
Azure Security Engineer
Posted 16 hours ago

Posted 16 hours ago
This is a fully remote position, open to applicants in United States.
• Create Azure cloud solutions with a focus on security from the ground up.
• Work alongside customer IT teams to deploy and safeguard cloud resources.
• Construct scalable and robust architectures for Azure Commercial and Azure Gov Cloud.
• Formulate migration strategies and plans to transition from on-premises environments to Azure.
• Secure systems and data within Microsoft Entra ID and Azure-based environments.
• Generate architectural and data flow diagrams.
• Develop and implement Infrastructure as Code (IaC) utilizing Terraform, ARM templates, Bicep, and PowerShell.
• Guarantee high availability, disaster recovery, monitoring, and alerting mechanisms.
• Assess and recommend Azure services aligned with business needs.
• Integrate Azure solutions with both new and existing systems and applications.
• Act as a Subject Matter Expert (SME) for Azure AI Foundry, encompassing generative AI, machine learning, RAG, Responsible AI, content safety, and guardrails.
• Protect AI workloads through the use of private endpoints, managed identities, customer-managed keys, and least-privilege access principles.
• Serve as an SME for Azure API Management, designing secure and scalable API gateways.
• Write APIM policies for OAuth 2.0, JWT validation, mutual TLS, rate limiting, caching, transformation, and routing.
• Design APIM to function as a GenAI gateway for Azure AI Foundry and Azure OpenAI.
• Integrate APIM with Entra ID, Application Gateway/WAF, private networking, and self-hosted gateways.
• Establish API governance, lifecycle management, developer portals, and observability practices.
• Define and uphold Azure governance policies, covering aspects such as subscription, cost, security, identity, and deployment policies.
• Support DevOps methodologies and Continuous Integration/Continuous Deployment (CI/CD) pipelines.
• Lead technical discussions and presentations for both internal teams and clients.
• Generate customer deliverables, internal procedures, and delivery playbooks.
• Provide training and mentorship on Azure technologies to staff.
• Engage in strategic planning, development of training materials, and tool creation.
• Keep abreast of emerging Azure technologies and undertake additional duties as required.
• Bachelor’s Degree with 5 years of experience in building or managing cloud environments within medium to large organizations.
• Professional certification in Azure, such as Azure Solutions Architect Expert or a similar qualification, is preferred.
• Comprehensive understanding of cloud computing technologies, business drivers, and emerging trends in computing.
• Proficient in Azure services, including Entra ID, Azure Virtual Networks/Machines, Azure App Services, Azure Kubernetes Service, Azure Key Vault, and Azure Private Link/Private Endpoint.
• SME-level expertise in Azure AI Foundry, covering model catalog and deployment, AI agents, prompt flow, RAG architectures, evaluations, and Responsible AI/content safety controls.
• SME-level knowledge in Azure API Management, including gateway architecture, policy authoring, API security and versioning, developer portals, self-hosted gateways, and GenAI/AI gateway applications.
• Experience with Azure OpenAI and generative AI patterns, such as prompt engineering, embeddings, and vector/semantic search.
• Hands-on experience with Azure Kubernetes Service (AKS), Azure Container Registry, and Azure Container Apps.
• Familiarity with Azure Monitor, Log Analytics, Application Insights, and Microsoft Defender for Cloud.
• Understanding of the Azure Well-Architected Framework and Cloud Adoption Framework landing zones.
• Proficient in PowerShell, Azure CLI, and at least one general-purpose programming language like Python.
• Experience designing Zero Trust architectures and implementing security controls for AI and API workloads.
• Knowledge of FinOps and Azure cost management, including AI token consumption and API usage expenses.
• Relevant Azure certifications such as AI-102, AZ-500, or AZ-700 are advantageous.
• Must complete either the CCSK or (ISC)2 Certified Cloud Security Professional certification within 6 months of employment.
• Experience in cloud security, networking, and disaster recovery best practices.
• Strong understanding of Infrastructure as Code (IaC) tools, such as ARM templates or Terraform.
• Familiarity with network security best practices and configurations.
• Excellent troubleshooting abilities, attention to detail, and strong written and verbal communication skills, as well as presentation capabilities.
• Ability to address technical, managerial, or operational challenges and assess various options.
• Capacity to leverage emerging AI technologies to enhance business outcomes.
• Sedentary work; substantial wrist, hand, and/or finger movement and close visual acuity are required for at least 8 hours daily.
• Primarily a remote workforce; U.S. based only.
• Group Medical Insurance options: Zero Deductible PPO Plan with GuidePoint covering 90% of employee premiums and 70% of family premiums.
• High Deductible Health Plan with HSA; GuidePoint pays 100% of employee premiums and 75% of family premiums.
• Annual HSA contribution of $850 for employees or $1,750 for family coverage.
• Group Dental Insurance; GuidePoint pays 100% of employee premiums and 75% of family premiums.
• 12 corporate holidays.
• Flexible Time Off (FTO) program.
• Healthy mobile phone and home internet allowance.
• Eligibility for retirement plan after 2 months during open enrollment.
• Pet Benefit Option.
• Up to 10% travel.
Zscaler
Viatris
ActBlue
AlphaSense
Get handpicked remote jobs straight to your inbox weekly.