Security Engineer

VirtusLab REMOTE KIELCE KRAKÓW WROCŁAW 2026-08-27
  • 5+ years of track record in Cloud/SaaS Infrastructure Security consulting or engineering engagements.
  • Hands-on expertise with Microsoft Security Stack including Entra ID, Microsoft Defender, Intune, Network Security, and Cloud Security.
  • Proficiency in security practices: incident response, security analysis, and posture hardening.
  • Demonstrated experience in securing and maintaining Microsoft Stack services.
  • Experience with insurance infrastructure ecosystems is a plus.
  • Formal background in Computer Science, STEM, or equivalent practical industry expertise.
  • English communication skills at B2+ level or higher.
  • Familiarity with security standards and compliance frameworks such as ISO 27001 / SOC-2 is advantageous.

Tech Stack

Microsoft Entra ID, Microsoft Defender for Endpoint, Defender for Identity, Defender for Cloud Apps, Defender for Office 365, Microsoft Sentinel, Microsoft Purview, Intune, Conditional Access, Azure, Microsoft Zero Trust framework, Terraform.

VirtusLab is a leading European software consulting and engineering company. Our mission is to craft clean code and practical solutions with precision and purpose. We foster a dynamic culture rooted in strong engineering, a sense of ownership, and transparency, empowering professionals to make a substantial impact in the software industry.

About the Engagement

Shape the future of a rapidly scaling UK insurance leader. The scope of cooperation encompasses supporting security operations within a modern security stack and streamlining integration capabilities to unify a high-growth MGA and brokerage ecosystem. Core deliverables include contributing to incident response operations, managing AV/EDR mechanisms, developing and updating security policy frameworks, optimizing SIEM operations, and driving IAM hardening initiative.

Project Scope

Establishing a modern, enterprise-grade security function for one of the UK’s fastest-growing Managing General Agents and brokerage groups. The end-client operates across three continents with entities spanning the UK, Europe, and Asia-Pacific, expanding dynamically through M&A operations.

The scope focuses on hardening a complex hybrid Microsoft environment, unifying fragmented security tooling across a multi-entity ecosystem, and driving a consistent, governed, and resilient security baseline across the entire Group.

Legacy, reactive security practices are being replaced with a Zero Trust architecture – deploying Microsoft’s full security stack across identity, endpoints, cloud apps, data, and network. The project aims at strengthening detection and response capabilities to protect a high-growth insurance business operating under Lloyd’s, UK GDPR, and MAS regulatory frameworks.

A few perks of being with us

Building tech community
Flexible hybrid work model
Home office reimbursement
Language lessons
MyBenefit points
Private healthcare
Training Package
Virtusity / in-house training
Access to the above perks is optional and completely voluntary for B2B contractors
,[Deploying and Optimizing Microsoft Defender XDR: Onboarding entities to Defender for Endpoint, Defender for Identity, and Defender for Cloud Apps, alongside integrating operational signals into Microsoft Sentinel as the central SIEM/SOAR platform., Identity and Access Hardening: Implementing Zero Trust identity controls including phishing-resistant MFA, Privileged Identity Management (PIM), Conditional Access policies, and Active Directory security hardening across hybrid on-premises and Entra ID environments., Security Operations & Incident Response: Co-operating with external MDR providers to optimize operational response workflows., Security Policy Standardization: Developing, documenting, and monitoring compliance with security baselines, configuration standards, and control frameworks across all Group entities worldwide., Cloud and SaaS Security Governance: Securing M365, Azure, and the broader SaaS ecosystem through Purview data classification, DLP policies, MDCA session controls, and continuous posture management., M&A Security Integration: Execution of a repeatable security onboarding framework for newly acquired entities during continuous business expansion.] Requirements: Cloud, Security, Microsoft Security Stack, Entra ID, Microsoft Defender, Intune, Network Security, Cloud Security, Incident response, Security analysis, Posture hardening, Microsoft Sentinel, Microsoft Purview, Conditional Access, Azure, Microsoft Zero Trust Framework, Terraform, ISO 270001, SOC-2 Additionally: Sport subscription, Training budget, Private healthcare, International projects.