Job Description
The Sr. Azure Cloud Security Engineer will be responsible for driving, implementing, managing, monitoring, and governance of AssureCare s Azure Security and Threat Operations to ensure that we remain proactively positioned with the ever-evolving threat and compliance landscape.
To achieve this goal, this person will drive, collaborate on, and implement secure designs, contribute changes to our infrastructure-as-code by implementing security controls as necessary, develop and cultivate threat models, countermeasures, and compensating controls. Additionally, this person will drive the design and deployment of new tools to continue improving our security posture. As such, the Sr. Azure Cloud Security Engineer is expected to stay abreast with emerging Azure Cloud technologies and implementations, as well as their impact on the security landscape.
You will use your technical experience to assess, design, engineer, implement, and manage security operational controls and tooling. These controls will be aligned and focused on maintaining compliance with AssureCare's security standards including but not limited to SOC2 TypeII, HITRUST CSF, NIST SP800-53 (Rev5), and FedRamp Moderate.
The Sr. Azure Cloud Security Engineer will partner with infrastructure, DevOps, and Security teams on security strategy, implementation, and management.
We are looking for individuals with a passion for security, technology, and innovation. Individuals should be champions of security who are eager to work on a collaborative team to drive change, create security tools and services, and to solve problems ultimately protecting AssureCare's intellectual property, data, and customer data.
Essential Duties / Responsibilities
Strategic
- Serve as an Azure security SME and provide guidance on industry best practices and in-depth defense strategies
- Contribute to the ongoing support, development, and maintenance of the infosec and risk management program
- Provide technical expertise on trends and emerging changes to Azure cloud security landscape
- Key member of the Detection and Incident Response team to operationalize newly developed security capabilities and perform investigations related to security incidents
Proactive
- Research, design, collaborate, Implement, maintain and monitor security solutions for AssureCare including but not limited to Azure advanced DDoS protection, NextGen Firewalls, host and network-based intrusion detection and intrusion prevention, WAFs, Application Gateways, load balancers, continuous security monitoring and risk assessment for our Azure cloud infrastructure
- Proactively identify security issues, recommend, collaborate on, and implement configuration remediations
- Identify opportunities for security improvement of our cloud infrastructure and services
- Analyze and make recommendations to improve security of our cloud infrastructure, platform, and architectures
- Examine network, server, application, and aggregated logs to determine trends and identify security incidents
- Ensure implementation of security and compliance requirements are met and maintained
- Security review of proposed new tooling, components, products, and systems including AI.
Tactical/Daily
- Maintain and create security and operational controls to enforce AssureCare's security policies
- Work closely with the Infrastructure, DevOps, and Security teams to resolve security related configuration issues
- Develop, document, and maintain security and compliance architecture standards for our Azure cloud
- Assess, measure, and communicate the risk impact of identified security deficiencies and remediate as appropriate
- Implement, review, and maintain strong access controls and identity roles within Azure IAM
- Maintain and improve continuous monitoring of Azure resources
- Review and approve controls needed to protect AssureCare technology assets and data
- Configure and troubleshoot security infrastructure resources
- Collaborate with DevOps to ensure cloud security for promoting DevSecOps
- Participate in the ongoing maintenance, testing, and improving the incident response program
- Work with Infrastructure, DevOps, and security Teams to ensure security is factored into evaluation and deployment
- Assist in the review and updates to infosec policies, architectures, and standards
- Assists in responding to audits, penetration tests and vulnerability assessments
- Drive ongoing hardening of the Azure infrastructure utilizing CIS Benchmark 2.0
- Monitor vulnerability feeds and prioritize findings; manage, monitor, and track completion in a POA&M list
Qualifications/Skills Requirements
- Expertise with Azure Virtual Networks, Azure Virtual WAN, ExpressRoute, VPN Gateway, Azure Firewall, Azure Front Door, Application Gateway, Web Application Firewall, Network Watcher, Traffic Manager, Private Link, Private DNS, Azure DNS, Active Directory, and Microsoft Entra ID.
- Five or more years of experience implementing, enhancing, and operationally managing security solutions in Microsoft Azure.
- Provide hands-on architecture leadership for Azure hosting infrastructure and networking, including Virtual Networks, Virtual WAN, ExpressRoute, VPN connectivity, firewalls, private connectivity, ingress and egress architecture, DNS, load balancing, high availability, resiliency, disaster recovery, and business continuity.
- Lead the secure and compliant adoption and integration of Azure AI services, including Azure AI Foundry, within hosted application environments.
Big Pluses to Have
- Information Risk or Security Certifications - (Azure Security AZ-500, CISSP, CCSP, CIAM)
- Experience working with container-based architectures
- Have worked in a rapid-growth software development/SaaS organization before
Personal Attributes
- Self-driven; motivated and possesses the ability to work independently with little or no supervision
- Excellent inter-personal skills: ability to interact with all layers of personnel
- Ability to communicate learnings gleaned from analysis in a clear, concise manner
- Outstanding written, verbal, and presentation skills
- Strong attention to detail
- Experience working with virtual teams in a global environment
- Adaptable and agile
- Good interpersonal, partnership, and leadership skills (without direct authority of others)
- Thrives in a fast-moving work environment