Senior Cloud Platform Security Engineer
Quick Summary
Partner with Data & AI teams to implement data governance and security controls covering discovery, classification, lineage, retention, DLP, access governance, and approved AI services, while securing
As a Senior Cloud Platform Security Engineer, you will be the primary technical owner of a large-scale Azure platform, cloud security controls, and infrastructure operations. You’ll play a hands-on role in keeping cloud environments secure, reliable, scalable, compliant, and operationally efficient. The position spans cloud architecture, identity and access management, security operations, infrastructure automation, compliance, disaster recovery, and cost optimization. You’ll also help enable secure data, AI, and agent-based workloads across a growing technology environment. Working as a senior individual contributor, you’ll collaborate closely with Technology, Engineering, Data & AI, Compliance, business stakeholders, auditors, vendors, and external partners. This is an opportunity to shape cloud standards, automate critical processes, strengthen security posture, and directly influence the resilience of an evolving technology platform.
- Own the Azure platform: Design, configure, operate, and continuously improve Azure subscriptions, management groups, networking, compute, storage, platform services, and shared infrastructure while establishing standards for environment separation, naming, tagging, approved services, secure configurations, and change management.
- Strengthen cloud identity and security: Design and maintain Microsoft Entra ID, MFA, Conditional Access, PIM, RBAC, managed identities, access reviews, emergency-access procedures, least-privilege controls, separation of duties, network segmentation, private connectivity, firewalls, DNS security, secure ingress and egress, and secrets management.
- Improve security operations and incident readiness: Operate cloud-security posture management, vulnerability remediation, configuration monitoring, logging, detection, and threat-response capabilities while developing actionable alerts, dashboards, escalation paths, and runbooks for security incidents.
- Build reliable infrastructure through automation: Develop and maintain infrastructure using Terraform, Bicep, ARM templates, or comparable technologies, establishing reusable modules, peer-review practices, automated testing, deployment controls, and configuration-drift management.
- Support compliance and technology risk: Translate requirements such as the GLBA Safeguards Rule, SOC 2, NIST Cybersecurity Framework, customer commitments, and internal policies into practical technical controls, documentation, evidence, and measurable outcomes while supporting audits and remediation activities.
- Enable secure Data & AI operations: Partner with Data & AI teams to implement data governance and security controls covering discovery, classification, lineage, retention, DLP, access governance, and approved AI services, while securing AI, machine-learning, LLM, and agent-based workloads through appropriate data boundaries, privileged-action controls, logging, monitoring, human approval, and incident-response measures.
- Drive reliability, recovery, and operational excellence: Maintain at least 99.9% availability for critical platform services within your operational control, support agreed Sev-1/2 response expectations, validate disaster recovery at least twice annually, and ensure critical services have effective monitoring, alerting, escalation paths, and documented recovery procedures.
- Improve infrastructure-as-code adoption: Drive toward at least 95% of production infrastructure being managed through infrastructure as code while reducing configuration drift and improving deployment consistency.
- Manage cloud costs and efficiency: Own cloud budgets, alerts, tagging standards, forecasting inputs, and recurring optimization recommendations, maintaining at least 98% resource-tagging compliance and evaluating Azure-native and third-party solutions based on effectiveness, maintenance effort, licensing cost, and architectural fit.
- Collaborate across technical and business functions: Work effectively with engineering teams, executives, auditors, managed-service providers, technology vendors, and distributed stakeholders while documenting architecture, standards, risk statements, runbooks, and executive-level updates.
Requirements
~2 min read- Cloud and security experience: 7+ years of hands-on cloud infrastructure or security engineering experience, including ownership of production Azure environments and demonstrated senior-level responsibility.
- Azure expertise: Strong experience with Azure subscriptions and management groups, networking, Microsoft Entra ID, RBAC, Azure Policy, monitoring, backup and recovery, security controls, and cloud cost management.
- Infrastructure as code: Demonstrated experience with Terraform, Bicep, ARM templates, or comparable infrastructure-as-code technologies, including source control, peer review, automated testing, and deployment practices.
- Security operations: Practical experience with cloud security operations, vulnerability remediation, logging and detection, incident response, access governance, configuration monitoring, and disaster-recovery testing.
- Data governance: Working knowledge of Microsoft Purview or comparable data-governance platforms, including classification, lineage, retention, DLP, and access controls.
- Compliance and risk: Experience translating regulatory, customer, or internal control requirements into technical designs, operating procedures, audit evidence, and measurable results; experience in financial services or another regulated environment is preferred.
- AI security: Experience securing AI, machine-learning, large-language-model, or agent-based workloads in production is preferred.
- Technical toolkit: Experience with Azure Monitor, Log Analytics, Microsoft Defender for Cloud, Microsoft Sentinel or comparable SIEM platforms, Azure DevOps pipelines, Azure Policy, Azure Key Vault, backup and recovery technologies, cloud networking, segmentation, firewalls, DNS security, zero-trust architectures, certificate and key management, and FinOps practices.
- Platform security: Experience with Databricks platform security, Microsoft 365 security, and SaaS identity integrations where applicable.
- Certifications: Relevant Microsoft certifications such as Azure Security Engineer Associate, Cybersecurity Architect Expert, Security Operations Analyst Associate, or Azure Solutions Architect Expert are preferred.
- Documentation and communication: Strong documentation skills across runbooks, architecture diagrams, standards, risk statements, and executive updates, with the ability to communicate clearly with technical teams, business stakeholders, executives, auditors, vendors, and external partners.
- Problem-solving and judgment: Strong independent judgment, risk-based decision-making, analytical thinking, and the ability to investigate complex systems, identify root causes, and continuously improve technology operations.
- Collaboration and adaptability: Comfortable balancing security, reliability, compliance, cost, and business priorities while managing multiple initiatives in a fast-moving environment and working effectively across distributed teams.
- Growth mindset: Naturally curious and proactive, with a demonstrated interest in automation, simplification, process improvement, and emerging cloud and security technologies.
What We Offer
~2 min readLocation & Eligibility
Listing Details
- Posted
- October 6, 2026
- First seen
- October 6, 2026
- Last seen
- October 6, 2026
Posting Health
- Days active
- 0
- Repost count
- 0
- Trust Level
- 68%
- Scored at
- October 6, 2026
Signal breakdown
Browse Similar Jobs
Stay ahead of the market
Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.
No spam. Unsubscribe at any time.