Jobs and Careers
WE

Senior Cloud Security

Welvaart
Portugalfull_timeVerifiedPosted 4 Nov 2025

About the role

<p><em><strong>About Welvaart</strong></em></p> <p>On a daily basis, we assume <strong>commitments</strong> and present solutions to our stakeholders in order to create a structure of human values, based on <strong>professionalism</strong>, <strong>honesty</strong> and <strong>rigor</strong>.</p> <p>With a management based on <strong>Human Centered Design</strong>, we take care of our professionals with consistent <strong>career plans</strong>, but flexible with their needs and expectations of evolution. Our management team guarantees an <strong>empathetic</strong> and present <strong>leadership</strong> that will provide superior <strong>technological engagement</strong> and delivery to our clients' projects and products.</p> <p><em><strong><br/></strong></em></p> <p><em><strong>Project</strong></em></p> <p>As a senior member of the Cloud CoE you will own the security and compliance strategy for our Microsoft Azure and Oracle Cloud Infrastructure (OCI) estates. You will translate the Azure &amp; OCI Well-Architected Frameworks, the Azure Security Benchmark/Baseline, CIS Foundations Benchmark v2.0, NIST SP 800-190 container-security guidance, and other industry standards into practical, automated controlsdesigning, building and continuously improving the secure landing zones that power our business‐critical workloads.</p> <p></p> <p><strong><em>Role</em></strong></p> <ul></ul> <ul><li>Propose and follow up with the various teams, the necessary improvements to increase the Security Score in Defender.</li><li>Design secure multi-subscription / multi-tenant landing zones in Azure and OCI, aligned to the five Well-Architected pillars (Security,</li><li>Reliability, Performance Efficiency, Operational Excellence, Cost).</li><li>Drive container-security reference architectures (AKS, OKE, ACI, OCI Containers, Kubernetes on IaaS) that satisfy NIST SP 800-190 and NSA/CISA hardening guidance.</li><li>Map regulatory and internal requirements to the Azure Security Benchmark/Baseline, CIS Azure/OCI 2.0 controls, PCI DSS, ISO 27001 and SOC 2.</li><li>Build automated policy as code (Azure Policy, OCI Guardrails, Terraform Sentinel, OPA/Gatekeeper) to enforce guardrails and generate evidence for auditors.</li><li>Develop and maintain IaC modules (Bicep/Terraform/OCI Resource Manager) with integrated security controls, reusable across product teams.</li><li>Integrate static/dynamic IaC security scans (Azure Defender for cloud, Oracle Guard tfsec, Trivy, Dockle) and container image signing into the CI/CD pipeline (GitHub Actions/Azure DevOps/ArgoCD).</li><li>Configure Azure Security Center/Defender, Microsoft Sentinel, and OCI Cloud Guard to detect, triage and respond to threats.</li><li>Establish KPIs/KRIs and real-time dashboards for cloud posture, vulnerability debt and compliance drift.</li><li>Act as a trusted advisor to engineering teams, running threat-model workshops, training on secure coding, and championing a paved-road DevSecOps culture.</li><li>Evaluate emerging controls (Confidential Computing, SBOM, DICE-based attestation) and present recommendations to the Architecture Review Board.</li></ul> <p><strong><em>We are looking for</em></strong></p> <ul><li>Hands-on experience in improving the Security Score in Defender, through configuring Microsoft Security tools (Microsoft Defender for Cloud CSPM/CWPP, Defender for Endpoint, Defender for Cloud Apps, Microsoft DLP, Microsoft for Identity)</li><li>5+ years in infrastructure or security engineering, with 5+ years focused on public cloud (Azure and/or OCI).</li><li>Proven design and delivery of secure landing zones at scale, including micro-segmentation, identity &amp; access boundary, logging pipeline, data-classification and encryption strategy.</li><li>Deep knowledge of Azure Well-Architected Framework, Azure Security Benchmark/Baseline, CIS Foundations Benchmark v2.0 (Azure &amp; OCI), NIST SP 800-190, NIST CSF/800-53, and MITRE ATT cloud tactics.</li><li>Hands-on mastery with Terraform/Bicep, Kubernetes security (RBAC, network policies, PodSecurity standards), container registry hardening and image-signing (Cosign/Notary v2).</li><li>Experience integrating cloud workloads with SIEM/SOAR platforms (Sentinel, Splunk, QRadar), EDR and CSPM tools (Wiz, Prisma Cloud, Microsoft Defender CSPM).</li><li>Scripting / coding proficiency (PowerShell, Python, Go or similar) for automation and custom control development.</li><li>Certifications: AZ-305 / AZ-500, OCI Architect Professional, CCSP or CISSP-ISSAP (or equivalent demonstrable expertise).</li>Preferably with Cloud Oracle knowledge.</ul> <p><strong><em>What you can discover with us?</em></strong></p> <ul><li>Be part of a tech start-up</li><li>Different scopes of project in different sectors</li><li>Structure of fairness and equity salary (Consultant Profile)</li><li>Training &amp; Certification</li><li>Career Path management</li><li>More than 30 Partnerships</li><li>Welvaart Ambassador Program</li></ul> <p></p> <p><

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Welvaart

View company profile →