We are seeking an Azure Security Engineer. You will implement and improve cloud, identity and endpoint controls in a regulated hedge fund environment. Based in Malaysia, you will support Singapore and regional offices by turning security designs into production-ready configurations across Entra ID, Microsoft Defender, Intune and Azure Firewall, with a focus on hardening, testing and documentation.
Responsibilities
- Configure and maintain Microsoft Entra ID controls including Conditional Access, multi-factor authentication (MFA) and Privileged Identity Management (PIM) workflows
- Build and improve Azure security controls including Microsoft Defender for Cloud, Azure Firewall and network segmentation in a hub-and-spoke design
- Manage endpoint security baselines in Microsoft Intune and Microsoft Defender for Endpoint, resolving configuration drift
- Implement security designs from the Security Architect through secure, reliable production configurations
- Perform configuration reviews and hardening aligned to CIS Controls v8 and internal standards
- Remediate findings from vulnerability scans, security assessments and technical reviews within agreed service levels
- Partner with Engineering, Security Operations and Governance teams on changes, control tuning, escalations and audit needs
- Maintain documentation and standard operating procedures (SOPs), test control effectiveness and recommend improvements
Requirements
- Hands-on experience implementing cloud, identity and endpoint security controls in production
- Practical knowledge of Microsoft Azure security services including Microsoft Entra ID, Conditional Access, Privileged Identity Management (PIM), Microsoft Defender for Cloud, Microsoft Defender for Endpoint and Azure Firewall
- Experience configuring device and endpoint controls through Microsoft Intune
- Understanding of vulnerability management tools and remediation workflows such as Nessus, Microsoft Defender or equivalent
- Familiarity with hardening frameworks such as CIS Controls v8 or equivalent standards
- Ability to translate security designs into secure, maintainable configurations and operating procedures
- Strong skills in troubleshooting, testing and documentation with accurate configuration records
- Clear collaboration across Security Architecture, Security Operations, Governance and Engineering teams
Nice to have
- Experience in financial services, investment management or another regulated environment
- Exposure to Microsoft Sentinel, Microsoft Defender XDR, Microsoft Purview Data Loss Prevention (DLP), MAS Technology Risk Management (TRM) or MAS Notice 658
- Microsoft certifications such as SC-100, SC-300 or AZ-500 or cloud security certifications such as CCSP or CISSP
We offer
- By choosing EPAM, you're getting a job at one of the most loved workplaces according to Newsweek 2021 & 2022&2023.
- Employee ideas are the main driver of our business. We have a very supportive environment where your voice matters
- You will be challenged while working side-by-side with the best talent globally. We work with top-notch technologies, constantly seeking new industry trends and best practices
- We offer a transparent career path and an individual roadmap to engineer your future & accelerate your journey
- At EPAM, you can find vast opportunities for self-development: online courses and libraries, mentoring programs, partial grants of certification, and experience exchange with colleagues around the world. You will learn, contribute, and grow with us