Aviva
Cloud Security Specialist

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Cloud Security Specialist
Location: Norwich/Bristol (Hybrid)
Contract Duration: 9 Months Initially
Inside IR35:
This contract engagement is designed for an experienced information security professional who can quickly integrate into a complex enterprise environment to configure, validate, and assure technical security controls. The role is positioned as an active, hands-on partner to operational IT and platform engineering teams. Rather than just writing policies, the successful contractor will be responsible for translating high-level security architecture into practice.
Key Responsibilities
- Hands-On Azure Configuration & Management: Directly analyze, refine, and configure security controls within Microsoft Azure. This includes managing and validating Identity & Access Management (Microsoft Entra ID), Network Security Groups (NSGs), Azure Firewalls, Web Application Firewalls (WAF), Key Vaults, and secure network architectures.
- Operational Security Assurance: Perform practical configuration reviews, compliance assessments, and control effectiveness reviews. Review and challenge technical and architectural designs to ensure that cloud-native security controls are implemented in practice rather than just on paper.
- Stakeholder Liaison & Enablement: Act as the primary technical security liaison and trusted advisor between security, operational IT engineering, platform, and service teams. Provide pragmatic, risk-based security guidance to support ongoing change, release, and operational activities.
- Threat & Vulnerability Remediation: Monitor and analyze security posture using native tooling like Microsoft Defender for Cloud and Microsoft Sentinel. Identify security gaps, vulnerabilities, and misconfigurations, recommend precise technical remediation actions, and partner with platform teams to track and drive remediation through to completion.
- Continuous Security Improvement: Participate in regular technical security governance processes, including log and access reviews. Identify opportunities to automate security guardrails (e.g., via Azure Policy) and drive continual improvements in operational security practices.
- Documentation & Reporting: Translate complex technical cloud security findings, risks, and configuration baselines into clear, professional documentation and reports tailored appropriately for both technical engineers and non-technical business stakeholders.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
Required Skills and Experience
- Hands-on Azure Security Infrastructure: Significant, proven experience (5+ years in information security, with substantial focus on cloud) actively configuring, securing, and maintaining Azure cloud resources. Must understand how cloud security controls are implemented and operate in practice.
- Security Technologies: Practical experience with critical security boundaries and systems, including firewalls, WAFs, modern web-based technologies, and landing zone structures.
- Native Azure Tooling Proficiency: Hands-on expertise utilizing Microsoft Defender for Cloud, Azure Policy, Microsoft Entra ID (for advanced IAM and RBAC controls), and Microsoft Sentinel or equivalent cloud SIEM systems.
- Security Design Review & Critique: Ability to review detailed technical and architectural designs, spot potential flaws, and recommend specific, practical cloud-native remediations and guardrails.
- Standards & Framework Application: Strong working knowledge of secure development principles and industry standards (e.g., ISO 27001, Cyber Essentials Plus, CIS Benchmarks, Cloud Security Alliance) and the ability to translate these high-level frameworks into hard technical controls.
- Stakeholder Management & Communication: Superb collaborative skills; able to partner effectively with engineering teams to resolve technical issues while simultaneously communicating risks and assurance status clearly to business owners and project stakeholders.
- Autonomous Execution: Self-driven, comfortable working independently to prioritize work, manage multiple operational demands, and deliver high-quality technical outcomes at pace in a complex enterprise ecosystem.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
Desirable Qualifications
- Cloud-Specific Certifications: Microsoft Certified: Azure Security Engineer Associate (AZ-500) or equivalent hands-on Azure security credentials.
- Professional Security Credentials: CISSP, CISM, or equivalent certifications showing a robust foundation in security principles, or equivalent deep, practical security engineering experience.
Please ensure that you attach an up-to-date CV to your application.
We flex locations, hours, and working patterns to suit our customers, the business, and you. Most of our people smart-work, spending at least 50% of their time in an Aviva office each week.
We’d love you to apply online. If you need a different way to apply, or have questions, please contact me at Katyayani.pathak@aviva.com.
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Skills
Location