Overview
Hybrid3 days week in office
Depends on Experience
Full Time
No Travel Required
Skills
Azure
"cloud security"
"cloud networking"
"cloud architecture"
OAuth2
SAML
Script
Job Details
Our client is a top financial services firm, seeking a Senior Azure Cloud Security Engineer with deep expertise in Azure security best practices, cloud networking, and cloud architecture and design.
This role is critical in ensuring the security, compliance, and resilience of our Azure-hosted infrastructure and services. The ideal candidate will be a strategic thinker and technical leader, capable of both guiding secure cloud architecture and diving into technical implementations.
Key Responsibilities:
- Design and implement secure cloud solutions across Azure and AWS based on industry best practices and organizational requirements.
- Provide subject matter expertise on cloud security for enterprise architecture reviews and strategic planning.
- Develop and enforce cloud security baselines, guardrails, and automation for threat detection and response.
- Lead threat modeling, security risk assessments, and cloud configuration reviews across the cloud environments.
- Conduct regular security assessments, threat modeling, and vulnerability scans in cloud environments.
- Architect and secure cloud networking configurations including VNETs, VPCs, subnets, security groups, firewalls, VPN, and hybrid connectivity.
- Implement secure identity and access controls using Azure AD, AWS IAM, RBAC, Conditional Access, and PIM.
- Ensure compliance with industry frameworks (e.g., NIST, CIS Benchmark, SOC 2, GDPR).
- Investigate and respond to security incidents and alerts, coordinating with the SOC as needed.
- Provide technical mentorship and guidance to junior engineers and cross-functional teams.
Required Qualifications:
- Bachelor s degree in Computer Science, Information Security, Engineering, or related field (or equivalent experience).
- 7+ years of hands-on experience in cloud security engineering
- Deep knowledge of Azure networking, including routing, NSGs, firewalls, DNS, load balancers, and hybrid connectivity.
- Strong understanding OAuth2/OIDC, SAML, and modern identity governance with respect to cloud
- Understanding of DevOps CI/CD pipelines
- Understanding of containerization (e.g., Kubernetes)
- Proficiency in scripting and automation (e.g., PowerShell, Python, Bash).
- Experience with security monitoring and incident response in cloud-native environments.
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.