Senior Cloud Platform Security Engineer

Posted 23 hours ago

This is a fully remote position, open to applicants in United States.

📋 Description

• Take ownership of and continuously enhance Greenbox Capital’s Azure platform.

• Design, configure, operate, and maintain Azure subscriptions, management groups, networking, compute, storage, platform services, and shared infrastructure.

• Set standards for environment separation, naming conventions, tagging, approved services, secure configurations, and change management processes.

• Design and manage Microsoft Entra ID, MFA, Conditional Access, PIM, RBAC, managed identities, access reviews, and emergency-access protocols.

• Implement least-privilege and separation-of-duties principles across cloud, SaaS, administrative, and non-human identities.

• Oversee network segmentation, private connectivity, firewalls, DNS security, secure ingress/egress, and secrets management.

• Manage cloud-security posture, vulnerability remediation, configuration monitoring, logging, detection, and threat-response capabilities.

• Create alerts and dashboards and coordinate containment, recovery, evidence preservation, and corrective actions during security incidents.

• Develop and maintain infrastructure using Terraform, Bicep, or similar infrastructure-as-code methodologies.

• Create reusable modules, conduct peer reviews, implement automated testing, deployment controls, and configuration-drift management.

• Convert GLBA Safeguards Rule, SOC 2, NIST Cybersecurity Framework, customer commitments, and internal policies into actionable technical controls.

• Maintain evidence, assist with audits and customer security assessments, and address control deficiencies.

• Collaborate with Data & AI leadership on data and AI governance controls, including discovery, classification, lineage, retention, DLP, access governance, and approved AI-service controls.

• Assist in securing AI and agent-based workloads through data boundaries, privileged-action controls, logging, monitoring, human approval, and incident response strategies.

• Manage cloud budgets, alerts, tagging standards, forecasting inputs, and ongoing optimization recommendations.

• Assess Azure-native and third-party capabilities based on their effectiveness, effort, maintenance, licensing costs, and architectural alignment.

• Ensure a minimum availability of 99.9% for critical platform services under operational control.

• Support Sev-1/2 response protocols and validate disaster recovery plans at least twice a year.

• Drive at least 95% of production infrastructure towards infrastructure-as-code management.

• Achieve and maintain at least 98% compliance in resource tagging and enhance cost visibility.


⛳️ Requirements

• A minimum of seven years of hands-on experience in cloud infrastructure or security engineering.

• Proven ownership of production Azure environments with demonstrated senior-level responsibilities.

• Extensive experience with Azure subscriptions, management groups, networking, Microsoft Entra ID, RBAC, Azure Policy, monitoring, backup and recovery, security controls, and cost management.

• Proficiency in infrastructure-as-code using Terraform, Bicep, ARM templates, or similar tools.

• Experience with source control and automated deployment practices.

• Familiarity with cloud security operations, vulnerability remediation, logging and detection, incident response, access governance, and disaster-recovery testing.

• Working knowledge of Microsoft Purview or similar data governance solutions.

• Experience in translating control requirements into technical designs, operating procedures, evidence, and measurable outcomes.

• Strong documentation skills, including creating runbooks, architecture diagrams, standards, risk statements, and executive-level updates.

• Ability to coordinate effectively with internal teams, auditors, managed-service providers, and technology vendors.

• Preferred experience in financial services or other regulated environments using SOC 2, NIST Cybersecurity Framework, or similar frameworks.

• Preferred experience in securing AI, machine learning, large language models, or agent-based workloads in production.

• Relevant Microsoft certifications are preferred, including Azure Security Engineer Associate, Cybersecurity Architect Expert, Security Operations Analyst Associate, or Azure Solutions Architect Expert.

• Strong judgment, independent risk-based decision-making, effective communication, organizational skills, adaptability, and a growth mindset.


🏝️ Benefits

• Competitive compensation.

• Flexible paid time off.

• Fully remote role within the U.S.

• Flexible work hours aligned with Eastern Time.

• Comprehensive benefits package, including health, dental, and vision insurance.

People also viewed

FCamara Consulting & Training21 hours ago

Senior/Expert Power Platform Developer

BR flagBrazil OnlyFull-timePlatform Engineer
ApplyView job
Redwood Logistics22 hours ago

Platform Reliability Engineer

US flagUnited States OnlyFull-timePlatform Engineer$160k – $175k/year
ApplyView job
NVIDIA1 day ago

Senior Data and Platform Engineer

US flagCalifornia, +3 more statesFull-timePlatform Engineer$200k – $322k/year
ApplyView job
Abnormal Security1 day ago

Senior ServiceNow Platform Engineer

US flagUnited States OnlyFull-timePlatform Engineer$141.5k – $203.5k/year
ApplyView job
Marsh McLennan1 day ago

Platform Engineer

US flagUnited States OnlyFull-timePlatform Engineer$84k – $126k/year
ApplyView job
Marketscope1 day ago

GCP Platform Engineer

US flagUnited States OnlyFull-timePlatform Engineer
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers