We have a permanent direct hire role for an Azure Security Engineer with Microsoft Defender, Entra and intune experience.
- Designs, implements, and manages security controls across the organization's Azure cloud environment, ensuring secure configurations, access controls, and compliance with company standards.
- Supports the organization's transition from on-prem infrastructure to Azure by embedding security into architecture, migration, and deployment processes.
- Establishes and maintains cloud security baselines, guardrails, and configuration standards (identity, networking, and data protection).
- Configures and manages Microsoft Defender for Cloud and Azure Security Center to monitor posture, secure score, and alerts.
- Acts as the organization's cloud security SME, supporting IT and engineering teams through design reviews, threat modeling, and security validation.
- Partners with infrastructure, application, and data teams to integrate security into system design and project delivery.
- Identifies and remediates security gaps in Azure and hybrid architectures.
- Implements and manages secure identity and access controls using Entra ID and related technologies (RBAC, Conditional Access, least privilege principles).
- Supports the design and implementation of identity strategies across cloud and on-prem environments.
- Manages and enhances device compliance and endpoint security using Microsoft Intune, including compliance policies and conditional access enforcement.
- Develops and enhances threat detection capabilities across Azure and enterprise environments using Microsoft-native telemetry.
- Participates in incident response activities, including investigation, containment, and post-incident reviews.
- Builds and maintains automation workflows for security monitoring, alerting, and response.
- Improves security processes through scripting and integration with existing tools and platforms.
- Develops and tracks KPIs and metrics to measure cloud security posture and program effectiveness.
- Supports security audits and helps ensure compliance with applicable regulatory frameworks.
- Develops and maintains cloud-specific security standards, procedures, and documentation.
- Contributes to vulnerability management and risk remediation efforts across cloud and enterprise systems.
- Works closely with IT, security, and business stakeholders to align security initiatives with organizational goals.
- Serves as the organization's primary point of contact for cloud security given the company's size, including managing relevant vendor relationships (a plus, not required).
- Provides guidance on emerging cloud threats, risks, and best practices.
- Supports disaster recovery and business continuity planning for cloud systems.
- Other duties as assigned.
Qualifications
- 7+ years of progressive experience in information security or systems engineering, with hands-on experience securing Azure cloud environments and enterprise infrastructure.
- Strong technical experience with Entra ID, Intune, and Microsoft Defender for Cloud / Azure Security Center.
- Strong technical experience with cloud security controls, identity and access management (RBAC, Conditional Access), endpoint security, and device compliance.
- Proven ability to collaborate across IT operations, engineering, and business teams to embed security into system design, implementation, and ongoing operations.
- Experience with vulnerability management, incident response, and threat detection.
- Strong analytical and problem-solving skills with the ability to translate risk into actionable recommendations.
- Experience supporting cloud migrations or transformation initiatives.
- Experience with scripting or automation (PowerShell preferred).
- Leadership experience or vendor relationship management is a plus, given this role acts as the primary cloud security resource for the company.
Azure Security Engineer in sacramento at Unknown Company
This position is listed as full time and hybrid.