About the job
ABOUT Avolution
Join Avolution, a prestigious global leader in Enterprise Architecture Software with over 20 years of experience. Our established presence spans across London, Sydney, Northern Virginia, and Singapore, and we are recognized in the Gartner Magic Quadrant as an industry frontrunner. Become part of our intelligent, friendly team, where your skills and initiative will drive our growth while enjoying a culture rated as collegial, collaborative, flexible, and supportive by our employees.
Key Responsibilities
Cloud & Infrastructure Security
- Design, manage, and enhance security configurations across Azure and AWS environments, ensuring seamless integration with Office 365.
- Implement and enforce industry best practices for identity and access management (IAM) in Azure AD (Entra ID) and AWS IAM.
- Monitor cloud workloads for vulnerabilities, misconfigurations, and threats utilizing tools such as Microsoft Defender.
- Collaborate with DevOps/Engineering teams to embed security controls into CI/CD pipelines, advocating for DevSecOps principles.
- Conduct thorough security assessments, including aiding in penetration testing and risk evaluations to identify and mitigate potential vulnerabilities.
Endpoint & Identity Security
- Enhance device posture, compliance, and management utilizing Microsoft Intune and Defender for Endpoint.
- Develop and maintain solid conditional access, multi-factor authentication (MFA), and endpoint protection policies.
- Oversee secure identity lifecycle processes, enforcing least-privilege access and zero-trust principles.
Security Operations
- Respond promptly to security alerts, incidents, and vulnerabilities with thorough investigations and remediation actions.
- Perform regular risk assessments, security reviews, and internal audits.
- Manage and optimize security tools, including SIEM, EDR, vulnerability scanners, and the Microsoft Defender suite.
- Lead incident response efforts and coordinate with cross-functional teams.
Compliance & Governance
- Support ISO 27001:2022 recertification and ongoing compliance activities, including internal audits.
- Prepare for and assist in obtaining additional compliance certifications (e.g., SOC 2, GDPR) to facilitate company growth.
- Develop, maintain, and enhance security policies, procedures, and technical documentation.
- Track, report on, and address audit findings or compliance gaps.
Collaboration & Culture
- Partner with globally distributed teams across EMEA, AMER, and APAC regions.
- Educate internal teams on security best practices and cultivate a security-first culture through training and awareness initiatives.

