud Security Engineer to strengthen and operate our Microsoft cloud security stack. This is a hands-on engineering role: you'll build, tune, and maintain the security and compliance controls that protect organizational and customer data while bringing a red-team mindset to find weaknesses before attackers do.
🏢 About Patch My PC
At Patch My PC, we exist to improve lives. What started as a free tool to keep apps updated has grown into a trusted enterprise solution that helps IT and Security teams automate, manage, deploy, and report on third-party updates in Microsoft ConfigMgr, Intune, and WSUS. Our fully remote crew of 150 GIF-loving humans supports over 10,000 customers and more than 32 million devices. We make patching easier, boost security, and give IT teams their time back.
Our core values guide how we work, how we treat each other, and how we grow. They keep us focused on what matters most. We're here to improve the lives of our customers, our team members, and our communities.
🎯 The Role
This role sits at the intersection of security engineering, cloud operations, and governance, ideal for someone who likes to build controls, break assumptions, and measurably improve security posture.
✅ Key Responsibilities
Design, deploy, configure, and maintain Microsoft cloud security and compliance technologies, including Microsoft Purview, Microsoft Defender for Cloud, Azure Log Analytics, Microsoft Entra ID, Privileged Identity Management (PIM), and Identity Governance.
Engineer and continuously improve technical security controls across Microsoft 365 and Azure.
Automate recurring security and compliance tasks to reduce manual effort and drift.
Monitor security and compliance posture, and drive continuous-improvement initiatives with measurable outcomes.
Build, deploy, and maintain Data Loss Prevention (DLP) policies across the organisation.
Monitor AI technology usage and engineer controls to mitigate data exposure, information leakage, and inappropriate use.
Assess emerging AI-related threats and implement appropriate governance and technical guardrails.
Apply a red-team mindset to proactively identify weaknesses in systems, configurations, processes, and controls.
Conduct security reviews, exposure assessments, and control-effectiveness evaluations.
Produce clear, concise reports for leadership covering findings, risk assessments, control gaps, and prioritized remediation recommendations.
Track remediation and support stakeholders in implementing corrective actions.
Use Azure Log Analytics and security tooling (e.g., KQL queries, alerting) to detect suspicious activity, trends, and compliance issues.
Support security investigations and incident response, including analysis, containment, and remediation recommendations.
Represent security and compliance in customer calls covering governance, data protection, and control topics.
Support the compliance team on customer questionnaires, assessments, and security reviews.
Communicate technical concepts effectively to both technical and non-technical audiences.
📌 Required Qualifications
7+ years of hands-on experience engineering and operating Microsoft cloud security technologies: Purview, Defender for Cloud, Azure Log Analytics, Entra ID, PIM, Identity Governance, and DLP.
Solid understanding of cloud security principles and Microsoft 365 / Azure security controls.
Experience investigating security risks and identifying control weaknesses.
Comfort writing queries (e.g., KQL) and automating tasks (PowerShell, Graph API, or similar) is a strong plus.
Willingness and ability to travel. This role may require travel to customers to discuss our security practices and showcase how our tooling improves their security posture.
Strong analytical and problem-solving skills, with the ability to think from an attacker's perspective.
Excellent written communication, able to produce professional reports and executive summaries.
Strong presentation and customer-facing skills.
⭐ Desirable Experience
No specific desirable experience mentioned.
🎁 Benefits
Competitive salary and benefits package.
🛂 Visa & Eligibility
No specific visa or eligibility information mentioned.
Please let Patch my PC know that you found this role at devopsprojectshq.com as a way to support us, so we can keep providing you with awesome DevOps jobs.
Never miss a job
Join 2,000+ DevOps developers getting weekly alerts for remote and US/EU roles, Kubernetes, AWS, Terraform, filtered for your stack.
🔒 Need an IP to whitelist?
Get a dedicated static EU outbound IP for Banks, payments, EHRs, APIs, AI.