Skip to sign up

Job matched to your search

Security Engineer

Doghouse Recruitment · The Randstad, Netherlands

The Randstad, Netherlands · HybridFull-TimeEUR 120k - EUR 120kPosted Aug 29, 2026

Free · Join 5,000+ job seekers using Qarera

How well do you match this role?

Tap the skills you already have — then see your real match score, what’s missing, and your resume fixed for this job.

↑ tap the skills you have
Loading sign-in…
Free · no credit card · 30 seconds

Job description

Azure Security Engineer – Entra ID | Defender | Azure Policy | Amsterdam / Rotterdam [€120K]

[Business Critical IT / Managed Services]

Security here is not a review at the end. It is the engineer inside the team writing the Azure Policy that makes the insecure thing impossible to deploy.

My client runs the infrastructure behind systems that large organisations cannot afford to lose, a good part of it in regulated sectors. Each client environment belongs to one dedicated team that designs it, builds it and then runs it for years, with the technical mandate sitting inside the team. Security is not a separate department reviewing other people’s work here, it lives inside the team that owns the platform. You join one of those teams as the engineer who owns that side of it.

What you’ll do

You own the security posture of an Azure platform that has to stay up and stay clean. Identity is the biggest piece, so Entra ID with Conditional Access, Privileged Identity Management, managed identities and workload identity federation instead of secrets sitting in config. Around that is the network: hub and spoke segmentation, Azure Firewall, NSGs, Private Link and private endpoints, WAF at the edge, and egress control that actually holds. Defender for Cloud gives you the posture picture across subscriptions, Microsoft Sentinel gives you detection, and you write your own KQL analytics rules rather than living off the defaults. Guardrails go in as code, so Azure Policy initiatives with deny and deployIfNotExists on top of the landing zone, deployed through Terraform or Bicep. Add Key Vault, certificate and secret lifecycle, AKS hardening, and Microsoft Cloud Security Benchmark and CIS baselines as the yardstick. You also do ordinary infrastructure work, because a security engineer who cannot build is not much use in a team like this.

Your profile

  • 6+ years in infrastructure or cloud engineering, with security as your main focus in recent years
  • Entra ID in depth: Conditional Access, Privileged Identity Management, managed identities, workload identity federation
  • Defender for Cloud and Microsoft Sentinel, including writing your own KQL detection rules
  • Azure network security: hub and spoke design, Azure Firewall, NSGs, Private Link, WAF, egress control
  • Guardrails as code: Azure Policy initiatives, Terraform or Bicep, plus PowerShell or Python
  • Key Vault, certificate and secret management, and AKS hardening
  • Fluent English, Dutch is a plus

What’s in it for you

Up to €120K gross per year on target, plus a car. A permanent contract from the start. Hybrid, so roughly half your week from home and the rest from the office in Amsterdam or Rotterdam or at the client site. Budget for security certification, training and conferences, and the time to actually use it.

Interested?

Contact me at sander@doghouse-recruitment.nl

Don’t just read the job — see if you’ll get it.

Get your match score, a resume tailored to this exact role, and jobs like it — free.

Check my fit for this job
Loading sign-in…
Apply →

Hiring for a role like this? Join the employer waitlist.