Security Engineer
- 5+ years of track record in Cloud/SaaS Infrastructure Security consulting or engineering engagements.
- Hands-on expertise with Microsoft Security Stack including Entra ID, Microsoft Defender, Intune, Network Security, and Cloud Security.
- Proficiency in security practices: incident response, security analysis, and posture hardening.
- Demonstrated experience in securing and maintaining Microsoft Stack services.
- Experience with insurance infrastructure ecosystems is a plus.
- Formal background in Computer Science, STEM, or equivalent practical industry expertise.
- English communication skills at B2+ level or higher.
- Familiarity with security standards and compliance frameworks such as ISO 27001 / SOC-2 is advantageous.
Tech Stack
Microsoft Entra ID, Microsoft Defender for Endpoint, Defender for Identity, Defender for Cloud Apps, Defender for Office 365, Microsoft Sentinel, Microsoft Purview, Intune, Conditional Access, Azure, Microsoft Zero Trust framework, Terraform.
VirtusLab is a leading European software consulting and engineering company. Our mission is to craft clean code and practical solutions with precision and purpose. We foster a dynamic culture rooted in strong engineering, a sense of ownership, and transparency, empowering professionals to make a substantial impact in the software industry.
About the Engagement
Shape the future of a rapidly scaling UK insurance leader. The scope of cooperation encompasses supporting security operations within a modern security stack and streamlining integration capabilities to unify a high-growth MGA and brokerage ecosystem. Core deliverables include contributing to incident response operations, managing AV/EDR mechanisms, developing and updating security policy frameworks, optimizing SIEM operations, and driving IAM hardening initiative.
Project Scope
Establishing a modern, enterprise-grade security function for one of the UK’s fastest-growing Managing General Agents and brokerage groups. The end-client operates across three continents with entities spanning the UK, Europe, and Asia-Pacific, expanding dynamically through M&A operations.
The scope focuses on hardening a complex hybrid Microsoft environment, unifying fragmented security tooling across a multi-entity ecosystem, and driving a consistent, governed, and resilient security baseline across the entire Group.
Legacy, reactive security practices are being replaced with a Zero Trust architecture – deploying Microsoft’s full security stack across identity, endpoints, cloud apps, data, and network. The project aims at strengthening detection and response capabilities to protect a high-growth insurance business operating under Lloyd’s, UK GDPR, and MAS regulatory frameworks.