
Staff Platform Engineer
Posted Aug 7

Posted Aug 7
This is a fully remote position, open to applicants in Germany, +4 more states.
• Design and execute the security architecture for the Azure environment, encompassing policy guardrails, network security, encryption, identity fortification, and secure defaults.
• Take ownership of the security within the Azure landing zone and guarantee that workloads transition onto a secure foundation.
• Manage Entra ID security, including conditional access, Privileged Identity Management, workload identity governance, Okta federation hardening, and tenant security.
• Co-manage the onboarding and configuration of the CNAPP platform, which includes posture management policies, prioritization of findings, and integration of workflows.
• Create and sustain security controls as code using Terraform and Azure Policy, ensuring integration into CI/CD.
• Ensure secure migrations from on-premises to Azure through risk assessments, controls, and validation of post-migration posture.
• Perform threat modeling for Azure infrastructure designs and prioritize controls based on actual risk.
• Automate the collection of compliance evidence for ISO 27001, GDPR, and DORA.
• Align Azure security patterns with AWS and GCP to establish a unified multi-cloud security posture.
• Empower cloud teams through security design reviews, paved-road patterns, comprehensive documentation, and office hours.
• Evaluate Azure security posture, define landing-zone architecture, onboard CNAPP, implement controls, enhance Entra ID security, improve detection capabilities, align cross-cloud standards, and enable team self-service.
• Over 8 years of experience in infrastructure or security engineering.
• Extensive hands-on expertise in Azure security at a production scale.
• Recognized as a staff-level technical authority with cross-team influence and sound judgment.
• Strong expertise in Entra ID security, including conditional access, PIM, workload identity, and federation hardening.
• Proficient with Defender for Cloud, Sentinel, Azure Policy, network security, and Key Vault.
• Experience with Terraform for infrastructure-as-code related to security, policy-as-code, security modules, and CI/CD integration.
• Capability in threat modeling that addresses cloud attack paths, privilege escalation, and lateral movement.
• Practical experience implementing compliance frameworks such as ISO 27001, GDPR, DORA, or similar.
• Familiarity with CNAPP/CSPM tools like Wiz, Cortex Cloud, Orca, Prisma Cloud, or Defender CSPM.
• Understanding of observability platforms.
• Basic knowledge of AWS or GCP security.
• Experience in security detection using a SIEM such as CrowdStrike, Splunk, Elastic, Sentinel, or Google Security Operations.
• Ability to influence without direct authority and establish standards across teams.
• Exceptional technical communication skills in English.
• Preferred: experience in fintech, banking, or regulated financial services.
• Preferred: expertise in Okta and Entra ID federation security.
• Preferred: experience in post-acquisition security integration.
• Preferred: background in DORA implementation.
• Preferred: familiarity with GCP security.
• Preferred: experience in on-premises or hybrid security environments.
• Preferred: knowledge of supply-chain or CI/CD pipeline security.
• Relevant certifications preferred: AZ-500, SC-300, AZ-305.
• Fully remote work option available from one of the European hubs, or hybrid work in one of the hubs.
• Supportive and transparent hiring process.
• Opportunity to collaborate with a multicultural European team.
• Professional growth through technical leadership, security design reviews, documentation, and office hours.
• Chance to contribute to the cross-cloud security strategy.
• Commitment to equal treatment and non-discrimination in employment.
Grafana Labs
Grafana Labs
Grafana Labs
Get handpicked remote jobs straight to your inbox weekly.