Cloud Security Engineer / Azure and M365 / Hybrid in Coatesville
Role details
Job location
Tech stack
Job description
Job DescriptionA federally regulated bank is hiring a Cloud Security Engineer to own cloud security posture across their Azure-heavy environment. This is a full-time, direct hire role, hybrid in the Philadelphia suburbs. The stack centers on Microsoft Defender for Cloud, Microsoft Purview, and Intune, with broader exposure to multi-cloud environments where relevant.\n \n \n This team isn't inheriting a mature program and polishing it. They're building. The right person here has hands-on experience standing up DLP frameworks and IAM controls in Azure environments, knows how to configure Purview for sensitive data discovery and classification, and has the instinct to architect things correctly from the start. While professional experience is necessary, lab work, independent projects, and personal investment in the craft separates you from the pack and will be acknowledged. If you've built your own environments to learn and test, that's going to come through, and it matters here.\n \n
Requirements
n
-
4+ years of experience in cybersecurity with a focus on cloud security engineering \n
-
Hands-on experience configuring Microsoft Purview, including DLP policy creation, sensitive data discovery, and PII classification across cloud and Microsoft 365 environments \n
-
Experience designing and implementing IAM controls in Azure, including Conditional Access policies, Entra ID, role-based access control (RBAC), and least privilege enforcement \n
-
Working knowledge of Microsoft Defender for Cloud and Intune for endpoint and cloud security management \n
-
Experience with cloud security posture management (CSPM) and remediating misconfigurations \n
-
Familiarity with cloud security log monitoring and integration with SIEM platforms (Splunk or Microsoft Sentinel) \n
-
Ability to conduct risk assessments and vulnerability analysis across cloud-hosted infrastructure (compute, storage, containers, networking) \n
-
Understanding of compliance frameworks relevant to financial services: NIST CSF, CIS Benchmarks, SOC 2, ISO 27001 \n
-
Comfortable working cross-functionally with IT, DevOps, and compliance teams \n, * Industry certifications: AZ-500, Security+, CISSP, or CCSP \n
-
Experience in financial services or another heavily regulated industry \n
-
Exposure to multi-cloud environments (AWS, GCP) in addition to Azure \n
-
Familiarity with IaC scanning or DevSecOps tooling \n
-
Track record of self-directed learning: personal lab environments, home projects, or independent cloud security builds \n