> Markdown version of [/jobs/ext/2154969-cloud-security-engineer](https://www.wearedevelopers.com/jobs/ext/2154969-cloud-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cloud Security Engineer - **Company:** Peoplentech Llc - **Location:** Santa Clara, CA, United States - **Experience:** Expert - **Salary:** $156,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Artificial Intelligence, Amazon Web Services, User Authentication, Microsoft Azure, Software as a Service, Cloud Computing, Cloud Computing Security, Continuous Delivery, Continuous Integration, Identity and Access Management, Information Systems Security Architecture Professional, Python (Programming Language), Key Management, Microsoft Software, OAuth, OpenID, Windows PowerShell, Protocol Independent Multicast, Azure Active Directory, Service Pack, Security Information and Event Management, Software Engineering, Policy as Code, Scripting, Google Cloud, Enterprise Software Applications, Large Language Models, Multi-Cloud, Data Management, Terraform - **Published:** August 20, 2026 - **Apply:** https://www.careerbuilder.com/job-details/senior-cloud-security-engineer-santa-clara-ca--6ae96b6e-b6f8-4520-ae14-9d024167b442 ## About the Role * 8+ years in cloud security or security engineering, with deep, hands-on Azure experience. * Strong, hands-on Microsoft Entra ID expertise: app registrations, Enterprise Apps, permissions and consent, and Conditional Access. * Solid working knowledge of modern authentication: OIDC, OAuth 2.0 / PKCE, JWT, and mTLS. * Proficiency with Terraform and Azure Policy for policy-as-code and automated guardrails. * Experience with Microsoft Defender for Cloud and cloud security posture management. * A demonstrable track record of root-causing and permanently closing security findings-not just patching them. * Working understanding of AI, AI agents, and AI security considerations. Nice to Have * Multi-cloud exposure (AWS, GCP). * Relevant certifications (e.g., Microsoft SC-100, AZ-500, SC-300; CISSP). * Experience with CI/CD pipeline security, secrets management, and SIEM/SOAR. * Scripting/automation (PowerShell, Python). * Hands-on experience securing LLM-based or agentic systems in production. Skills: Amazon Web Services (AWS), Artificial Intelligence (AI), Artificial Intelligence (AI) Agents, Authentication, Best Practices, CISSP - Certified Information Systems Security Professional, Cloud Computing, Continuous Deployment/Delivery, Continuous Integration, Enterprise Applications, Error Handling, GCP (Good Clinical Practices), Identify Issues, Identity Data Management, Injections, Just in Time (JIT), Machine Tool, Microsoft Product Family, Microsoft Windows Azure, OAuth, Production Systems, Protocol Independent Multicast (PIM), Python Programming/Scripting Language, Risk, Risk Analysis, Risk Management, Scripting (Scripting Languages), Security Information and Event Management (SIEM), Security Monitoring, Service Level Agreement (SLA), Software Engineering, Software Patches, Software as a Service (SaaS), Standards Development, Trend Analysis, Windows PowerShell ## Description We're hiring a Senior Cloud Security Engineer to serve as the dedicated owner of cloud security remediation and hardening across our environment. Our organization already has an established security team that identifies risks and issues recommendations. This role does not sit on that team. Instead, you are the engineer who turns those recommendations into durable, well-architected fixes-and, just as importantly, makes sure the same findings don't come back. This is a hands-on engineering role, not an advisory one. Success means a measurably more secure environment, a shrinking backlog of recurring findings, and security controls that are enforced by design rather than by manual effort or one-off patches. What You'll Do Remediation & recurrence prevention (the core of this role) * Own the full lifecycle of security findings and recommendations-whether they come from the security team, Microsoft Defender for Cloud, or other tooling-through triage, remediation, verification, and closure. * Root-cause recurring issues and implement systemic fixes (policy-as-code, automated guardrails, secure baselines) so the same findings don't reappear quarter after quarter. * Track remediation SLAs and report on risk reduction and posture trends over time. Identity & authentication * Secure and govern modern authentication flows across the estate: OIDC, OAuth 2.0 with PKCE, JWT validation and handling, and mTLS. * Administer and harden Microsoft Entra ID (Azure Entra): app registrations and Enterprise Application permissions, consent governance, service principals and managed identities, credential and secret hygiene, and least-privilege scoping. * Design, implement, and continuously tune Conditional Access policies. Cloud security engineering & governance * Build and enforce guardrails using Azure Policy and Terraform; maintain secure-by-default infrastructure-as-code baselines and detect/remediate configuration drift. * Operate Microsoft Defender for Cloud-drive secure-score improvement, remediate recommendations, and manage cloud security posture (CSPM). * Contribute to security governance: standards, control definitions, exception handling, and audit evidence. Admin portal & privileged access security * Secure all cloud and SaaS administrative portals-Azure and other admin consoles (e.g., Microsoft 365 admin, identity providers, and any additional cloud platforms in use). * Strengthen privileged access: MFA enforcement, Privileged Identity Management (PIM) / just-in-time elevation, role minimization, and break-glass procedures. AI security * Apply security controls to AI workloads, services, and AI agents: agent and workload identities, tool and permission scoping, data-exposure and prompt-injection risk, and emerging AI security best practices. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Hacking MSSQL on Cloud. All of them. How I became sysadmin on Azure, AWS, GCP and Alibaba.](https://www.wearedevelopers.com/videos/100339-hacking-mssql-on-cloud-all-of-them-how-i-became-sysadmin-on-azure-aws-gcp-and-alibaba) - [Infrastructure as Code: The Developer's Secret Weapon](https://www.wearedevelopers.com/videos/1221-infrastructure-as-code-the-developer-s-secret-weapon) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) - [Implementing Feature Environments with AWS and Terraform](https://www.wearedevelopers.com/videos/531-implementing-feature-environments-with-aws-and-terraform) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [7 Cloud Computing Trends Coming in 2025 for Developers](https://www.wearedevelopers.com/magazine/412-7-cloud-computing-trends-coming-in-2025-for-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this)