Cloud Azure Security Engineer
Cloud Azure Security Engineer
.Monks is a global consulting firm mastering AI-powered transformations for the Fortune 500. We combine long-term strategic thinking, deep enterprise experience, and a human-centered approach to help clients transform business processes and dominate their industries.
Position Overview:
We are seeking a talented Cloud Azure Security Engineer to join our team. The ideal candidate will have a deep understanding of cloud security principles, particularly within the Azure environment, and a proven track record of implementing robust security measures. As a Cloud Azure Security Engineer, you will be responsible for designing, implementing, and maintaining security solutions to protect our clients' cloud assets.
Responsibilities:
Assess the security posture of cloud environments in Microsoft Azure, including infrastructure, applications, and data, to identify vulnerabilities, misconfigurations, and compliance gaps.
Develop and maintain security control policies and procedures for cloud environments, ensuring alignment with industry standards, regulatory requirements, and organizational objectives.
Collaborate with stakeholders to understand business requirements and translate them into actionable security controls and policies.
Conduct regular security audits and assessments to validate adherence to security policies and identify areas for improvement.
Provide guidance and recommendations to engineering and operations teams for implementing security best practices and remediating security issues.
Design and implement cloud security solutions across infrastructure, network, identity, and access management.
Support the implementation and enforcement of security and compliance controls across Azure environments.
Investigate and remediate security findings, vulnerabilities, and misconfigurations across cloud environments.
Stay current with emerging threats, vulnerabilities, and security trends in cloud computing, and incorporate findings into security policies and controls.
Participate in incident response activities and assist in the investigation and resolution of security incidents as needed.
Requirements
Bachelor's degree in Computer Science, Information Technology, or a related field. (Master's degree preferred)
2+ years of experience in cloud security engineering, with a focus on Microsoft Azure.
Hands-on experience with Microsoft Entra ID (formerly Azure Active Directory) and cloud identity and access management.
Strong understanding of Entra ID concepts, including users, groups, roles, RBAC, administrative roles, service principals, managed identities, application registrations, and enterprise applications.
Experience implementing and managing Entra ID Conditional Access policies, including MFA, risk-based access, device-based controls, and least-privilege access.
Experience with Microsoft Entra ID Privileged Identity Management (PIM), access reviews, identity governance, and privileged access controls.
Experience with application authentication and authorization using technologies such as SAML, OAuth 2.0, and OpenID Connect.
Experience with Terraform, GitHub Actions, and containers.
In-depth knowledge of Azure services and features related to security, such as Microsoft Defender for Cloud, Microsoft Sentinel, Azure Firewall, Microsoft Entra ID, Azure Policy, Key Vault, and Network Security Groups (NSGs).
Experience with scripting and automation using languages and tools such as PowerShell, Python, or Azure CLI.
Strong understanding of network security principles, encryption protocols, identity management, authentication, authorization, and Zero Trust security principles.
Familiarity with implementing and managing security policies and controls in Azure environments to enforce organizational policies and compliance standards.
Experience with cloud security posture management and vulnerability management tools such as Wiz, Microsoft Defender for Cloud, or similar platforms.
Ability to investigate security findings and translate them into actionable remediation steps, including infrastructure-as-code changes where appropriate.
Relevant certifications such as Microsoft Certified: Azure Security Engineer Associate (AZ-500), Microsoft Certified: Identity and Access Administrator Associate (SC-300), Certified Cloud Security Professional (CCSP), or similar.
Excellent problem-solving skills and ability to work independently or as part of a team in a fast-paced environment.
Effective communication skills with the ability to articulate complex technical concepts to non-technical stakeholders.
What We Offer
Benefits
Excellent, full coverage medical, dental, and vision insurance
Generous PTO and 15 company-wide holidays
401k with company contribution
Paid parental leave
Work-life balance with an emphasis on personal well-being
Career growth in a disruptor space & entrepreneurial opportunities within the Monks network
A globally diverse & inclusive culture with employee resource groups such as S4 Melanin, Pride.Monks, Cultura.Monks, and more!
Authentic commitment to DEI efforts and sustainable growth. (Why Sir Martin Sorrell signed The Climate Pledge here!)
This role is subject to our Return to Office (RTO) policy. If you reside within a commutable distance of one of our office locations, you will be expected to work from the office a set number of days per week. The specific details, including the number of required office days, will be in accordance with the company’s then-current RTO policy, which is subject to change from time to time.
Monks has provided a compensation range that represents its good faith estimate of what Monks may pay for the position at the time of posting. Monks may ultimately pay more or less than the posted compensation range. The salary offered to the selected candidate will be determined based on job-related factors, but not based on a candidate’s sex or any other protected status.
Salary Range:
$155,000—$165,000 USD