
Cloud Security Engineer
Brown Advisory28 days ago
Baltimore, MD, USA or Washington, DC, USAMid Level / Senior
Base Salary
$140k - $165k/yr
Responsibilities
- Own day-to-day security engineering for Azure environments, including secure configuration, cloud control hardening, logging, monitoring, and remediation.
- Implement Azure security baselines, secure networking patterns, key management practices, storage protections, and workload guardrails with Infrastructure and Engineering teams.
- Support Microsoft Defender for Cloud, Azure Policy, Entra-related cloud controls, conditional access inputs, and other Microsoft security capabilities.
- Review hosted and third-party-developed applications for secure architecture, authentication, authorization, logging, data protection, and operational readiness.
- Configure and improve security controls for Salesforce, Box, Microsoft 365, and other business-critical SaaS applications.
- Coordinate static and dynamic application-security testing, vulnerability triage, and remediation guidance for development teams.
- Integrate cloud, SaaS, and application telemetry into SIEM and detection workflows and support actionable alerting and response procedures.
- Maintain sanctioned application lists, cloud security standards, exception records, and implementation documentation.
- Coordinate complex remediation across platform, application, and vendor teams and report on security posture, risks, remediation progress, and control maturity.
Requirements
- Bachelor’s degree in cybersecurity, computer science, engineering, information systems, or a relevant field, or equivalent professional experience.
- 4–8 years of experience in information security, cloud security, infrastructure security, application security, or a related technical discipline.
- Hands-on experience securing Microsoft Azure environments.
- Experience with Azure security architecture, Defender for Cloud, Azure Policy, logging, monitoring, and secure configuration practices.
- Knowledge of Microsoft 365 security and compliance concepts, Entra ID, Purview, Defender, and conditional access.
- Experience with SaaS security administration, static and dynamic application-security testing concepts, vulnerability triage, and secure SDLC practices.
- Knowledge of SIEM integration, alert tuning, security telemetry, and operational handoff to incident response teams.
- Ability to work independently and coordinate with technology, vendor, risk, and business stakeholders.
- Strong written communication skills for standards, procedures, exception documentation, and leadership reporting.
- Financial-services or other regulated-industry experience, Microsoft Azure security certifications, CISSP, CCSP, or other relevant professional designations are preferred.
Benefits
- Medical, dental, vision, wellness program participation incentive, financial wellness program, fitness event fee reimbursement, gym membership discounts, colleague assistance, and telemedicine programs.
- Adoption benefits, daycare late pick-up fee reimbursement, life and accidental death and dismemberment insurance, short-term and long-term disability, paid parental leave, and pet insurance.
- 401(k) with a 50% employer match up to the IRS limit and four-year vesting.
- The posting lists base salary ranges of $140,000–$150,000 for Maryland and $154,000–$165,000 for Washington, DC, excluding bonus and long-term incentive eligibility.