
Senior Azure Cloud Security Engineer
Posted Sep 9

Posted Sep 9
This is a fully remote position, open to applicants in United States.
• Design, implement, and oversee security architecture and controls within Microsoft Azure environments.
• Act as a senior technical expert on Azure cloud security and industry best practices.
• Ensure the security of Azure subscriptions, management groups, resource groups, networking, storage, compute, databases, containers, and various cloud services.
• Manage and implement Microsoft Defender for Cloud, Microsoft Sentinel, Azure Policy, Microsoft Entra ID, Key Vault, and related Microsoft security solutions.
• Design and uphold Identity and Access Management (IAM) controls, including Role-Based Access Control (RBAC), Conditional Access, Privileged Identity Management (PIM), managed identities, service principals, and least-privilege access principles.
• Create and enforce cloud security policies, standards, guardrails, and configuration baselines.
• Identify and resolve cloud vulnerabilities, configuration flaws, excessive permissions, and other security threats.
• Collaborate with engineering teams to integrate security throughout the Continuous Integration/Continuous Deployment (CI/CD) and DevSecOps lifecycle.
• Assess Terraform, Bicep, and/or ARM template deployments for security vulnerabilities and compliance.
• Implement Azure networking security measures such as Virtual Networks (VNets), Network Security Groups (NSGs), Azure Firewall, Private Endpoints, Application Gateway/WAF, and related technologies.
• Facilitate logging, monitoring, threat detection, and incident response across Azure environments.
• Develop detection rules, alerts, dashboards, and automated security responses.
• Investigate cloud security incidents and aid in root-cause analysis and remediation efforts.
• Conduct security assessments for new Azure services, applications, architectures, and third-party integrations.
• Review proposed cloud architectures and provide security recommendations to architecture and engineering teams.
• Automate security processes and controls utilizing PowerShell, Azure CLI, Python, or similar technologies.
• Support compliance initiatives related to regulations and security standards such as NIST, CIS, ISO 27001, SOC 2, PCI DSS, or similar frameworks.
• Mentor junior engineers and offer technical leadership on cloud security projects.
• Stay up-to-date with emerging Azure threats, vulnerabilities, Microsoft security capabilities, and cloud security best practices.
• Over 7 years of experience in information security, infrastructure security, cloud engineering, or a comparable technical field.
• At least 4 years of practical Microsoft Azure security experience in enterprise settings.
• In-depth understanding of Azure architecture and security principles.
• Advanced experience with Microsoft Entra ID (Azure AD), RBAC, Conditional Access, PIM, MFA, managed identities, and service principals.
• Practical experience with Microsoft Defender for Cloud and Azure security posture management.
• Familiarity with Microsoft Sentinel or another enterprise SIEM platform.
• Strong comprehension of Azure networking and network security protocols.
• Experience in securing Azure IaaS and PaaS services.
• Solid understanding of encryption, secrets management, certificates, and Azure Key Vault.
• Proven experience in implementing security via Azure Policy and cloud governance controls.
• Background in vulnerability management and cloud security posture management.
• Experience in securing CI/CD pipelines and DevOps environments.
• Working knowledge of Infrastructure-as-Code technologies such as Terraform, Bicep, or ARM templates.
• Proficiency in scripting or automating tasks using PowerShell, Python, Azure CLI, or similar technologies.
• Strong understanding of Zero Trust principles, least privilege, defense-in-depth strategies, network segmentation, and secure-by-design architecture.
• Ability to troubleshoot complex security challenges across cloud infrastructure, networking, identity, and applications.
• Excellent communication skills with both technical and non-technical stakeholders.
• Preferred: experience securing large-scale or highly regulated Azure environments.
• Preferred: experience with Azure Kubernetes Service (AKS), container security, and Kubernetes security.
• Preferred: experience with Microsoft Defender XDR and the broader Microsoft security ecosystem.
• Preferred: experience with CSPM, CNAPP, Wiz, Prisma Cloud, Orca Security, or similar technologies.
• Preferred: experience integrating security tools into CI/CD pipelines.
• Preferred: experience with GitHub Actions, Azure DevOps, or similar platforms.
• Preferred: familiarity with NIST CSF, NIST 800-53, CIS Benchmarks, ISO 27001, SOC 2, and PCI DSS.
• Preferred: experience in financial services, healthcare, insurance, or other highly regulated industries.
• Preferred certifications include Microsoft Certified: Azure Security Engineer Associate; Microsoft Certified: Cybersecurity Architect Expert; Microsoft Certified: Azure Solutions Architect Expert; CISSP; CCSP; equivalent security certification; and relevant Terraform, Kubernetes, or cloud security certifications.
• Long-term contract.
Sony Interactive Entertainment
Squads
Neo4j
PingWind Inc. (SDVOSB)
Get handpicked remote jobs straight to your inbox weekly.