Cloud Security Engineer
Posted 13hrs ago
Employment Information
Report this job
Job expired or something wrong with this job?
Job Description
Cloud Security Engineer securing Azure infrastructure, identities, and AI workloads for a global IT transformation leader. Driving remediation, policy-as-code guardrails, and Microsoft Defender for Cloud posture improvement.
Responsibilities:
- Own the full lifecycle of security findings and recommendations through triage, remediation, verification, and closure
- Root-cause recurring issues and implement systemic fixes using policy-as-code, automated guardrails, and secure baselines
- Track remediation SLAs and report on risk reduction and security posture trends
- Secure and govern authentication flows including OIDC, OAuth 2.0 with PKCE, JWT validation and handling, and mTLS
- Administer and harden Microsoft Entra ID, including app registrations, Enterprise Application permissions, consent governance, service principals, managed identities, credential hygiene, and least-privilege scoping
- Design, implement, and continuously tune Conditional Access policies
- Build and enforce guardrails using Azure Policy and Terraform
- Maintain secure-by-default infrastructure-as-code baselines and detect or remediate configuration drift
- Operate Microsoft Defender for Cloud to improve secure score, remediate recommendations, and manage CSPM
- Contribute to security governance, including standards, control definitions, exception handling, and audit evidence
- Secure cloud and SaaS administrative portals, including Azure, Microsoft 365 admin, and identity providers
- Strengthen privileged access through MFA, PIM / just-in-time elevation, role minimization, and break-glass procedures
- Apply security controls to AI workloads, services, and AI agents, including identity, tool and permission scoping, data-exposure mitigation, and prompt-injection risk mitigation
Requirements:
- 5+ years in cloud security or security engineering, with deep, hands-on Azure experience
- Strong, hands-on Microsoft Entra ID expertise, including app registrations, Enterprise Apps, permissions and consent, and Conditional Access
- Solid working knowledge of OIDC, OAuth 2.0 / PKCE, JWT, and mTLS
- Proficiency with Terraform and Azure Policy for policy-as-code and automated guardrails
- Experience with Microsoft Defender for Cloud and cloud security posture management
- Demonstrable track record of root-causing and permanently closing security findings
- Working understanding of AI, AI agents, and AI security considerations
- Resilience, emotional intelligence, and focus on agile delivery
- Deep understanding of the difference between coding and engineering
- Advanced oral English
- Advanced Spanish
- Multi-cloud exposure (AWS, GCP)
- Relevant certifications such as Microsoft SC-100, AZ-500, SC-300, or CISSP
- Experience with CI/CD pipeline security, secrets management, and SIEM/SOAR
- Scripting/automation proficiency with PowerShell or Python
- Hands-on experience securing LLM-based or agentic systems in production
- Familiarity with cloud-native foundations or AI coding assistants
Benefits:
- Remote work arrangement
- Flexibility to support your lifestyle
- Global career opportunities
- Exposure to high-impact projects
- World-class, high-impact projects
- Collaboration with global teams
- Work within an international network of expertise
- Opportunity to work for an award-winning employer
- Opportunity to work for a sustainable corporation




















