
Cloud Security Engineer
Posted Aug 28

Posted Aug 28
This is a fully remote position, open to applicants in Mexico.
• Take ownership of the entire lifecycle of security findings and recommendations, including triage, remediation, verification, and closure.
• Identify root causes of recurring issues and implement systemic solutions using policy-as-code, automated guardrails, and secure baselines.
• Monitor remediation SLAs and provide reports on risk reduction and trends in security posture.
• Ensure security and governance of authentication flows such as OIDC, OAuth 2.0 with PKCE, JWT validation and handling, and mTLS.
• Manage and strengthen Microsoft Entra ID, covering app registrations, Enterprise Application permissions, consent governance, service principals, managed identities, credential hygiene, and least-privilege scoping.
• Design, implement, and continuously optimize Conditional Access policies.
• Develop and enforce guardrails using Azure Policy and Terraform.
• Maintain secure-by-default infrastructure-as-code baselines and address configuration drift.
• Operate Microsoft Defender for Cloud to enhance secure scores, remediate recommendations, and manage CSPM.
• Contribute to security governance by defining standards, control definitions, exception handling, and gathering audit evidence.
• Secure cloud and SaaS administrative portals, including Azure, Microsoft 365 admin, and identity providers.
• Enhance privileged access through MFA, PIM/just-in-time elevation, role minimization, and break-glass procedures.
• Implement security controls for AI workloads, services, and AI agents, focusing on identity, tool and permission scoping, data-exposure mitigation, and prompt-injection risk mitigation.
• Over 5 years of experience in cloud security or security engineering, with extensive, hands-on expertise in Azure.
• Strong practical knowledge of Microsoft Entra ID, encompassing app registrations, Enterprise Apps, permissions and consent, and Conditional Access.
• Solid understanding of OIDC, OAuth 2.0 / PKCE, JWT, and mTLS protocols.
• Proficient in Terraform and Azure Policy for policy-as-code and automated guardrails.
• Experience with Microsoft Defender for Cloud and cloud security posture management.
• Proven ability to identify root causes and permanently resolve security findings.
• Familiarity with AI, AI agents, and AI security considerations.
• Resilient, emotionally intelligent, and focused on agile delivery.
• In-depth understanding of the distinctions between coding and engineering.
• Advanced proficiency in oral English.
• Advanced proficiency in Spanish.
• Experience with multiple clouds, including AWS and GCP.
• Relevant certifications such as Microsoft SC-100, AZ-500, SC-300, or CISSP.
• Background in CI/CD pipeline security, secrets management, and SIEM/SOAR.
• Proficient in scripting/automation using PowerShell or Python.
• Hands-on experience securing LLM-based or agentic systems in a production environment.
• Familiarity with cloud-native foundations or AI coding assistants.
• Work remotely.
• Flexibility to accommodate your lifestyle.
• Opportunities for global career advancement.
• Involvement in high-impact projects.
• Engagement with world-class, high-impact initiatives.
• Collaboration with international teams.
• Access to a global network of expertise.
• Work for an award-winning employer.
• Contribute to a sustainable corporation.
Sony Interactive Entertainment
Squads
Neo4j
PingWind Inc. (SDVOSB)
Get handpicked remote jobs straight to your inbox weekly.