
Infrastructure & Security Engineer
Posted Aug 7

Posted Aug 7
This is a fully remote position, open to applicants in United States.
• Examine phishing attacks, questionable login activities, and incidents of account breaches.
• Conduct threat hunting, analyze logs, and handle containment and remediation efforts.
• Spearhead response initiatives for security events related to Microsoft 365 and Azure.
• Work in collaboration with security partners and vendors during ongoing incidents.
• Execute post-incident evaluations and enhance prevention strategies.
• Design and refine Conditional Access policies along with identity security controls.
• Oversee and optimize Microsoft Defender and Entra ID security functionalities.
• Apply security baselines and hardening standards across client environments.
• Enhance multi-factor authentication (MFA), privileged access, and identity governance workflows.
• Provide support and troubleshoot issues within Azure infrastructure and Azure Virtual Desktop environments.
• Manage complex escalations that involve networking, virtualization, storage, and authentication challenges.
• Direct migrations related to Microsoft 365, Azure, servers, and cloud infrastructure.
• Assist with automation and initiatives related to infrastructure-as-code.
• Act as the Tier 3 escalation point for advanced technical problems.
• Guide junior engineers and contribute to the establishment of technical standards.
• Produce documentation, operational runbooks, and standardized processes.
• Identify recurring issues and develop long-term resolutions.
• Stay accessible during P1 incidents.
• Over 5 years of progressive experience in IT.
• Minimum of 2 years concentrated on security operations.
• Extensive experience with the Microsoft 365 security stack, including Defender for Office 365, Defender for Endpoint, Defender for Identity, Entra ID Protection, and Conditional Access at scale.
• Strong foundational knowledge of Azure, including Entra ID, Azure Virtual Desktop, VNets, NSGs, Private Endpoints, and RBAC.
• Familiar with infrastructure-as-code tools, particularly Bicep or Terraform.
• Comprehensive incident response experience with real-world BEC, ransomware incidents, or account takeovers.
• Proficient in PowerShell scripting for administrative automation, including Microsoft 365/Azure modules, and troubleshooting or modifying scripts.
• Exceptional writing skills for incident reports, root cause analysis documents, and summaries for clients.
• Capacity to work remotely from the East Coast or Central US.
• Availability to remain reachable during P1 incidents.
• Preferable certifications: SC-200, SC-300, or AZ-500.
• Desirable operational experience with Blackpoint Cyber MDR.
• Valuable experience with HaloPSA, NinjaOne/NinjaRMM, CIPP, Hudu, and Barracuda Email Protection.
• Preferable experience in designing CIS- or NIST CSF-aligned baselines for SMB clients using Microsoft 365 and Azure.
• Willingness to undergo a background check.
• Annual performance bonus linked to security KPIs (mean time to detect, mean time to contain, reduction of recurring incidents).
• Health insurance coverage.
• Simple IRA retirement plan.
• Starting with 12 days of paid time off (PTO), with accrual increasing based on tenure.
• 8 paid holidays each year.
• Stipend for home office setup.
• Flexibility to work remotely.
Legacy Community Health
NeoGuardian
Fresh Consulting
CrowdStrike
Get handpicked remote jobs straight to your inbox weekly.