Cloud Security Engineer

Amazon.com, Inc.
Denver, CO, United States
about 1 month ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
4 years minimum
Compensation
$124,800.0 - $135,200.0
Working hours
Regular working hours

Tech stack

Kubernetes Security Microsoft Azure Bash Shell Microsoft Online Services Cloud Computing Cloud Computing Security Cloud Engineering Identity and Access Management Intrusion Detection and Prevention Python (Programming Language) Key Management Log Analysis
+17 more
Windows PowerShell Kusto Query Language Security Information and Event Management Software Vulnerability Management Policy as Code Data Logging Microsoft Power Automate Cloud Monitoring Mitre Att&ck HybridCloud Infrastructure Automation Frameworks Bicep Microsoft Sentinel Terraform Serverless Computing Security Orchestration, Automation & Response Key Vault

Job description

We are seeking an experienced Azure Cloud Security Engineer to support the design, implementation, and optimization of enterprise cloud security controls across Microsoft Azure. The ideal candidate will have strong expertise in Azure security services, cloud governance, CSPM, identity and access management, infrastructure-as-code (IaC), and cloud-native security tooling. This role involves implementing security guardrails, performing security assessments, automating compliance, and collaborating with platform and security teams to strengthen the organization’s cloud security posture. Key Responsibilities

  • Design and implement Azure landing zone security controls, including identity, networking, VNets, NSGs, and private endpoints.
  • Configure, deploy, and optimize Microsoft Sentinel, Microsoft Defender XDR, Defender for Cloud, and Defender for Cloud Apps (CASB).
  • Perform Cloud Security Posture Management (CSPM) assessments against CIS Azure Foundations Benchmark and Microsoft Cloud Security Benchmark (MCSB), and recommend remediation plans.
  • Build and manage Azure Policy initiatives, policy-as-code, and automated remediation to enforce governance and reduce configuration drift.
  • Implement encryption, key management, and certificate governance using Azure Key Vault.
  • Configure Azure Monitor, Log Analytics, telemetry, alerting, and SIEM integrations.
  • Secure Azure services including AKS, Container Apps, Azure Functions, Logic Apps, and Azure Container Instances.
  • Conduct cloud architecture security reviews and threat modeling.
  • Develop Infrastructure-as-Code (Terraform, Bicep, ARM) security guardrails and vulnerability management workflows.
  • Support cloud security incident investigation and containment activities.
  • Create documentation, operational runbooks, standards, and knowledge transfer materials.

Requirements

  • 4-7 years of hands-on experience in Azure Cloud Security Engineering.
  • Strong experience with Microsoft Azure security services, including Defender for Cloud, Microsoft Sentinel, Defender XDR, and Defender for Cloud Apps (CASB).
  • Experience implementing Azure Policy, governance frameworks, and Infrastructure-as-Code (Terraform, Bicep, or ARM).
  • Experience performing CSPM assessments using CIS Azure Foundations Benchmark and Microsoft Cloud Security Benchmark (MCSB).
  • Strong knowledge of Azure IAM, networking, encryption, Key Vault, and cloud-native security best practices.
  • Experience securing hybrid cloud environments.
  • Proficiency in scripting and automation using PowerShell, Python, Bash, KQL, or similar technologies.

Preferred Qualifications

  • Experience with container and Kubernetes security (AKS).
  • Knowledge of MITRE ATT&CK framework and cloud detection engineering.
  • Experience with cloud monitoring, logging, and security automation.
  • Strong documentation and technical communication skills.

Certifications

  • Required: Microsoft Certified Azure Security Engineer Associate (AZ-500)
  • Preferred: CCSP or equivalent cloud security certification

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.careerjet.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:55 min

Centralizing credentials management using Azure Key Vault resource integration

Marcel Lupo · LIVE

1:34 min

Essential commands for running and testing Terraform configurations

Hennie Francis · LIVE

2:56 min

Provisioning a secure container infrastructure with Bicep

Matthias Falkenberg +1 · WWC 2022

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

2:32 min

Overview of Terraform and Terraform Cloud features

Devlin Duldulao · LIVE

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

Videos

See all

Related articles

See all