Senior Security Engineer (Azure)

Nava PBC · Remote · Engineering

Posted 2026-10-08

Apply for this role →

This role is open for multiple levels and titles. Final title/compensation will be determined by how your interview weighs against our core competencies during your interview cycle

Position summary

We are seeking a Security Engineer to support the design and implementation of a secure Azure cloud environment for a large-scale government modernization effort. This role will focus on establishing strong security and compliance foundations, including identity and access management, monitoring, and policy enforcement across the tenant. The Security Engineer will partner closely with cloud architects, engineers, and client stakeholders to define and implement security best practices aligned with federal and state requirements.

What you'll do

Design and implement identity and access management (IAM) models, including RBAC and privileged access controls

Configure and advise on security tools such as Microsoft Defender for Cloud

Define and enforce security policies and governance guardrails using Azure Policy

Set up and guide centralized logging, monitoring, and threat detection capabilities

Design key management and secrets handling solutions (e.g., Azure Key Vault)

Support compliance efforts, including HIPAA alignment and ATO preparation activities

Collaborate with teams to identify security risks and define remediation approaches

Contribute to secure cloud architecture decisions, including networking and access patterns

Support Infrastructure-as-Code (IaC) and CI/CD practices to ensure secure deployments

Create security documentation, runbooks, and provide guidance to enable client teams to operate securely

Required skills

Experience with Azure cloud security, including Microsoft Entra ID and Defender for Cloud

Strong knowledge of Identity and Access Management (IAM), including RBAC and privileged access controls

Familiarity with security and compliance frameworks (e.g., HIPAA, state security standards, ATO processes)

Experience implementing cloud security monitoring, logging, and incident detection

Knowledge of Azure Policy and governance guardrails for enforcing security standards

Experience with key management and secrets handling (e.g., Azure Key Vault)

Understanding of secure network architecture and connectivity (including hybrid/on-prem integrations)

Experience supporting Infrastructure-as-Code (IaC) and secure CI/CD pipeline practices

Ability to define and document security architecture, standards, and operational runbooks

Strong collaboration skills to work with engineers, architects, and stakeholders on security design and remediation

Compensation

$135,900—$153,000 USD

Apply for this role →

← Back to all jobs