
Cloud Security Engineer
OneStream Software27 days ago
Remote, United StatesMid Level
Base Salary
$86k - $112k/yr
Responsibilities
- Design, implement, and improve security controls and configuration baselines across Microsoft Azure and Microsoft 365.
- Configure, administer, and optimize Microsoft Defender for Cloud, Microsoft Defender for Endpoint, Microsoft Defender for Cloud Apps, and related cloud security technologies.
- Assess cloud resources, applications, Azure Kubernetes Service, and containerized workloads for vulnerabilities, misconfigurations, excessive permissions, and other risks.
- Perform vulnerability management, including prioritizing findings, coordinating remediation, and validating corrective actions.
- Enhance cloud security monitoring, threat detection, investigation, response, and automation using Microsoft Sentinel and Kusto Query Language.
- Collaborate with Cloud, Compliance, and internal teams to apply security best practices, organizational standards, CIS Benchmarks, and DISA STIGs.
- Respond to customer security inquiries, assessments, and questionnaires concerning security controls and cloud practices.
- Maintain technical documentation, procedures, dashboards, alerts, and security reporting.
- Support internal and external audits by gathering evidence and validating control adherence.
- Investigate suspicious, anomalous, or unauthorized cloud activity and support incident response activities.
Requirements
- Bachelor’s degree in Cybersecurity, Computer Science, Engineering, or a technology-related field, or equivalent work experience.
- At least 3 years of experience securing cloud-based infrastructure, services, and technologies.
- Experience identifying, analyzing, and mitigating security risks in cloud environments.
- Experience securing Microsoft Azure through configuration, least-privilege access, data protection, threat detection and response, and security hardening.
- Experience deploying and administering Microsoft Defender, SIEM, CASB, vulnerability management, and related security technologies.
- Working knowledge of Azure Log Analytics, Kusto Query Language, PowerShell, Bash, and identity and access management concepts.
- Working knowledge of Microsoft Entra ID, role-based access control, authentication, authorization, Windows, and Linux.
- Familiarity with incident response, incident management, and change management processes.
- Preferred: experience with a cloud, managed service, SaaS, or similarly regulated provider.
- Preferred: 5+ years of Microsoft Azure experience, including Azure Kubernetes Service and containerized workloads.
- Preferred: knowledge of NIST 800-53, FedRAMP, SOC 1, SOC 2, ISO 27001, or similar compliance frameworks.
- Preferred: experience with Microsoft Entra ID, Okta, SAML, OAuth, OpenID Connect, ARM, Bicep, Terraform, and Azure DevOps pipelines.
- Preferred: knowledge of network security, TCP/IP, DNS, TLS, and firewall technologies.
- Preferred: familiarity with Agile, Scrum, and DevSecOps methodologies.
- Relevant cybersecurity certifications such as AZ-500, AZ-104, SC-200, SC-300, SC-100, Security+, or Cloud+ are preferred.
- Strong analytical, communication, presentation, prioritization, organizational, and problem-solving skills are required.
Benefits
- Remote work arrangement in the USA.
- Full-time employment.
- Medical, dental, vision, life, short- and long-term disability, vacation, paid holidays, professional development, and retirement plan benefits.
- Training opportunities and professional development support.
- Additional variable compensation and benefits may apply.