> Markdown version of [/jobs/ext/1447635-azure-cloud-security-engineer](https://www.wearedevelopers.com/jobs/ext/1447635-azure-cloud-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Azure Cloud Security Engineer - **Company:** RESOURCE CONSULTING SERVICES INC - **Location:** Arlington, VA, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Android Software Development, Apple IOS, Apple Mac Systems, Microsoft Azure, Cloud Computing, Cyber Security, Information Systems, Information Leak Prevention, Data Security, Identity and Access Management, Python (Programming Language), Microsoft Security Essentials, Microsoft Office, Windows PowerShell, Azure Active Directory, Phishing, Zero Trust Network Access, Runbook, Microsoft SharePoint, Data Classification, Microsoft InTune, Information Technology, Casper Suite, SailPoint, Splunk - **Published:** July 26, 2026 - **Apply:** https://www.careerjet.com/jobad/us98c61468c573dad8776a1ff905fb2601 ## About the Role This role requires expert-level, hands-on experience in the Microsoft security ecosystem coupled with deep proficiency in best-of-breed third-party tools like CrowdStrike, Splunk, and Tenable., * 7+ years of professional experience relevant experience supporting enterprise cloud and/or infrastructure environments. * Deep knowledge & hands on experience in core components of the Microsoft security and management ecosystem designed for a Zero Trust Approach. Specifically on Azure Entra, Intune and Purview (DLP, eDiscovery, Information Protection, Insider Risk Management) and Azure Conditional Access Policies for automated guardrails. * Advanced proficiency in PowerShell or Python for automating security tasks and incident response playbooks. * Expertise in using Proofpoint Targeted Attack Protection (TAP) and Threat Response Auto-Pull (TRAP) to stop phishing and malware. * Experience managing the full user lifecycle (joiner, mover, leaver) and automating provisioning / deprovisioning using SailPoint. * Experience with JAMF Pro and JAMF Protect for securing Apple endpoints within an enterprise Azure environment. * Bachelor's degree in Cybersecurity, Computer Science, or Information Systems. * Microsoft Certified Azure Security Engineer Associate (AZ-500) (Preferred) * SC-100 (Cybersecurity Architect) or CISSP (Highly Preferred) ## Description * Design and maintain complex conditional access policies incorporating device compliance, location, and risk-based signals. * Implement Privileged Identity Management (PIM) to enforce just-in-time (JIT) and just-enough-administration (JEA) for high-impact roles. * Conduct regular access reviews and manage identity lifecycles for employees, contractors, guests, and service accounts. * Configure MDM and MAM policies, including device enrolment restrictions, compliance baselines, and configuration profiles for Windows, macOS, iOS, and Android. * Oversee patching deployments and automate OS/Application patching cycles to maintain a low vulnerability footprint. * Build and tune sensitivity labels for automatic data classification across SharePoint, Teams, and Exchange. * Develop Data Loss Prevention (DLP) policies to prevent unauthorized data exfiltration. * Manage the full suite (Endpoint, Office 365, Identity, and Cloud) to investigate and remediate sophisticated threats. ## Related Videos - [Hacking MSSQL on Cloud. All of them. How I became sysadmin on Azure, AWS, GCP and Alibaba.](https://www.wearedevelopers.com/videos/100339-hacking-mssql-on-cloud-all-of-them-how-i-became-sysadmin-on-azure-aws-gcp-and-alibaba) - [Technical Documentation - How Can I Write Them Better and Why Should I Care?](https://www.wearedevelopers.com/videos/681-technical-documentation-how-can-i-write-them-better-and-why-should-i-care) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [3 Key Steps for Optimizing DevOps Workflows](https://www.wearedevelopers.com/videos/962-3-key-steps-for-optimizing-devops-workflows) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [7 Cloud Computing Trends Coming in 2025 for Developers](https://www.wearedevelopers.com/magazine/412-7-cloud-computing-trends-coming-in-2025-for-developers) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)