Cloud Security Engineer

LucyRx

$120K — $140K *
US-AnywhereRemote in United States
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years of experience in cloud engineering, security engineering, or infrastructure security roles.
  • Hands-on experience securing Azure environments with a focus on identity, networking, and workload protections.
  • Deep understanding of Azure security architecture and shared responsibility models.
  • Proven experience implementing identity-centric security models like MFA and Conditional Access.
  • Ability to translate security requirements into enforceable technical controls.
  • Strong documentation skills and disciplined approach to configuration management.
  • AZ-500 certification required; SC-300 recommended.

Responsibilities

  • Design and implement Azure security controls for identity, networking, and workloads.
  • Operate and maintain security tools like Defender for Cloud and Microsoft Sentinel.
  • Develop and refine Conditional Access, MFA, and Zero Trust identity patterns.
  • Embed security into cloud platform standards and Infrastructure-as-Code pipelines.
  • Collaborate with Cloud Engineers to ensure consistent secure cloud architectures.
  • Align cloud-native controls with network and infrastructure security standards.
  • Monitor security posture, review alerts, and engage in incident response activities.

Benefits

  • Comprehensive health insurance coverage.
  • Retirement savings plan with employer contributions.
  • Professional development opportunities and support for obtaining certifications.
  • Flexible work environment with options for remote work.
  • Paid time off and holidays.
Full Job Description
The Cloud Security Engineer designs, implements, and enforces cloud-native security controls directly within Azure, with a focus on identity-first security, workload protection, and secure cloud architectures. This role ensures that security is built into the cloud platform itself, not layered on after deployment. The Cloud Security Engineer partners closely with Cloud Engineers, Infrastructure Security Engineers, and operations teams to ensure that Azure environments are secure by default, compliant by design, and resilient under real-world operating conditions. Role and Responsibilities: On a day-to-day basis, the Cloud Security Engineer focuses on engineering and operating security controls inside Azure, translating security requirements into enforceable technical guardrails. This role combines design authority, hands-on implementation, and operational accountability. CORE RESPONSIBILITIES • Design and implement Azure security controls across identity, networking, and workloads, including native Azure services and security features. • Operate and maintain Defender for Cloud, Microsoft Sentinel, and related security posture and monitoring tools. • Design, implement, and continuously refine Conditional Access, MFA, and Zero Trust identity patterns. • Embed security controls into cloud platform standards and Infrastructure-as-Code pipelines, ensuring security is repeatable and auditable. • Partner with Cloud Engineers to ensure secure cloud architectures are implemented consistently across environments. • Partner with Infrastructure Security Engineers to align cloud-native controls with network and infrastructure security enforcement. • Monitor security posture, review alerts, and participate in incident response related to cloud security events. • Identify gaps in cloud security controls and drive remediation through improved design, automation, or policy enforcement. • Produce and maintain security documentation, metrics, and evidence to support leadership reporting and regulatory requirements. • Participate in post-incident reviews and root-cause analysis to strengthen cloud security posture over time. Qualifications & Education Requirements: • 5+ years of experience in cloud engineering, security engineering, or infrastructure security roles. • Strong hands-on experience securing Azure environments, including identity, networking, and workload protections. • Deep understanding of Azure security architecture, including native controls and shared responsibility models. • Proven experience implementing identity-centric security models (MFA, Conditional Access, least-privilege access). • Ability to translate security requirements into enforceable technical controls, not just policy statements. • Strong documentation skills and a disciplined approach to configuration and change management. • AZ-500 (Azure Security Engineer Associate) - required • SC-300 (Identity and Access Administrator Associate) - strongly recommended • Bachelor's degree in Information Security, Computer Science, or a related field preferred. • Equivalent cloud security engineering experience, certifications, and demonstrated outcomes are accepted in lieu of a degree. Preferences: • Experience designing and operating security controls in regulated environments (e.g., PBM, healthcare, financial services). • Familiarity with cloud governance frameworks, security posture management, and compliance evidence collection. • Experience automating security controls using Infrastructure-as-Code or policy-as-code approaches. • Comfort operating as a security decision-maker within engineering and operations teams. Physical Requirements The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job. This is a largely sedentary role; however, some standing, walking, bending, and reaching may be required. Regularly operates in an office or home office setting which involves utilizing a computer, mouse, keyboard, and occasionally operating other standard office equipment, such as printer, copier, phone. Travel may be required by either car or airplane, or a combination of multiple modes of transportation.

Similar Jobs

More Jobs at LucyRx

More Information Technology Jobs

Find similar Cloud Security Engineer jobs: