
Senior Cloud Platform Security Engineer
Posted 23 hours ago

Posted 23 hours ago
This is a fully remote position, open to applicants in United States.
• Take ownership of and continuously enhance Greenbox Capital’s Azure platform.
• Design, configure, operate, and maintain Azure subscriptions, management groups, networking, compute, storage, platform services, and shared infrastructure.
• Set standards for environment separation, naming conventions, tagging, approved services, secure configurations, and change management processes.
• Design and manage Microsoft Entra ID, MFA, Conditional Access, PIM, RBAC, managed identities, access reviews, and emergency-access protocols.
• Implement least-privilege and separation-of-duties principles across cloud, SaaS, administrative, and non-human identities.
• Oversee network segmentation, private connectivity, firewalls, DNS security, secure ingress/egress, and secrets management.
• Manage cloud-security posture, vulnerability remediation, configuration monitoring, logging, detection, and threat-response capabilities.
• Create alerts and dashboards and coordinate containment, recovery, evidence preservation, and corrective actions during security incidents.
• Develop and maintain infrastructure using Terraform, Bicep, or similar infrastructure-as-code methodologies.
• Create reusable modules, conduct peer reviews, implement automated testing, deployment controls, and configuration-drift management.
• Convert GLBA Safeguards Rule, SOC 2, NIST Cybersecurity Framework, customer commitments, and internal policies into actionable technical controls.
• Maintain evidence, assist with audits and customer security assessments, and address control deficiencies.
• Collaborate with Data & AI leadership on data and AI governance controls, including discovery, classification, lineage, retention, DLP, access governance, and approved AI-service controls.
• Assist in securing AI and agent-based workloads through data boundaries, privileged-action controls, logging, monitoring, human approval, and incident response strategies.
• Manage cloud budgets, alerts, tagging standards, forecasting inputs, and ongoing optimization recommendations.
• Assess Azure-native and third-party capabilities based on their effectiveness, effort, maintenance, licensing costs, and architectural alignment.
• Ensure a minimum availability of 99.9% for critical platform services under operational control.
• Support Sev-1/2 response protocols and validate disaster recovery plans at least twice a year.
• Drive at least 95% of production infrastructure towards infrastructure-as-code management.
• Achieve and maintain at least 98% compliance in resource tagging and enhance cost visibility.
• A minimum of seven years of hands-on experience in cloud infrastructure or security engineering.
• Proven ownership of production Azure environments with demonstrated senior-level responsibilities.
• Extensive experience with Azure subscriptions, management groups, networking, Microsoft Entra ID, RBAC, Azure Policy, monitoring, backup and recovery, security controls, and cost management.
• Proficiency in infrastructure-as-code using Terraform, Bicep, ARM templates, or similar tools.
• Experience with source control and automated deployment practices.
• Familiarity with cloud security operations, vulnerability remediation, logging and detection, incident response, access governance, and disaster-recovery testing.
• Working knowledge of Microsoft Purview or similar data governance solutions.
• Experience in translating control requirements into technical designs, operating procedures, evidence, and measurable outcomes.
• Strong documentation skills, including creating runbooks, architecture diagrams, standards, risk statements, and executive-level updates.
• Ability to coordinate effectively with internal teams, auditors, managed-service providers, and technology vendors.
• Preferred experience in financial services or other regulated environments using SOC 2, NIST Cybersecurity Framework, or similar frameworks.
• Preferred experience in securing AI, machine learning, large language models, or agent-based workloads in production.
• Relevant Microsoft certifications are preferred, including Azure Security Engineer Associate, Cybersecurity Architect Expert, Security Operations Analyst Associate, or Azure Solutions Architect Expert.
• Strong judgment, independent risk-based decision-making, effective communication, organizational skills, adaptability, and a growth mindset.
• Competitive compensation.
• Flexible paid time off.
• Fully remote role within the U.S.
• Flexible work hours aligned with Eastern Time.
• Comprehensive benefits package, including health, dental, and vision insurance.
FCamara Consulting & Training
Redwood Logistics
NVIDIA
Abnormal Security
Get handpicked remote jobs straight to your inbox weekly.