> Markdown version of [/jobs/ext/1336113-security-administrator](https://www.wearedevelopers.com/jobs/ext/1336113-security-administrator). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Administrator - **Company:** Kuvare Holdings LLC - **Location:** Cedar Rapids, IA, United States - **Experience:** Experienced - **Salary:** $100,000.0 - $125,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Software System Penetration Testing, User Authentication, Build Automation, Microsoft Azure, Microsoft Online Services, Cloud Computing, Cloud Computing Security, Cyber Security, Databases, Disaster Recovery, Infrastructure as a Service (IaaS), Identity and Access Management, Virtual Private Networks (VPN), Python (Programming Language), Network Security, Microsoft Software, Network Segmentation, Platform as a Service (PAAS), Windows PowerShell, Role-Based Access Control, Azure Active Directory, Kusto Query Language, Software Vulnerability Management, Enterprise Software Applications, Microsoft Power Automate, HybridCloud, Firewalls (Computer Science), Microsoft InTune, Information Technology, Bicep, Microsoft Sentinel, Terraform, Devsecops, Key Vault - **Published:** July 18, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=30b89eba02cbc500 ## About the Role * 7+ years of Information Technology experience, with at least 3 years focused on Cybersecurity * Minimum of 4 years on Microsoft technologies in hands-on administration, engineering or operations capacity. * Advanced cybersecurity certifications in good standing (e.g., CEH, OSCP, AZ-500, SC-300, SC-200, SC-100). * Deep, hands-on knowledge of Microsoft services such as Defender (Cloud/Endpoint/XDR), Intune, Sentinel, and Entra ID, sufficient to operate and troubleshoot in a live environment on day one. * Extensive experience operating hybrid cloud security architecture and controls. * Strong background in security tooling administration, configuration, and tuning. * Proven experience with endpoint security and modern device management (Intune). * Advanced knowledge of network security concepts, including VPNs, firewalls, and SASE. * Demonstrated experience leading security monitoring, incident response, and day-to-day security operations. ## Description The Security Administrator is a hands-on technical role on the Information Security team, responsible for engineering, hardening, and operating security controls across a hybrid environment spanning Microsoft Azure, Microsoft Entra ID, Microsoft 365, and traditional infrastructure. This is not a policy-focused position. The ideal candidate is an accomplished Security Administrator who can walk into an existing complex environment, quickly understand the architecture, and immediately contribute to incident response, identity and access hardening, cloud security engineering, and vulnerability remediation. Success in this role requires deep, current technical expertise in Information Security, Security Operations, Microsoft Ecosystem, a DevSecOps mindset, and fluency with automation and infrastructure-as-code / security-as-code practices. The organization operates in a highly regulated financial services environment, so the candidate must apply strong engineering discipline while meeting compliance obligations. What you'll do Security Operations & Incident Response * Operate, tune, and build detections in Microsoft Sentinel (KQL for analytics rules, hunting queries, workbooks) and Microsoft Defender XDR to detect, investigate, and respond to threats. * Design and automate response with SOAR playbooks (Logic Apps / Sentinel automation rules) to reduce mean time to respond. * Lead and coordinate hands-on incident response for events such as data breaches, malware outbreaks, and identity compromises, including containment, eradication, and root-cause analysis across cloud and on-premises systems. * Partner with Security and Risk leadership to translate policies and frameworks into enforceable, technically implemented controls. * Develop, test, and validate disaster recovery and resilience strategies from a security perspective. Access Management & Compliance * Engineer and administer Microsoft Entra ID: Conditional Access, PIM, Privileged Access Groups, authentication methods, identity protection, and hybrid identity. * Manage privileged access controls and conduct recurring, evidence-based access reviews across cloud and on-premises systems. * Ensure technical controls map to financial industry regulatory and compliance requirements; produce audit-ready evidence and documentation. * Coordinate with compliance officers on security-related regulatory requirements. * Maintain asset inventory and system/component security documentation. * Coordinate and oversee third-party penetration testing and remediate findings. Security Infrastructure Management * Administer and continuously improve security solutions across our hybrid environment. * Harden PaaS/IaaS workloads and partners with engineering teams on secure-by-design cloud implementations (e.g., network segmentation, private endpoints, Key Vault, managed identities, RBAC). * Conduct regular security assessments and vulnerability scans; drive remediation to closure. * Perform periodic access and configuration reviews of enterprise systems. * Build automation and infrastructure-as-code solutions (PowerShell, Python, Bicep/ARM/Terraform) to deploy controls consistently and reliably. * Recommend and implement improvements, upgrades, and modernization of the security stack. Leadership & Guidance * Provide security architecture guidance for cloud and infrastructure initiatives. * Mentor IT team members on security best practices and secure engineering patterns. * Partner with network, application, and database teams to implement secure solutions. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Best Practices for Using GitHub Secrets](https://www.wearedevelopers.com/videos/1214-best-practices-for-using-github-secrets) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Back(end) to the Future: Embracing the continuous Evolution of Infrastructure and Code](https://www.wearedevelopers.com/videos/440-back-end-to-the-future-embracing-the-continuous-evolution-of-infrastructure-and-code) - [Develop enterprise-ready applications for Microsoft Teams with Azure resources on modern web technologies](https://www.wearedevelopers.com/videos/187-develop-enterprise-ready-applications-for-microsoft-teams-with-azure-resources-on-modern-web-technologies) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)