This is a remote position.
Job Title: Senior Azure Cloud Security Engineer
Location: Remote
Duration: Long-term contract
Position Overview
We are seeking an experienced Senior Azure Cloud Security Engineer to design, implement, and maintain security controls across a complex Microsoft Azure environment. This individual will serve as a senior technical resource responsible for securing cloud infrastructure, applications, identities, and data while helping the organization mature its overall cloud security posture.
The ideal candidate has deep hands-on experience with Azure security technologies, identity and access management, cloud networking, security monitoring, vulnerability management, and infrastructure-as-code security. This role will partner closely with Cloud Engineering, Infrastructure, DevOps, Application Development, Security Operations, and Governance/Risk teams.
Key Responsibilities
- Design, implement, and maintain security architecture and controls across Microsoft Azure environments.
- Serve as a senior technical subject matter expert for Azure cloud security and cloud security best practices.
- Secure Azure subscriptions, management groups, resource groups, networking, storage, compute, databases, containers, and other cloud services.
- Implement and manage security capabilities using Microsoft Defender for Cloud, Microsoft Sentinel, Azure Policy, Microsoft Entra ID, Key Vault, and related Microsoft security technologies.
- Design and maintain Identity and Access Management (IAM) controls, including RBAC, Conditional Access, Privileged Identity Management (PIM), managed identities, service principals, and least-privilege access.
- Develop and enforce cloud security policies, standards, guardrails, and configuration baselines.
- Identify and remediate cloud vulnerabilities, configuration weaknesses, excessive permissions, and other security risks.
- Partner with engineering teams to incorporate security throughout the CI/CD and DevSecOps lifecycle.
- Review Infrastructure-as-Code deployments, including Terraform, Bicep, and/or ARM templates, for security risks and compliance.
- Implement security controls for Azure networking, including VNets, NSGs, Azure Firewall, Private Endpoints, Application Gateway/WAF, and related technologies.
- Support logging, monitoring, threat detection, and incident response across Azure environments.
- Develop detection rules, alerts, dashboards, and automated security responses.
- Investigate cloud security incidents and assist with root-cause analysis and remediation.
- Perform security assessments of new Azure services, applications, architectures, and third-party integrations.
- Partner with architecture and engineering teams to review proposed cloud designs and provide security recommendations.
- Automate security processes and controls using PowerShell, Azure CLI, Python, or similar scripting technologies.
- Support regulatory and security compliance initiatives using frameworks such as NIST, CIS, ISO 27001, SOC 2, PCI DSS, or similar standards.
- Mentor junior engineers and provide technical leadership on cloud security initiatives.
- Stay current on emerging Azure threats, vulnerabilities, Microsoft security capabilities, and cloud security best practices.
Required Qualifications
- 7+ years of experience in information security, infrastructure security, cloud engineering, or a related technical discipline.
- 4+ years of hands-on Microsoft Azure security experience in enterprise environments.
- Strong knowledge of Azure architecture and security concepts.
- Advanced experience with Microsoft Entra ID (Azure AD), RBAC, Conditional Access, PIM, MFA, managed identities, and service principals.
- Hands-on experience with Microsoft Defender for Cloud and Azure security posture management.
- Experience with Microsoft Sentinel or another enterprise SIEM platform.
- Strong understanding of Azure networking and network security.
- Experience securing Azure IaaS and PaaS services.
- Strong understanding of encryption, secrets management, certificates, and Azure Key Vault.
- Experience implementing security through Azure Policy and cloud governance controls.
- Experience with vulnerability management and cloud security posture management.
- Experience securing CI/CD pipelines and DevOps environments.
- Working knowledge of Infrastructure-as-Code technologies such as Terraform, Bicep, or ARM templates.
- Scripting or automation experience using PowerShell, Python, Azure CLI, or similar technologies.
- Strong understanding of security principles including Zero Trust, least privilege, defense-in-depth, network segmentation, and secure-by-design architecture.
- Ability to troubleshoot complex security issues across cloud infrastructure, networking, identity, and applications.
- Strong communication skills with the ability to work effectively with both technical and non-technical stakeholders.
Preferred Qualifications
- Experience securing large-scale or highly regulated Azure environments.
- Experience with Azure Kubernetes Service (AKS), container security, and Kubernetes security.
- Experience with Microsoft Defender XDR and the broader Microsoft security ecosystem.
- Experience with CSPM, CNAPP, or cloud security platforms such as Wiz, Prisma Cloud, Orca Security, or similar technologies.
- Experience integrating security tooling into CI/CD pipelines.
- Experience with GitHub Actions, Azure DevOps, or similar platforms.
- Familiarity with security frameworks such as NIST CSF, NIST 800-53, CIS Benchmarks, ISO 27001, SOC 2, and PCI DSS.
- Experience working within financial services, healthcare, insurance, or another highly regulated industry.
Preferred Certifications
- Microsoft Certified: Azure Security Engineer Associate
- Microsoft Certified: Cybersecurity Architect Expert
- Microsoft Certified: Azure Solutions Architect Expert
- CISSP, CCSP, or equivalent security certification
- Relevant Terraform, Kubernetes, or cloud security certifications
Ideal Candidate
The successful candidate will be a hands-on senior cloud security engineer who can operate at both the architectural and engineering levels. This person should be comfortable identifying cloud security risks, recommending solutions, and then working directly within Azure to implement and automate those controls.
Similar Jobs
What you need to know about the Los Angeles Tech Scene
Key Facts About Los Angeles Tech
- Number of Tech Workers: 375,800; 5.5% of overall workforce (2024 CompTIA survey)
- Major Tech Employers: Snap, Netflix, SpaceX, Disney, Google
- Key Industries: Artificial intelligence, adtech, media, software, game development
- Funding Landscape: $11.6 billion in venture capital funding in 2024 (Pitchbook)
- Notable Investors: Strong Ventures, Fifth Wall, Upfront Ventures, Mucker Capital, Kittyhawk Ventures
- Research Centers and Universities: California Institute of Technology, UCLA, University of Southern California, UC Irvine, Pepperdine, California Institute for Immunology and Immunotherapy, Center for Quantum Science and Engineering



