
Cloud Security Engineer
Posted 2 hours ago

Posted 2 hours ago
This is a fully remote position, open to applicants in Colorado.
• Design, implement, and manage security controls primarily within Microsoft Azure environments.
• Lead the design and execution of cloud landing zones, as well as identity and network controls (VPC/VNet, security groups/NSGs, private endpoints).
• Configure cloud-native security services (such as Microsoft Defender for Cloud, Microsoft Sentinel, Defender XDR).
• Develop posture management (CSPM) and workload protection (CWPP) utilizing policy-as-code and automated remediation.
• Implement key management, encryption both at rest and in transit, and certificate governance using KMS/Key Vault/Cloud KMS.
• Set up logging, telemetry, and alerting (Azure Monitor) integrated with SIEM/XDR.
• Collaborate with key team members across IT and Security to test and validate the overall coverage and maturity of detection telemetry from cloud-native sources.
• Determine architecture as required to enhance the security of serverless containers and managed services (Functions, Logic Apps, Container Apps, AKS, ACI).
• Conduct threat modeling and security assessments for cloud architectures and application designs.
• Work alongside platform and product teams to implement IaC guardrails, image baselines, and patch/vulnerability workflows.
• Serve as a point of escalation for cloud incidents; perform triage, containment, and enhancements post-incident.
• Develop automation architecture where relevant to improve cloud detection and response capabilities.
• Utilize automation and AI-assisted features as appropriate to bolster cloud detection and response.
• Document standards and runbooks; conduct training sessions with development and operations teams.
• Act as a design partner in cloud security strategy and program enhancement.
• Bachelor’s degree in computer science/engineering or equivalent experience.
• 4–7 years of experience in cloud security engineering with at least one major cloud service provider.
• Strong understanding of IAM, networking, encryption, and cloud-native security tools.
• Experience securing hybrid environments that include both on-premises and Azure cloud.
• Proficiency in scripting/automation (Python/Bash/PowerShell; Terraform/Bicep/ARM).
• Certifications: CCSP; AWS Certified Security – Specialty, Azure Security Engineer Associate (AZ-500), or Google Professional Cloud Security Engineer.
• Preferred: Experience with CIEM solutions and multi-cloud governance.
• Certifications: GIAC Cloud (GCSA/GPCS), CNCF CKA/CKS, or vendor-level architect certifications.
• Medical, Dental and Vision Coverage.
• Health and Dependent Savings Accounts.
• Life and Disability Programs.
• Voluntary Benefit Programs.
• Company Sponsored Wellness Programs.
• Retirement Savings with Company Match.
• Team Member and Family Assistance Program (EAP).
• Paid Time Off and Paid Holidays.
• Employee Recognition Program with Rewards (RAVE).
Accenture Federal Services
Heinsohn
Jane
CACI International Inc
Get handpicked remote jobs straight to your inbox weekly.