Senior MS Intune & Cloud Security Specialist
Job description
About the role
The Senior Cloud Security Architect Opportunity at Coderio represents a pivotal role in shaping the security posture of modern, cloud-native environments. You will own the end-to-end design and implementation of a zero-trust device and security framework from the ground up. This position requires a deep commitment to building scalable digital solutions that align with the product-oriented mindset of our international teams. You will act as the technical authority responsible for ensuring that device management and endpoint security strategies are robust, future-proof, and aligned with global standards. The role demands close collaboration with partners across different time zones to deliver technology that creates real impact. You will be instrumental in establishing the foundational security architecture that protects our clients' digital assets. Ultimately, this is a leadership position that defines how security is architected and operationalized in a greenfield setting.
Key facts
What you'll do
- Architect a greenfield Microsoft Intune and Entra ID Join strategy, establishing a foundational zero-dependency environment free from legacy on-premises Active Directory constraints.
- Configure and deploy Windows Autopilot for seamless out-of-box device experience, integrating Apple Business Manager (ADE) for macOS and mobile device management for iOS and Android ecosystems.
- Implement and manage Microsoft Defender for Endpoint (MDE) to provide comprehensive EDR capabilities, ensuring advanced threat protection across all managed endpoints.
- Establish Microsoft Defender for Vulnerability Management (MDVM) workflows to continuously assess, prioritize, and remediate security vulnerabilities across the infrastructure.
- Extend Microsoft Defender for Cloud protection to non-Azure assets by connecting AWS EC2 instances via Azure Arc, enabling MDE extension scanning on cloud servers.
- Integrate GitHub and GitLab repositories with Microsoft Defender for Cloud to establish a DevSecOps pipeline that scans for exposed secrets, Infrastructure as Code misconfigurations, and dependency vulnerabilities through Software Composition Analysis.
- Define and document security policies and configurations, ensuring strict alignment with ISO 27001:2022 compliance requirements and industry best practices.
- Conduct hands-on knowledge transfer sessions and enablement workshops for internal engineering and security leadership to ensure sustainable operations.
- Map all implemented configurations and controls against ISO 27001:2022 standards to validate compliance and identify areas for continuous improvement.
- Leverage advanced scripting capabilities in PowerShell and Bash to automate repetitive tasks and enhance the efficiency of security operations.
- Collaborate closely with international partners to ensure that security architectures are implemented consistently and effectively across global deployments.
- Own the documentation of all architectural decisions, configurations, and procedures to maintain clear institutional knowledge.
- Drive the successful adoption of new security technologies through clear communication and structured training sessions.
- Ensure that all device management and security policies are enforced consistently across Windows, macOS, Android, and AWS server environments.
- Contribute to the continuous improvement of the security framework by monitoring emerging threats and recommending proactive measures.
Requirements
- Bring 5+ years of experience leading complex IT infrastructure, endpoint management, or cloud security implementations in diverse environments.
- Demonstrate a proven track record of executing zero-base MS Intune and Entra ID deployments without reliance on previous legacy systems.
- Exhibit advanced hands-on expertise in Microsoft Intune, Entra ID, Windows Autopilot, Apple Business Manager (ADE), and Microsoft Defender for Endpoint.
- Show demonstrated experience connecting non-Azure infrastructure, specifically AWS EC2, to Microsoft Defender for Cloud using Azure Arc.
- Possess practical experience integrating GitHub and GitLab repositories for security scanning within cloud environments.
- Maintain flexible part-time availability that aligns with the Argentina time zone (ART) to ensure effective collaboration.
- Communicate fluently in Spanish, both spoken and written, to ensure clear understanding and precise execution of requirements.
- Excel at documenting technical processes in a clear and concise manner and delivering effective knowledge transfer sessions to technical audiences.
- Adhere strictly to the outlined requirements and hard bars as defined in this job description.
- Apply a methodical approach to problem-solving and implementation within the specified technology stack.
Nice to have
- Hold Microsoft Certified Cybersecurity Architect Expert (SC-100) certification, demonstrating advanced security architecture knowledge.
- Possess the Endpoint Administrator Associate Associate (MD-102) certification, validating deep expertise in endpoint management.
- Hold the Azure Security Engineer (AZ-500) certification, indicating strong cloud security implementation skills.
- Show practical understanding of the ISO 27001:2022 framework and its application in real-world security architecture scenarios.
- Write basic scripting using PowerShell and Bash to automate security tasks and improve operational efficiency.
Practical notes
This is a freelance, project-based engagement with flexible part-time hours. The role is 100% remote, and location is specified as Argentina for eligibility purposes. Please