Staff Platform Engineer - Azure (Madrid)

Staff Platform Engineer - Azure (Madrid)

15 sep
|
shine
|
Madrid

15 sep

shine

Madrid

Founded by serial entrepreneurs Rico Andersen and Martin Hegelund, Shine is a leading European fintech unicorn on a mission to restore the joy of running a business, by ending wasted time on financial admin. Shine offers a connected solution for invoicing, accounting, payroll, business accounts, payments, and financing, meaning business owners can focus their energy on growing a healthy business, not held back by manual admin. Today we're part of Cegid, a European leader in cloud software for finance and accounting.

The Infrastructure & IT unit at Shine Our Infrastructure & IT unit builds and operates the cloud platforms, developer tooling, and IT services that underpin every product Shine ships. We run multiple cloud teams (AWS, GCP, Azure), Engineering Efficiency, and IT operations. Infrastructure security is a dedicated function within this unit — senior engineers who own the security posture of our cloud estate as a traversal role across all teams.

We're looking for a Staff Platform Engineer to own the security of our Azure cloud environment and contribute to multi-cloud security strategy. Azure is a strategic platform for the group, driven by recent acquisitions, and it needs the same security depth we are already building on AWS. This is a hands‐on, senior IC role.

You will define security architecture, build controls as code, harden identity, implement detection, and partner with platform teams to make secure defaults the path of least resistance. You work alongside a peer Staff Platform Engineer who covers AWS and IT, sharing cross‐cloud strategy while owning separate execution domains. Define and implement the security architecture for our Azure estate — policy guardrails, network security, encryption, identity hardening,



and secure defaults.

Own the security of our Azure landing zone — the platform teams build it, you ensure it's built securely and that workloads migrate onto a secure foundation. Co‐own the onboarding and configuration of our CNAPP platform (e.g. Wiz, Cortex Cloud, Orca, or FortiCNAPP) — posture management policies, finding prioritisation, and workflow integration.

Build and maintain security controls as code using Terraform and Azure Policy — CIS baselines, automated remediation, integrated into CI/CD. Ensure on‐prem → Azure migrations happen securely — risk assessment pre‐migration, controls during, posture validation post. Conduct threat modelling for Azure infrastructure designs.

Identify attack paths and prioritise controls based on vigente risk.

Align

Azure security patterns with AWS and GCP to maintain a coherent multi‐cloud security posture. GCP security coverage will be shared with your peer as it matures.

Enable teams: security design reviews, paved‐road patterns, documentation, and office hours so cloud teams can self‐serve securely. Full remote in one of our European hubs (Germany, Netherlands, Denmark, Spain, Protugal), or Hybrid in one of our Hubs (Berlin, Amsterdam, Copenhagen, Madrid, Porto) 8+ years of infrastructure or security engineering experience,



with deep hands‐on Azure security expertise at production scale. ~ Proven experience implementing Azure security controls: Defender for Cloud, Sentinel, Azure Policy, network security, Key Vault. ~ Infrastructure‐as‐code for security (Terraform) — policy‐as‐code, security modules, CI/CD integration. ~ Threat modelling capability — reasoning about cloud attack paths, privilege escalation, and lateral movement. ~ Practical compliance framework implementation (ISO 27001, GDPR, DORA, or similar) — actual control automation, not just awareness. ~ CNAPP/CSPM tooling experience (Wiz, Cortex Cloud, Orca, Prisma Cloud, Defender CSPM, or similar). ~ Working knowledge of at least one other CSP (AWS or GCP) from a security perspective. ~ CrowdStrike, Splunk, Elastic, or native solutions like Sentinel or Google Security Operations). ~ Excellent technical communication in English.

Experience in fintech, banking, or regulated financial services. On‐prem / hybrid security experience. Senior IC who leads through code, designs, reviews, and enablement — not standalone documents. Traversal role across all cloud teams — you partner with them, not sit above them.

Tight collaboration with the Azure platform teams: you build a secure platform with them.

Peer relationship with the AWS/IT Staff Engineer: shared strategy, separate domains. 90 Days: Assessed the current Azure security posture across all subscriptions. Started CNAPP onboarding and initial policy configuration. Relationships built with all cloud teams. Cross‐cloud security standards aligned with AWS. Cloud teams self‐serving on T2/T3 security decisions. Azure security at parity with AWS.

📌 Staff Platform Engineer - Azure (Madrid)
🏢 shine
📍 Madrid

Postulate a este anuncio

Muestra tus habilidades a la empresa, rellenar el formulario y deja un toque personal en la carta, ayudará el reclutador en la elección del candidato.

Suscribete a esta alerta:

Recibe por email las nuevas ofertas de trabajo para: staff platform engineer - azure (madrid) / madrid

Suscribete a esta alerta:

Recibe por email las nuevas ofertas de trabajo para: staff platform engineer - azure (madrid) / madrid