Apply now!

Senior Azure / Entra Engineer Amsterdam

Own B2B Access & Conditional Access Behind a Global Industrial Group | Up to €110,000 + Bonus

  • Amsterdam
  • € 110.000
Cloud / DevOps
Azure

Vacancy: Senior Azure / Entra Engineer Amsterdam

Your job: Senior Azure / Entra Engineer Amsterdam

  • Do you want to become the go-to Entra specialist for a compact Amsterdam organisation sitting at the financial heart of a multi-billion global industrial group?
  • Is Microsoft Entra ID, B2B access, Conditional Access and application identity a genuine part of your day-to-day work?
  • Do you want to help users, applications, external partners and international group entities connect securely without turning access management into bureaucracy?
  • And do a senior ownership role, international stakeholders, a high-quality Amsterdam office and a package up to €110,000 + performance bonus sound like a strong next step?

Then this role is worth your attention.

Your employer: global scale, compact local ownership

You will join the Amsterdam-based financial centre of a globally recognised industrial group. This is a company behind real-world engineering at massive scale: energy, industrial technology, transport, critical infrastructure and advanced physical systems used across the world.

Behind a company of that size sits a financial and operational backbone that cannot simply pause. International entities need to connect securely. Banks, SaaS providers and external applications need to exchange sensitive data safely. Payments and financial data flows need to move reliably. Access needs to be controlled, auditable and secure.

The local organisation is compact, with around eight people in Amsterdam, but its impact is significant. That creates the attractive contradiction of this role: you get the scale, reputation and complexity of a global industrial group, while locally working in a small team where your judgement, ownership and technical decisions are highly visible.

You will help bring a modern cloud-first Azure environment further into production, then become one of the key technical owners of how secure access is operated and improved over time.

Your role: Senior Azure / Entra Engineer Amsterdam

The centre of gravity is Microsoft Entra ID and secure access. This is not a standard AKS, GitOps or CI/CD role. The real work sits where identity, users, applications, external parties and production operations meet.

You will work hands-on with:

  • Entra ID B2B / guest access
  • Conditional Access
  • MFA, PIM and RBAC
  • Enterprise Applications
  • App Registrations and Service Principals
  • SAML / OIDC and modern authentication
  • Identity lifecycle and access governance
  • External/vendor access and secure onboarding of group entities
  • Production troubleshooting around authentication, permissions and application access
  • Governance, operational standards, auditability and careful change management

You will work closely with local finance and business stakeholders, technical specialists elsewhere in the group, application teams and external providers. The role is not just about configuring Azure services. You need to understand what is happening, why it matters, what the risk is and what decision should be made.

The engineering challenge

The challenge is making secure access work in practice around the financial artery of a global industrial group.

You will think about questions such as:

  • How do we securely give external partners or group entities access without creating unmanaged guest accounts?
  • How do we design Conditional Access policies that improve security without breaking legitimate business workflows?
  • How do we reduce standing privileged access while still allowing engineers and users to do their work?
  • How do we manage Enterprise Applications, App Registrations and Service Principals without permissions slowly becoming too broad?
  • How do we troubleshoot an authentication issue when the problem sits somewhere between Entra, the application and connectivity?
  • How do we keep access secure and auditable while still allowing the business to move?

Networking still matters, but the role is not looking for a deep networking architect. You should understand concepts such as VNets, NAT, Private Endpoints, Private DNS and Azure Firewall, but the networking architecture is expected to remain relatively stable. The preference is for someone with deeper Entra knowledge who can grow further into networking, rather than someone who is excellent at networking but light on identity.

Because the local team is compact, you will not be one of fifty engineers maintaining a tiny corner of a giant platform. You will become one of the people others turn to when access, identity or Azure operations need to work properly.

What is asked?

  • You have strong experience as a Senior Azure Engineer, Entra Engineer, Cloud Security Engineer, Azure Consultant, IAM Engineer or similar.
  • You have worked in Azure environments where security, governance and production ownership mattered.
  • You bring hands-on experience with Microsoft Entra ID / Azure AD.
  • You have practical experience with several of the following: B2B / guest access, Conditional Access, PIM, RBAC, Enterprise Applications, App Registrations, Service Principals, SAML/OIDC or identity governance.
  • You understand Azure networking fundamentals such as VNets, NAT, Private Endpoints, Private DNS and firewalling, without necessarily being the person who designed a complex network from scratch.
  • You still enjoy hands-on engineering, troubleshooting, operational improvements and stakeholder support.
  • You can explain technical topics clearly to non-technical stakeholders and external partners.
  • You have preferably worked in an enterprise, regulated, consultancy, managed-service or Microsoft-partner environment where access and security mattered.
  • You speak fluent English.

You do not need to be a polished consultant. But you do need to be able to explain: what is the risk, what are the options, what are the trade-offs, and what do you recommend?

Because this role involves privileged access to security-sensitive infrastructure, an internal eligibility/background screening is part of the process.

What is offered?

  • Between €90,000 and €110,000 gross per year
  • Performance-based annual bonus on top
  • 27 holiday days
  • Company pension scheme
  • OV business card / travel support
  • High-quality work equipment
  • Strong learning and development budget for training, certifications and conferences
  • No standard evening or weekend standby rotation
  • Hybrid working, with a formal policy of 2 days working from home per week
  • High-quality Amsterdam WTC office
  • The chance to take visible ownership in a compact local team within a globally recognised industrial group
  • Visa sponsorship possibilities for qualifying candidates already established in the Netherlands

Ready to own secure Azure access behind the financial artery of a global industrial powerhouse?

If Entra ID, B2B access and Conditional Access are genuinely part of your expertise, and you want a role where identity and access are the main event rather than something you do on the side, then I would like to hear from you.

Send your CV to Robert Hawker via r.hawker@codeguild.nl.

Interested?

Apply right away by filling out the form below!

01/04
Hi, what's your name?
Next
How can we reach you?
Next
Upload your CV
Upload file (max. 5mb)*
Next
Tell us about yourself and why you're applying

Your message has been sent successfully

Something went wrong, please try again later

You're missing a few fields; could you check them again?