Azure Security Engineer

Intersources Inc.
United States
7 days ago
Apply on www2.jobdiva.com
Prepare application

Role details

Contract type
Temporary contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Compensation
$26,000.0
Working hours
Regular working hours

Tech stack

Kubernetes Security Application Programming Interfaces (APIs) Application Services Microsoft Azure Cloud Computing Cloud Computing Security Cyber Security Databases Data as a Services Information Engineering DevOps Github
+33 more
Identity and Access Management Intrusion Detection and Prevention Log Analysis Network Planning and Design Network Monitoring Windows PowerShell Role-Based Access Control Cloud Services Kusto Query Language Zero Trust Network Access Runbook YAML Policy as Code Data Logging Microsoft Power Automate Cloud Monitoring Spring Cloud Delivery Pipeline Software Security Mitre Att&ck Azure Powershell Kubernetes Information Technology Bicep Microsoft Sentinel Azure AKS CIS Benchmarks Firewall Services Module Terraform Devsecops Api Management Key Vault Vulnerability Analysis

Job description

Client is seeking an experienced Azure Security Engineer to define, implement, operate, test, and continuously improve technical security controls across the Microsoft Azure environment. This hands-on security engineering role establishes security requirements, configures and operates Azure security capabilities, monitors cloud security posture, identifies control gaps, and validates remediation. The engineer partners with the Senior Azure Infrastructure & Network Architect, Platform Engineering, IAM, Application Security, Security Operations, and resource-owning teams to ensure Azure infrastructure, applications, identities, networks, data services, containers, and deployment pipelines comply with approved security requirements.

What This Role Owns

  • Definition, implementation, operation, testing, and continuous improvement of Azure technical security controls, in partnership with IT Security, Platform Engineering and other resource-owning teams.
  • Azure cloud security posture management (CSPM), cloud misconfiguration and vulnerability identification, remediation governance, and security-control validation, while resource-owning teams perform remediation for the resources they own.
  • Azure Policy security guardrails, Defender for Cloud, Azure security telemetry, and Azure-focused Sentinel integration.
  • Security requirements and validation for Azure network paths, workload exposure, secrets, keys, certificates, and privileged access.
  • DevSecOps controls embedded into Terraform and Azure DevOps (ADO) YAML pipelines, including policy checks, pipeline gates, and reusable security modules.
  • Azure expertise for escalated cloud security incidents in partnership with Security Operations and the managed SOC.

Key Responsibilities

Cloud Security Engineering & Guardrails

  • Define security requirements and partner with Platform Engineering and other resource-owning teams to implement, validate, operate, and continuously improve security controls across Azure workloads and shared platform services.
  • Define security requirements for Azure networking and hybrid connectivity in partnership with the Senior Azure Infrastructure & Network Architect
  • Assess network designs for segmentation, inspection, private connectivity, ingress, egress, public exposure, and logging requirements
  • Validate the security configuration of Private Endpoints, NSGs, Azure Firewall policies, WAF policies, Front Door, API Management, and traffic-monitoring controls
  • Identify overly permissive network rules, inspection bypasses, unintended public exposure, weak segmentation, and deviations from approved security requirements
  • Validate that corrective actions effectively resolve identified network-security findings
  • Monitor network-security control posture and escalate architectural concerns to the Senior Azure Infrastructure & Network Architect
  • Develop and maintain secure Azure baselines, implementation standards, and reusable security patterns.
  • Implement Azure Policy definitions, initiatives, assignments, exemptions, and remediation tasks to enforce approved requirements.
  • Test security controls after deployment and identify control regressions, missing protections, configuration drift, and unintended public exposure.
  • Automate repeatable security validation and remediation so recurring weaknesses are addressed through guardrails rather than one-resource-at-a-time fixes.
  • Establish clear security acceptance criteria and remediation expectations with Platform Engineering and other resource-owning teams and validate that required controls are implemented before release.

Security Posture & Risk Management

  • Administer Microsoft Defender for Cloud and review recommendations, alerts, attack paths, regulatorycompliance assessments, and coverage gaps.
  • Identify, prioritize, remediate, and validate Azure security vulnerabilities, configuration weaknesses, excessive privileges, and public-access exposures.
  • Perform security reviews of Azure subscriptions, resource groups, networking, storage, Key Vault, application services, databases, AKS, and other cloud services.
  • Protect PHI, PII, secrets, credentials, keys, certificates, and other sensitive information across Azure environments.
  • Maintain evidence showing findings, corrective actions, validation, exceptions, and closure status.

Identity Security Integration

  • Partner with the IAM Engineer to secure Azure identities, permissions, and privileged administrative access and secure identity lifecycle management without duplicating IAM ownership.

  • Validate Azure RBAC assignments, least-privilege controls, PIM requirements, and MFA requirements.
  • Secure service principals, managed identities, workload identities, and deployment identities.
  • Assist with implementation and validation of Conditional Access controls affecting Azure administration.
  • Investigate unusual or excessive Azure privileged activity with IAM and Security Operations.
  • Recommend managed identities and workload identity patterns where feasible in place of stored credentials.

DevSecOps, IaC & Automation

  • Integrate security validation into Terraform and Azure DevOps YAML pipelines and review security-relevant infrastructure changes before prod deployment.
  • Design and implement Terraform security scanning, policy validation, compliance checks, secrets scanning, and security gates appropriate to the workload, using reusable modules and policy-as-code patterns.
  • Develop automation using PowerShell, Azure CLI, KQL, Logic Apps, Terraform, Bicep, or APIs.
  • Validate pipeline service connections and deployment identities for least privilege and appropriate credential handling.
  • Drive resource-owning Engineering and Platform teams to remediate findings, validate closure, and make approved security patterns easier to consume through reusable modules, guardrails, and pipeline integrations.

Security Monitoring & Incident Support

  • Develop Azure-specific detections, analytics rules, investigations, and monitoring use cases to identify cloud threats, control failures, and suspicious activity.
  • Configure and maintain Azure security logging, diagnostic settings, monitoring, and alerting needed for investigation and control validation.
  • Integrate Azure security telemetry with Microsoft Sentinel and managed SOC processes and develop or tune Azure-focused detections and KQL queries.
  • Provide Azure subject-matter expertise for escalated cloud security alerts and incidents rather than functioning as the primary Tier 1 analyst.
  • Support investigation, containment, recovery, evidence preservation, root-cause analysis, and post incident hardening for Azure incidents.
  • Convert lessons learned into improved Azure Policy, Terraform, monitoring, detections, or procedures.

AKS & Container Security

  • Define and maintain AKS cluster security requirements, container security standards, and approved container security policy controls.
  • Harden Azure Container Registry (ACR), including access controls, network exposure, image provenance, vulnerability scanning, retention, and approved image-use requirements.
  • Implement and validate container-specific security gates in Azure DevOps YAML pipelines, including image, dependency, Infrastructure as Code, secrets, and policy checks.
  • Assess AKS cluster and workload configurations against approved requirements, identify control gaps, and drive resource-owning teams to remediate findings.
  • Implement or integrate runtime detection and monitoring for container and Kubernetes threats, suspicious workload behavior, and policy violations.

Compliance, Documentation & Collaboration

  • Support Azure technical controls and evidence for HIPAA, SOC 2, URAC, NIST-aligned requirements, internal security standards, and applicable customer obligations.
  • Maintain Azure security standards, implementation guidance, runbooks, diagrams, metrics, and remediation records.
  • Partner with Infrastructure, DevOps, Application Engineering, Data Engineering, IAM, Application Security, Compliance, Security Operations, and external providers.
  • Participate in audits and technical reviews by supplying accurate implementation evidence and remediation status.

Requirements

  • 5+ years of information security experience, including 3+ years of hands-on Azure security engineering
  • Demonstrated experience implementing Azure Policy, Defender for Cloud, Azure Monitor, Log Analytics, Sentinel integration, Key Vault, and Azure security controls

  • Hands-on experience identifying and remediating Azure vulnerabilities, security misconfigurations, excessive privileges, and public exposures
  • Experience implementing security requirements for Azure networking, applications, storage, databases, identities, containers, and platform services
  • Strong PowerShell, Azure CLI, KQL, and security-automation experience
  • Advanced experience implementing security checks, policy controls, and deployment gates in Azure DevOps YAML pipelines
  • Hands-on Terraform security experience, including plan review, policy as code, secrets protection, state security, provider security, and secure module patterns
  • Experience securing AKS, ACR, container pipelines, and container runtime environments
  • Working knowledge of cloud threat detection, incident investigation, Zero Trust, encryption, least privilege, and regulated cloud environments
  • Experience maintaining security evidence, findings, exceptions, remediation records, and controlvalidation results, * Microsoft Certified: Azure Security Engineer Associate (AZ-500) or Cybersecurity Architect Expert (SC100).
  • Healthcare, HIPAA-regulated, or other regulated-industry experience.
  • Experience with Azure landing zones, GitHub Advanced Security, Microsoft Purview, or complementary cloud-security tooling.

  • Experience securing Kubernetes/container environments and cloud-native applications.
  • Understanding of NIST CSF, CIS Benchmarks, and MITRE ATT&CK.
  • CISSP, CCSP, GIAC, or comparable security certification.
  • Master’s or Bachelor’s degree in Information Technology, Information Security, Computer Science, or a related field, or equivalent relevant experience.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www2.jobdiva.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

6:36 min

Funding open source through GitHub Accelerator and Sponsors

Stormy Peters · World Congress 2023

2:56 min

Provisioning a secure container infrastructure with Bicep

Matthias Falkenberg +1 · World Congress 2022

1:35 min

Centralizing configuration logic with native YAML block references

Matthieu Vincent Matthieu Vincent · Europe 2026 Virtual

2:40 min

Using GitHub primitives for internal documentation and corporate operations

Kyle Daigle · Coffee With Developers

4:09 min

Selecting infrastructure tools and determining proper abstraction layers

Alayshia Knighten Alayshia Knighten · World Congress 2024

Videos

See all

Related articles

See all