inspiracareers
New

Sr. Cloud Security Engineer (Remote)

United StatesUnited States·Headquarters - Oak BrookSourcingsenior
EngineeringSecurity Engineer
0 views0 saves0 applied

Quick Summary

Key Responsibilities

Vulnerability Remediation & Security Operations Perform hands-on remediation of infrastructure and cloud vulnerabilities,

Requirements Summary

Vulnerability Remediation & Security Operations Perform hands-on remediation of infrastructure and cloud vulnerabilities,

Technical Tools
EngineeringSecurity Engineer

The Sr. Cloud Security Engineer (Sr. CSE) is a hybrid cloud and security engineering role responsible for the hands-on remediation of infrastructure and cloud vulnerabilities, ensuring cloud and infrastructure resources maintain compliance with established policies and Minimum-Security Baselines (MSBs), and reporting the organization's current compliance posture. The Sr. CSE will partner with the Security team to define, author, and maintain cloud security policies - keeping pace with evolving industry trends and regulatory requirements. This role will also actively participate in audit activities, including evidence gathering, reporting, and cross-functional collaboration with Compliance, Legal, and IT teams. 

 

Responsibilities

~4 min read

As part of the evaluation process, candidates who progress beyond the initial screening will be required to complete a formal technical assessment to validate coding proficiency and technical competency.

Education & Experience 

  • →10+ years of experience in cloud engineering, infrastructure, or security engineering - with demonstrated hands-on security work, not just advisory 
  • →Bachelor's Degree in Computer Science, Software/Computing Engineering, Information Security, or related field - or equivalent experience 
  • →Technical certifications preferred: AZ-500, SC-100, SC-200, AZ-104, or equivalent cloud/security certifications 
  • →Experience working in regulated industries (Financial Services, Insurance, or Health-Tech preferred) 
  • →Familiarity with compliance frameworks: NIST, HIPAA, PCI and Minimum Security Baselines (MSBs) 

 

Skills & Abilities 

Hands-on experience or significant exposure to the following services and concepts: 

Cloud Platform - Azure 

  • →Networking & Security: Virtual Networks (VNETs) and peering, NSGs, UDRs, Private Endpoints, Azure Firewall, Application Gateways (including WAF - OWASP ruleset configuration, Detection vs. Prevention mode), ExpressRoute, VPN Gateways, and Azure Bastion 
  • →Compute & Containers: Virtual Machines, VM Scale Sets, AKS (Kubernetes), and Container App Environments - including cluster hardening, network policy enforcement, workload identity, and Azure Policy for Kubernetes 
  • →Identity & Access: Active Directory (on-prem, hybrid Entra Connect sync), Microsoft Entra ID, Privileged Identity Management (PIM), Conditional Access policy design and enforcement, Azure RBAC (including custom role design), and Entra ID Protection 
  • →Security & Compliance Tooling: Microsoft Sentinel, Microsoft Defender for Cloud (Defender for Containers, Defender for Servers, Defender CSPM), and Azure Policy 
  • →Monitoring & Observability: Azure Monitor - KQL, alert rule configuration, log-based queries, and action group integrations; familiarity with Log Analytics Workspace architecture and log ingestion patterns at scale 
  • →Secrets & Certificates: Azure Key Vault and Key Vault CSI Secrets Store driver for AKS 
  • →Storage & Recovery: Storage Accounts, Backup Vault, and Azure Site Recovery 
  • →Virtual Desktop: Azure Virtual Desktop (AVD) 

 

Security Tooling 

  • →Rapid7 - vulnerability management and scanning (InsightVM or InsightIDR); scan configuration, reporting, and SLA tracking 
  • →Wiz and/or Orca Security - CSPM/DSPM platform experience; cloud misconfiguration identification, prioritization, and remediation workflows 
  • →Microsoft Sentinel - SIEM administration, analytics rule management, and data connector configuration; familiarity with security log feeds from edge and email security platforms preferred 
  • →Microsoft Defender for Cloud - Defender plans (Servers, Containers, CSPM), agentless scanning, and security recommendation management 
  • →Datadog - log management, infrastructure monitoring, and security-adjacent alerting 
  • →Identity, Access & Privileged Access Management 
  • →Delinea Secret Server (Thycotic) - PAM administration, privileged credential vault management, and access policy configuration 
  • →Active Directory + Entra ID - hybrid identity, Entra Connect sync, group policy (GPO), DNS, and DHCP administration 
  • →Conditional Access, PIM, and RBAC - policy design, enforcement, and least-privilege access models at enterprise scale 
  • →Microsoft Intune - device compliance enforcement as part of a Zero Trust security posture 
  • →Certificate Management - PKI, TLS/SSL lifecycle management, certificate inventory, and renewal processes 

 

Network & Perimeter Security 

  • →Cloudflare (Enterprise) - CDN, WAF, DDoS protection, and DNS proxy configuration and management 
  • →Network routing and VPN - hub-and-spoke topology, route tables, ExpressRoute, and VPN Gateway 
  • →Cisco ASAv - virtual firewall configuration and management 
  • →DNS, DHCP, and Group Policy - enterprise-scale administration in hybrid environments 
  • →DevOps, IaC & Pipeline Security 
  • →Azure DevOps (ADO) - CI/CD pipeline security, build agent management, and secure pipeline design 
  • →GitHub / GitLab - source control security, branch protection, secret scanning, and pipeline hardening 
  • →Infrastructure-as-Code (IaC) - Terraform, ARM templates, or Bicep - with a security-first approach to cloud deployments 
  • →CHEF - configuration management and compliance-as-code for server fleet hardening and baseline enforcement 
  • →Endpoint & Server Platforms 
  • →Windows Server - administration, hardening, security baseline enforcement, and Group Policy management 
  • →Linux Server - administration, hardening, and security baseline enforcement across enterprise server fleets 
  • →Microsoft 365 Suite - Exchange, SharePoint, Teams, and Intune - security configuration and administration 

 

Frameworks & Compliance 

  • →Familiarity with NIST, HIPAA, and organizational Minimum Security Baselines (MSBs) 
  • →Understanding of Zero Trust architecture principles and how they apply across identity, network, and workload security 
  • →Familiarity with PCI-DSS scoped environment security requirements preferred 
  • →Experience operating in regulated industries (Financial Services, Insurance, or Health-Tech)  

 

Experience with or exposure to the following developer runtimes and technologies is a plus, as this role will consult on security posture within environments built on: 

  • →ASP.NET, .NET, Java (JBoss / Hibernate / JMS), gRPC, Redis, SQL Server 

Location & Eligibility

Where is the job
Headquarters - Oak Brook, United States
On-site at the office
Who can apply
US

Listing Details

First seen
September 25, 2026
Last seen
September 25, 2026

Posting Health

Days active
0
Repost count
0
Trust Level
52%
Scored at
September 25, 2026

Signal breakdown

freshnesssource trustcontent trustemployer trust
Newsletter

Stay ahead of the market

Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.

A
B
C
D
Join 12,000+ marketers

No spam. Unsubscribe at any time.

inspiracareersSr. Cloud Security Engineer (Remote)