> Markdown version of [/jobs/ext/1807825-sr-security-engineer-cloud-infrastructure](https://www.wearedevelopers.com/jobs/ext/1807825-sr-security-engineer-cloud-infrastructure). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Sr. Security Engineer, Cloud Infrastructure - **Company:** VACO LLC - **Location:** Tampa, FL, United States - **Experience:** Expert - **Salary:** $135,200.0 - $145,600.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Proxy Servers, Systems Engineering, Audit Trail, Microsoft Azure, Microsoft Online Services, Software as a Service, Cloud Computing, Cloud Computing Security, Cyber Security, System Configuration, Information Leak Prevention, Domain Name System (DNS), Identity and Access Management, Virtual Private Networks (VPN), Network Security, Microsoft Security Essentials, Role-Based Access Control, Remote Access Technology, Web Application Security, Security Information and Event Management, Software Vulnerability Management, EndPointSecurity, Data Logging, Transport Layer Security, Data Classification, Software Troubleshooting, Firewalls (Computer Science), Microsoft InTune, CIS Benchmarks - **Published:** July 7, 2026 - **Apply:** https://diversityjobs.com/main/sendform/8/8/28176/1/17503517?backUrl=%2Fcareer%2F17503517%2FSr-Security-Engineer-Cloud-Infrastructure-Florida-Tampa ## About the Role * Bachelor's degree and 6+ years of experience in cybersecurity, cloud security, infrastructure security, systems engineering, network security, endpoint security, or data protection. Additional relevant experience may be considered in lieu of degree. * Hands-on experience implementing, configuring, and supporting security controls in Microsoft Azure, Microsoft 365, Entra ID, Intune, Defender, Sentinel, Purview, and related Microsoft security platforms. * Strong practical understanding of identity security, endpoint protection, cloud security, data protection, network security, server hardening, logging, vulnerability management, and incident response. * Hands-on experience with Microsoft Purview, DLP, sensitivity labels, data classification, eDiscovery support, audit logging, or related data protection controls. * Experience supporting web proxy, secure web gateway, URL filtering, CASB, browser controls, SSL inspection, or internet access security controls. * Experience working with vulnerability management tools, EDR/XDR platforms, SIEM/logging platforms, IAM tools, endpoint management platforms, DLP tools, web proxy platforms, and cloud security posture tools. * Ability to review technical findings, determine practical remediation steps, implement improvements, validate results, and produce clear evidence. * Working knowledge of Microsoft 365 security, Entra ID, Conditional Access, Intune, Defender for Endpoint, Defender for Cloud, Sentinel, Purview, Azure Policy, RBAC, and cloud logging concepts. * Practical understanding of data loss prevention, PHI/PII protection, cloud app access, file movement controls, web activity monitoring, and data protection practices. * Experience supporting endpoint security improvements, including patching, encryption, EDR coverage, device compliance, configuration baselines, application control, and local administrator controls * Experience supporting network security controls, including firewalls, segmentation, VPN, remote access, DNS, certificates, and secure administration practices. * Familiarity with HIPAA, PHI/PII handling, NIST CSF, CIS benchmarks, Microsoft security baselines, and security evidence requirements. * Ability to work with infrastructure, cloud, network, application, compliance, vendor, and business teams to complete security improvement activities. * Strong troubleshooting, documentation, and communication skills. * Healthcare experience or experience supporting regulated environments with sensitive data is preferred. * Microsoft security and cloud certifications such as AZ-500, SC-200, SC-300, SC-400, SC-100, MS-102, or MD-102 are strongly preferred. Security+, CySA+, CISSP, CCSP, CCNA Security, or similar certifications are also preferred. ## Description The ideal candidate is a hands-on security engineer with strong Microsoft cloud and infrastructure security experience who can configure, troubleshoot, document, and improve security controls in a regulated healthcare environment. Core Responsibilities * Implement and support security controls across Microsoft cloud services, endpoint platforms, identity systems, infrastructure, SaaS applications, and network environments. * Support vulnerability management activities, including validation, prioritization, remediation coordination, patching support, and closure documentation. * Configure and improve Microsoft security capabilities across Microsoft 365, Entra ID, Intune, Defender, Sentinel, Purview, Azure, and related security platforms. * Support endpoint security improvements, including endpoint protection, device compliance, encryption, patching, configuration baselines, and secure administration practices. * Support identity and access security controls, including MFA, Conditional Access, privileged access, service accounts, vendor access, and access review processes. * Support Azure security controls, including RBAC, policy enforcement, logging, secure networking, resource configuration, and cloud security posture improvements. * Support Microsoft Purview and data protection capabilities, including DLP, sensitivity labels, data classification, audit support, eDiscovery support, and policy tuning. * Support web security controls, including web proxy, secure web gateway, URL filtering, browser controls, internet access logging, and related policy enforcement. * Configure, validate, and improve security logging to support monitoring, investigation, reporting, and audit evidence. * Investigate security alerts and incidents, perform technical analysis, support containment and recovery actions, and document findings. * Partner with infrastructure, cloud, network, application, compliance, vendor, and business teams to implement practical security improvements. * Produce technical documentation, including implementation notes, runbooks, standards, evidence, and operational procedures. * Support security reviews and remediation activities for third-party platforms, hosted systems, applications, and infrastructure services. * Support business continuity and disaster recovery security activities, including technical validation, documentation, and remediation support. * Recommend practical security improvements that are achievable in an operational healthcare environment. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Exploring the Power of gRPC-Gateway for Writing RESTful Services](https://www.wearedevelopers.com/videos/2072-exploring-the-power-of-grpc-gateway-for-writing-restful-services) - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [Resilient by Design: Building Robust Architectures in High-Stakes Financial Systems](https://www.wearedevelopers.com/videos/2106-resilient-by-design-building-robust-architectures-in-high-stakes-financial-systems) - [Hacking MSSQL on Cloud. All of them. How I became sysadmin on Azure, AWS, GCP and Alibaba.](https://www.wearedevelopers.com/videos/100339-hacking-mssql-on-cloud-all-of-them-how-i-became-sysadmin-on-azure-aws-gcp-and-alibaba) - [Stop Using Node.js Like It’s 2020! - Alfonso Graziano](https://www.wearedevelopers.com/videos/1863-stop-using-node-js-like-it-s-2020-alfonso-graziano) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Security Basics for Vibe Coders](https://www.wearedevelopers.com/magazine/598-security-basics-for-vibe-coders)