> Markdown version of [/jobs/ext/1241738-cybersecurity-cloud-infrastructure-engineer](https://www.wearedevelopers.com/jobs/ext/1241738-cybersecurity-cloud-infrastructure-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cybersecurity & Cloud Infrastructure Engineer - **Company:** CHDI Management - **Location:** Princeton, NJ, United States - **Experience:** Expert - **Salary:** $120,000.0 - $180,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Amazon Web Services, Software System Penetration Testing, Microsoft Azure, Cloud Computing, Cloud Computing Security, Cloud Engineering, CompTIA Security+, Cyber Security, Data Governance, Information Leak Prevention, Data Loss, Data Security, Domainkeys Identified Mail, Domain-Based Message Authentication Reporting and Conformance (DMARC), Multi-Factor Authentication, Identity and Access Management, IT Management, Information Systems Security Architecture Professional, Python (Programming Language), Windows PowerShell, Azure Active Directory, Cloud Services, Phishing, Zero Trust Network Access, Security Information and Event Management, Software Vulnerability Management, AI Infrastructure, Data Logging, Data Processing, Scripting, Computer Networking Systems, Cloud Platform System, Data Classification, AI Platforms, Information Technology, Tenable Nessus, Microsoft Sentinel, Malware Detection, CIS Benchmarks, Splunk, Qualys - **Published:** July 11, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=f185c4acbe4f4d5f ## About the Role * Minimum 5 years of experience in an information security or cloud security engineering role. * Demonstrated experience managing vulnerability management programs, including scanning tools (e.g., Tenable, Qualys) and remediation workflows. * Hands-on experience managing and securing cloud environments in AWS and/or Microsoft Azure, including IAM, security groups, logging, and monitoring configurations. * Experience managing identity and access management platforms including AWS IAM and Microsoft Entra ID (Azure AD), including conditional access and privileged identity management. * Familiarity with AI platform security considerations, including access governance and data handling for services such as AWS Bedrock, Azure OpenAI, or equivalent. * Experience coordinating penetration testing engagements with third-party vendors and driving remediation of findings. * Strong understanding of security frameworks and standards such as NIST CSF, CIS Controls, ISO 27001, or SOC 2. * Excellent written and verbal communication skills with the ability to convey complex security concepts to non-technical stakeholders. * Demonstrated ability to establish and maintain effective working relationships across the organization. * Ability to self-initiate, manage competing priorities, and respond decisively under pressure., * Experience implementing or operating a Security Information and Event Management (SIEM) platform (e.g., Microsoft Sentinel, Splunk, or equivalent). * Familiarity with zero-trust architecture principles and implementation. * Experience with Microsoft Purview for data governance, compliance, and information protection. * Scripting or automation skills (e.g., Python, PowerShell) to support security operations and tooling. * Knowledge of data privacy regulations and compliance frameworks relevant to research organizations (e.g., GDPR, HIPAA, FISMA). * Experience in a non-profit, research, or life sciences organization. * Familiarity with ITIL best practices and IT service management frameworks., * A Bachelor's degree in a relevant field is required. One or more of the following certifications are strongly preferred: * Certified Information Systems Security Professional (CISSP) * Certified Cloud Security Professional (CCSP) * AWS Certified Security - Specialty * Microsoft Certified: Security Operations Analyst Associate (SC-200) * Microsoft Certified: Identity and Access Administrator Associate (SC-300) * CompTIA Security+ or CySA+ * Certified Ethical Hacker (CEH) or GIAC Penetration Tester (GPEN) (preferred, not required) ## Description CHDI Management is seeking an experienced and proactive Cybersecurity and Cloud Infrastructure Engineer to manage and protect the organization's data assets, cloud infrastructure, and technology systems. This individual will serve as the internal subject matter expert on cybersecurity, responsible for identifying and remediating vulnerabilities, governing identity and access across cloud platforms, and ensuring that CHDI's security posture keeps pace with an evolving threat landscape. This role carries both operational and strategic responsibilities. Day-to-day, the individual will monitor and respond to security events, manage vulnerability and penetration testing programs, and administer cloud security controls across platforms including AWS, Microsoft Azure, and Microsoft 365. Looking forward, this individual will play a key role in securing emerging AI infrastructure, including AWS Bedrock and related services as CHDI expands its use of artificial intelligence in research and operations. Reporting to the Director, Information Technology, the Cybersecurity and Cloud Infrastructure Engineer will collaborate closely with IT, researchers, the Data Protection Officer (DPO), Data Manager, and end users to embed security best practices across the organization and ensure that all systems, accounts, and data remain protected. The successful candidate will: Organization Cybersecurity * Lead the organization's vulnerability management program, including continuous scanning, prioritization, tracking, and remediation of identified vulnerabilities across endpoints, servers, cloud workloads, and applications. * Manage scheduled penetration testing engagements, including vendor selection and scoping, coordinating testing activities, reviewing findings, and driving remediation efforts to completion. * Develop and maintain a formal remediation tracking process and develop appropriate SOPs, working cross-functionally with IT and application owners to ensure timely resolution of critical and high-severity findings. * Produce clear, actionable reports on vulnerability status and remediation progress for IT leadership and organizational stakeholders. * Stay current on emerging threats, CVEs (Common Vulnerability and Exposures), and security advisories; assess organizational exposure and initiate appropriate response actions. * Manage security posture management (SPM), including Data and Cloud, tooling and ensuring findings are reviewed and addressed on a timely basis. * Monitor and respond to security events, alerts, and incidents across endpoints, cloud services, email, and network systems, maintaining documentation of investigations and remediation actions. * Manage data loss prevention (DLP) policies, information protection labels, and data classification frameworks to safeguard sensitive organizational and research data. * Administer email security controls including anti-phishing, anti-malware, and DMARC/DKIM/SPF configurations; investigate and respond to phishing reports and suspicious account activity. * Maintain and test the organization's incident response plan; lead or support incident response activities in the event of a security breach or data loss event. * Develop and deliver security awareness content and communications to help staff recognize and respond to common threats such as phishing and social engineering. * Maintain thorough documentation of security configurations, procedures, incident records, and audit evidence. * Manage vendor relationships, contracts, and invoicing for security providers; hold vendors accountable to agreed-upon service levels and deliverables. * Other duties as assigned. Cloud Infrastructure and AI Security * Administer and enforce security configurations across CHDI's cloud environments, including AWS and Microsoft Azure, ensuring alignment with security baselines and industry best practices (CIS Benchmarks, NIST, etc.). * Secure AI infrastructure and services, including AWS Bedrock and other generative AI platforms, implementing appropriate access controls, data handling policies, SOPs, and usage governance frameworks. * Monitor cloud environments for misconfigurations, anomalous activity, and policy violations using cloud-native and third-party security tools (e.g., AWS Security Hub, Microsoft Defender for Cloud). * Collaborate with infrastructure and application teams to embed security requirements into cloud architecture decisions and new service deployments. Identity and Access Management * Administer and govern identity and access management (IAM) across cloud platforms, including AWS IAM, Microsoft Entra ID (Azure AD), and related services, enforcing least-privilege principles and role-based access controls. * Work with CHDI's DPO and Data Manager providing appropriate access to cloud-based assets. * Manage multi-factor authentication (MFA), conditional access policies, and privileged identity management (PIM) configurations to protect against unauthorized access. * Conduct periodic access reviews and entitlement certifications, working with department heads to validate that user permissions remain appropriate and aligned with job function. * Oversee the join/move/leave process from a security perspective, ensuring timely provisioning and de-provisioning of access across all systems and platforms. ## Related Videos - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Skynet wants your Passwords! The Role of AI in Automating Social Engineering](https://www.wearedevelopers.com/videos/770-skynet-wants-your-passwords-the-role-of-ai-in-automating-social-engineering) - [MFA? Game over! Watch your protection collapse – live](https://www.wearedevelopers.com/videos/100322-mfa-game-over-watch-your-protection-collapse-live) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [7 Cloud Computing Trends Coming in 2025 for Developers](https://www.wearedevelopers.com/magazine/412-7-cloud-computing-trends-coming-in-2025-for-developers)