Remote job
Cloud Azure Security Engineer
Job details
About this role
Role overview A consulting technology services team is hiring a Cloud Azure Security Engineer to safeguard client Microsoft Azure environments. The role centers on assessing cloud posture, hardening identity and access, and engineering automated controls across infrastructure, networks, and applications. Hands-on Microsoft Entra ID expertise is mandatory, with broad responsibility for compliance, remediation, and incident response.
Responsibilities - Evaluate Azure infrastructure, applications, and data for vulnerabilities, misconfigurations, and compliance gaps - Develop and maintain cloud security policies, controls, and procedures aligned with industry and regulatory standards - Translate business and stakeholder requirements into concrete security controls and policies - Conduct audits and assessments, validating policy adherence and surfacing improvement opportunities - Guide engineering and operations teams on remediation and security best practices - Manage identity and access using Entra ID, Conditional Access, Privileged Identity Management, and identity governance - Automate controls and remediation through Terraform, GitHub Actions, PowerShell, Python, or Azure CLI - Investigate findings, participate in incident response, and monitor emerging cloud threats
Requirements - 2+ years of cloud security engineering experience focused on Microsoft Azure - Hands-on Microsoft Entra ID experience (users, groups, roles, RBAC, service principals, managed identities, app registrations) - Practical knowledge of MFA, risk-based access, device-based controls, and least-privilege design in Conditional Access - Experience with Privileged Identity Management, access reviews, and identity governance - Familiarity with authentication protocols (SAML, OAuth 2.0, OpenID Connect) - Scripting/automation proficiency with PowerShell, Python, or Azure CLI - English proficiency at B2 level or higher
Nice to have - Bachelor's or master's degree in Computer Science, IT, or related field - Microsoft Defender for Cloud, Sentinel, Azure Firewall, Azure Policy, Key Vault, and NSG expertise - Terraform and GitHub Actions experience, plus container technologies - Certifications such as Azure Security Engineer (AZ-500), Identity and Access Administrator (SC-300), or CCSP