Job Description
Position Title: Security Engineer, Cloud
Position Location: Remote in the United States
The Cloud Security Engineer is responsible for securing and improving the organization’s cloud environments, with a primary focus on Microsoft Azure. This role partners closely with platform, engineering, infrastructure, and Security Operations teams to implement cloud security governance, secure architecture patterns, identity and access controls, monitoring capabilities, and compliance-aligned security controls. The ideal candidate combines hands-on Azure security expertise with strong knowledge of cloud governance, landing zone architecture, and secure deployment practices to help create a cloud environment that is secure, scalable, and operationally sustainable by design.
Essential Functions:
• Design, implement, and maintain cloud security guardrails across Microsoft Azure environments, including subscription governance, resource organization, role-based access controls, and secure configuration baselines.
• Develop and support Azure landing zone architectures, including management group hierarchy, policy enforcement, governance standards, tagging strategies, and security controls that minimize organizational risk.
• Configure and maintain cloud security capabilities including encryption, secrets management, logging, monitoring, alerting, and secure remote administration solutions.
• Collaborate with platform, engineering, and infrastructure teams to conduct architecture reviews and implement secure cloud networking and hardening initiatives.
• Perform cloud security posture reviews to identify misconfigurations, excessive permissions, security gaps, and compliance drift within cloud environments.
• Support the investigation, detection, and remediation of cloud security incidents in partnership with Security Operations and infrastructure teams.
• Develop and maintain technical documentation and evidence demonstrating cloud security control implementation, monitoring, and compliance alignment.
• Support secure infrastructure-as-code (IaC) and deployment practices by establishing repeatable security guardrails and standards across environments.
• Provide recommendations for secure connectivity, segmentation, workload hardening, and monitoring coverage to improve cloud security maturity.
• Coordinate with Security Operations, Governance Risk and Compliance (GRC), architecture teams, and auditors to support cloud control validation and compliance reviews.
• Enable engineering and delivery teams to adopt secure cloud development and deployment practices while ensuring security requirements are measurable and consistently applied.
Required Skills/Abilities/Competencies:
• Strong knowledge of Microsoft Azure cloud security architecture, including subscription governance, resource organization, and role-based access control (RBAC).
• Experience designing and implementing Azure landing zones, management group structures, governance frameworks, and policy-based security controls.
• Expertise in cloud identity and access management, privileged access controls, policy enforcement, secrets management, encryption, logging, and monitoring.
• Strong understanding of cloud networking, segmentation, workload hardening, and secure connectivity principles.
• Experience conducting cloud security assessments, posture reviews, and remediation planning.
• Ability to build, refine, and support cloud detection capabilities and coordinate cloud security investigations and response activities.
• Working knowledge of infrastructure-as-code (IaC) and policy-as-code concepts, including secure and repeatable deployment methodologies.
• Proficiency in scripting, automation, and cloud operational tooling to improve security effectiveness and efficiency.
• Ability to document technical architectures, communicate security requirements clearly, and collaborate effectively with technical and non-technical stakeholders.
• Experience mapping cloud security controls to audit, compliance, and evidence requirements.
• Knowledge of centralized logging, security monitoring, and detection engineering practices within cloud environments.
• Strong analytical, problem-solving, collaboration, and project coordination skills.
• Demonstrated competencies in Cloud Security Engineering, Azure Governance, Cloud Identity and Access Management, Secure Networking, Logging and Monitoring, Secrets Management, Cloud Posture Management, Infrastructure as Code Security, and Architecture Review.
Education and Experience:
• Bachelor's degree in Computer Science, Information Technology, Cybersecurity, Engineering, or a related field; or an equivalent combination of education and relevant professional experience.
• Minimum of three (3) years of hands-on cloud security, cloud infrastructure security, or related cybersecurity experience.
• Experience implementing and supporting Microsoft Azure security controls, governance frameworks, and cloud architecture best practices.
• Experience performing cloud security assessments, control reviews, remediation planning, and security posture management activities.
• Experience with infrastructure-as-code, cloud automation, and cloud architecture concepts.
• Experience supporting audit, compliance, and evidence collection activities related to cloud security controls is preferred.
• Familiarity with Microsoft Defender for Cloud or equivalent cloud security posture management and cloud workload protection tools is preferred.
• Exposure to AWS and/or Google Cloud Platform (GCP) environments is preferred, particularly in multi-cloud governance or security programs.
• Experience participating in cloud architecture reviews, landing zone implementations, or cloud security assessments is preferred.
• Relevant certifications such as Microsoft Azure Security Engineer (AZ-500), CISSP, CCSK, or equivalent cloud security certifications are preferred.
Physical Requirements:
• Prolonged periods of sitting at a desk and working on a computer.
• Must be able to lift up to 15 pounds at times.