The posting
Azure Security Manager KPMG Keywords: Azure, Cyber Security, Security Management Contract Type: Type: Permanent employment Location: Amstelveen Education Level: Education: Bachelor (EQF 6) Published on: Published: 18/02/2026 Status: Open Apply before: 31/10/2026 Hours p/wk: 40 Jouw uitdagingen KPMG's Cyber & TechLaw practice enables clients to design and operate secure‑by‑default Microsoft Azure platforms. As an Azure Security Manager/Expert, you lead the design, build and hardening of cloud landing zones and core services, embedding zero‑trust, policy‑as‑code and identity‑first controls across enterprise and regulated environments. Wat ga je doen? Cloud platform architecture & landing zones - Design Enterprise‑Scale Azure Landing Zones per CAF (management groups, subscription strategy, naming/tagging). - Engineer guardrails using Azure Policy/initiatives and automate subscription vending with Bicep/Terraform. Data protection & key management - Enforce encryption by default; apply CMK for PaaS; govern secrets/certificates with Azure Key Vault. - Adopt Microsoft Purview‑aligned protection patterns and define DR/backup guardrails for critical data services. Container & platform hardening - Define AKS standards (policy for Kubernetes, RBAC, network policies, ACR signing/scanning gates). - Secure PaaS (App Service, Functions, Storage, SQL, Cosmos DB) with least privilege and network isolation. Identity & privileged access (Microsoft Entra) - Establish Conditional Access baselines, authentication strengths, workload identities and B2B collaboration. - Implement PIM (just‑in‑time), RBAC/ABAC models, break‑glass design and access reviews. Network & perimeter security - Architect hub‑and‑spoke or Virtual WAN with zero‑trust segmentation. - Implement Private Link/Endpoints, Azure Firewall/WAF, DDoS Protection, and NSG/ASG/egress controls. Posture & compliance (build‑time/run‑time) - Own Defender for ...



