
Cloud Security Engineer
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in Mexico.
• Oversee the entire lifecycle of security findings and recommendations, encompassing triage, remediation, verification, and closure.
• Identify root causes of recurring issues and implement systemic solutions utilizing policy-as-code, automated guardrails, and secure baselines.
• Monitor remediation service level agreements (SLAs) and report on risk reduction and trends in security posture.
• Secure and manage authentication flows, including OIDC, OAuth 2.0 with PKCE, JWT, and mTLS.
• Administer and strengthen Microsoft Entra ID, which involves app registrations, Enterprise Application permissions, consent governance, service principals, managed identities, credential hygiene, and least-privilege configurations.
• Design, implement, and fine-tune Conditional Access policies.
• Develop and enforce Azure Policy and Terraform guardrails.
• Maintain secure-by-default infrastructure-as-code baselines and identify/remediate configuration drift.
• Operate Microsoft Defender for Cloud, enhance secure score, remediate recommendations, and manage Cloud Security Posture Management (CSPM).
• Contribute to security governance, establish standards, define controls, manage exception handling, and provide audit evidence.
• Secure cloud and SaaS administrative portals.
• Enhance privileged access through Multi-Factor Authentication (MFA), Privileged Identity Management (PIM)/just-in-time elevation, role minimization, and break-glass procedures.
• Implement security controls for AI workloads, services, and agents, focusing on identity, permission scoping, data exposure, and prompt-injection risks.
• Over 5 years of experience in cloud security or security engineering, with extensive, hands-on experience in Azure.
• Strong, practical expertise in Microsoft Entra ID, including app registrations, Enterprise Apps, permissions and consent management, and Conditional Access.
• Solid understanding of modern authentication methods such as OIDC, OAuth 2.0 / PKCE, JWT, and mTLS.
• Proficient in Terraform and Azure Policy for policy-as-code and automated guardrails.
• Experience with Microsoft Defender for Cloud and cloud security posture management.
• Proven ability to identify root causes and permanently resolve security findings rather than merely applying patches.
• Working knowledge of AI, AI agents, and related security considerations.
• Advanced proficiency in English.
• Nice to have: Experience with multi-cloud environments (AWS, GCP).
• Nice to have: Relevant certifications (e.g., Microsoft SC-100, AZ-500, SC-300; CISSP).
• Nice to have: Familiarity with CI/CD pipeline security, secrets management, and SIEM/SOAR.
• Nice to have: Skills in scripting/automation (PowerShell, Python).
• Nice to have: Practical experience securing LLM-based or agentic systems in a production environment.
• Competitive salary and performance-based bonuses.
• Comprehensive health, dental, and vision insurance.
• Flexible work hours and remote work opportunities.
• Professional development and training programs.
• Generous vacation and paid time off policies.
• Retirement savings plan with company matching.
DigitalOcean
XBOX
WSGR
Harris Computer
Get handpicked remote jobs straight to your inbox weekly.