Position Overview
The IT Cloud Cybersecurity Specialist defines, implements, and continuously improves security controls across Microsoft 365, Azure, identity, data protection, SaaS integrations, cloud data flows, and approved AI and Microsoft 365 agent capabilities. The role serves as a trusted security advisor to technology owners, project stakeholders, and operational teams, ensuring that secure-by-design principles are embedded across the enterprise.
Responsibilities
Cloud Security Strategy and Governance
- Drive the continuous improvement of the cloud security posture across Microsoft 365, Azure, approved SaaS platforms, and AI-enabled services.
- Define cloud security baselines, identity controls, data protection requirements, logging, monitoring, and secure configuration standards.
- Contribute to the cloud security roadmap by identifying priorities, recommending improvements, and driving implementation.
- Develop and report cloud security KPIs, KRIs, posture trends, compliance metrics, and remediation status to management.
Microsoft 365 and Data Protection Security
- Lead Microsoft 365 security and Microsoft Purview initiatives, including identity protection, email and collaboration security, data loss prevention, sensitivity labelling, information protection, retention, insider risk, and data exposure reduction.
- Define and validate data protection and SaaS security controls for Microsoft 365, SharePoint, Teams, Exchange, OneDrive, SaaS platforms, and business workflows.
- Monitor data security alerts, investigate exposure risks, and coordinate remediation with business, legal, compliance, and technical teams.
- Evaluate and implement Microsoft security capabilities across Microsoft Entra ID, Microsoft Defender XDR, Microsoft Purview, Microsoft Defender for Cloud, and Microsoft 365 security services.
Identity and Access Security
- Strengthen cloud identity security across Microsoft Entra ID, Conditional Access, multifactor authentication, Identity Governance, Privileged Identity Management, and Zero Trust controls.
- Define standards for single sign-on, federation, authentication, authorization, lifecycle management, access recertification, and third-party access governance.
Secure Architecture, Application Security, and Cloud Operations
- Review cloud architectures, solution designs, data flows, single sign-on models, API integrations, operational readiness evidence, and security requirements.
- Define and validate security controls, exceptions, risk acceptance requirements, and go-live security evidence for cloud and SaaS implementations.
- Lead Azure security posture improvement initiatives using Microsoft Defender for Cloud, Secure Score, and cloud-native security controls.
- Collaborate with infrastructure, application, and delivery teams to integrate security controls into cloud delivery and DevSecOps practices.
- Automate recurring cloud security processes through policy-as-code, infrastructure-as-code, workflow automation, and reusable control patterns.
- Support application security reviews covering secure design, authentication and authorization, API security, secrets management, secure coding practices, and remediation of findings.
AI and Emerging Technologies Security
- Define secure adoption and governance practices for Microsoft Copilot, Microsoft 365 agents, AI-enabled services, and agentic AI capabilities that use enterprise data.
- Assess security, privacy, identity, data protection, prompt-related risks, data exposure, and compliance risks related to AI implementations.
Qualifications
- Bachelor’s degree in information security, computer science, cloud technology, software engineering, or a related field.
- CISSP, CCSP, SC-100, AZ-500, SC-300, SC-400/SC-401, GCSA, or equivalent security certifications is stronggly preferable.
Experience
- Seven or more years of experience in cybersecurity, cloud security, Microsoft 365 security, application security, or identity and access management.
- At least three years of experience focused on cloud, SaaS, Microsoft 365, Azure security, Microsoft Entra ID, Microsoft Purview, data loss prevention, or secure cloud integrations.
- Demonstrated experience with cloud architecture reviews, security control definition, implementation validation, operational readiness, and evidence collection.
- Hands-on experience with Microsoft Purview, data loss prevention, Microsoft Defender XDR, Microsoft Entra ID, Conditional Access, Microsoft Defender for Cloud, and cloud-native security controls.
- Experience with automation, infrastructure-as-code, DevSecOps, security monitoring, and security process standardization is a strong asset.
- Expert knowledge of NIST CSF, NIST SP 800-53, and ISO 27001 is preferred. Experience applying ISO 27017/27018, SOC 2, CIS Benchmarks, and Microsoft Security Baselines within enterprise cloud environments is highly desirable.
Skills And Abilities
- Strong knowledge of cloud security, Microsoft 365 security, Azure security, Microsoft Entra ID, Identity Governance, Microsoft Purview, data loss prevention, and data protection controls.
- Proficiency in cloud architecture reviews, secure integration patterns, single sign-on, data flows, API security, SaaS security, and secure-by-design project controls.
- Familiarity with application security, DevSecOps, infrastructure-as-code, policy-as-code, security automation, and AI security governance.
- Strong analytical and problem-solving skills with the ability to assess cloud, identity, data, AI, and application security risks.
- Excellent communication, reporting, and presentation skills, including the development and tracking of security KPIs, KRIs, and remediation metrics.
- Ability to build effective relationships and align cloud, infrastructure, application, legal, compliance, project delivery, and cybersecurity teams.
- Demonstrated autonomy, ownership, accountability, leadership, influence, and commitment to continuous improvement and operational excellence.
LANGUAGES
- Bilingual, French and English.
Knowledge of English is required for this specific position as Kruger deals with partners across North America and the successful candidate will be required to communicate frequently with them. Kruger has taken all reasonable steps to avoid imposing English language requirements, including assessing the actual language needs associated with the duties to be performed, ensuring that the language skills already required of other employees were insufficient for the performance of those duties, and limiting as much as possible the number of positions with duties requiring English language skills.