Full Job Description
Brown Advisory is currently seeking a pragmatic and hands-on Cloud Security Engineer to strengthen the firm's Azure security posture and help mature secure cloud operations. This blended role is designed for a security professional who can operate across cloud configuration, SaaS security, application integration, and security tooling without losing sight of business enablement.
As part of a lean Information Security team within a mid-sized financial services organization, this individual will partner closely with Infrastructure, Engineering, Enterprise Applications, third-party developers, and Risk partners. The role will help ensure that Brown Advisory-hosted applications, cloud services, and SaaS platforms are configured securely, monitored effectively, and integrated into the firm's broader security control environment.
Blended Role Coverage
Primary emphasis: Cloud Security Engineer with a specific focus on secure Azure management, application hosting, and cloud control maturity.
Blended coverage: Application Security / DevSecOps Analyst, SaaS security administration, cloud tool operations, SIEM integration support, and third-party application-development security guidance.
Duties and Responsibilities
• Own day-to-day security engineering for Azure environments, including secure configuration, cloud control hardening, logging, monitoring, and remediation follow-through.
• Partner with Infrastructure and Engineering teams to implement Azure security baselines, secure networking patterns, key management practices, storage protections, and workload guardrails.
• Support Microsoft Defender for Cloud, Azure Policy, Entra-adjacent cloud controls, conditional access inputs, and other Microsoft security capabilities as part of the broader cloud security stack.
• Review Brown Advisory-hosted applications and third-party-developed cloud solutions for secure architecture, authentication, authorization, logging, data protection, and operational readiness.
• Configure and improve security controls for SaaS platforms such as Salesforce, Box, Microsoft 365, and other business-critical cloud applications.
• Support limited DevSecOps activities, including static and dynamic application-security testing coordination, vulnerability triage, and practical remediation guidance for internal and third-party development teams.
• Integrate cloud, SaaS, and application telemetry into SIEM and detection workflows, and partner with Security Operations on actionable alerting and response procedures.
• Maintain sanctioned application lists, cloud security standards, exception records, and implementation documentation in partnership with GRC and technology owners.
• Execute immediate remediation actions where appropriate and coordinate more complex fixes across platform, application, and vendor teams.
• Develop clear reporting on cloud security posture, open risks, remediation progress, and control maturity for security and technology leadership.
Preferred Qualifications
• Bachelor's degree in cyber security, computer science, engineering, information systems, or a relevant field, or equivalent professional experience.
• 4-8 years of experience in information security, cloud security, infrastructure security, application security, or a related technical discipline.
• Hands-on experience securing Microsoft Azure environments; financial services or other regulated-industry experience preferred.
• Ability to work independently in a lean team while coordinating across technology, vendor, risk, and business stakeholders.
• Microsoft Azure security certifications, CISSP, CCSP, or other relevant professional designations preferred.
Technical Skills
• Azure security architecture, Defender for Cloud, Azure Policy, logging, monitoring, and secure configuration practices.
• Microsoft 365 security and compliance concepts, including integration points with Entra ID, Purview, Defender, and conditional access.
• SaaS security administration for platforms such as Salesforce, Box, and other enterprise cloud applications.
• Static and dynamic application-security testing concepts, vulnerability triage, and secure SDLC practices.
• SIEM integration patterns, alert tuning, security telemetry, and operational handoff to incident response teams.
• Strong written communication skills for standards, procedures, exception documentation, and leadership reporting.
• Demonstrates curiosity and a continuous improvement mindset by identifying opportunities to enhance processes, improve efficiency, and thoughtfully leverage new technologies and tools, including AI-enabled productivity solutions
Personal Attributes
• Take ownership and move initiatives forward without constant oversight.
• Balance technical depth, process discipline, and sound business judgment.
• Approach risk management pragmatically rather than theoretically.
• Thrive in collaborative, high-accountability environments.
• Communicate clearly with technical and non-technical colleagues.
• Bring an entrepreneurial mindset to building and improving security capabilities.
Applicants must be authorized to work in the United States without the need for current or future employer-sponsored work authorization (e.g., H-1B , O-1, F-1 (OPT), TN, or any other non-immigrant visa classifications that require employer support or sponsorship).
MD Salary: $140-$150k. Commensurate with experience and location. Does not include bonus or long term incentive eligibility (if applicable).
Benefits
At Brown Advisory we offer a competitive compensation package, including full benefits.
• Medical
• Dental
• Vision
• Wellness program participation incentive
• Financial wellness program
• Fitness event fee reimbursement
• Gym membership discounts
• Colleague Assistance Program
• Telemedicine Program (for those enrolled in Medical)
• Adoption Benefits
• Daycare late pick-up fee reimbursement
• Basic Life & Accidental Death & Dismemberment Insurance
• Voluntary Life & Accidental Death & Dismemberment Insurance
• Short Term Disability
• Paid parental leave
• Group Long Term Disability
• Pet Insurance
• 401(k) (50% employer match up to IRS limit, 4 year vesting)