Cloud Security Engineer

Morgan & Morgan, P.A.

$100K — $120K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 5-7 years of experience as a Security Engineer in a large, multi-state organization.
  • Hands-on expertise with Microsoft security tools like Defender XDR and Sentinel and proficient in KQL.
  • Experience in M365 tenant hardening, Azure security, and security automation practices.
  • Knowledge of vulnerability assessments and securing AI workloads in enterprise settings.
  • Effective communicator with strong organizational and time-management skills.

Responsibilities

  • Engineer and optimize detections and response workflows using Microsoft Defender XDR and Sentinel.
  • Lead M365 tenant hardening initiatives and maintain secure configurations.
  • Administer endpoint security using Microsoft Defender and Intune to enhance device compliance.
  • Implement security automation to streamline processes and accelerate threat response.
  • Oversee Azure infrastructure security, focusing on cloud governance best practices.
  • Manage data governance and compliance with Microsoft Purview tools and practices.
  • Document security standards and communicate risks and strategies clearly to stakeholders.

Benefits

  • Medical and dental insurance coverage.
  • 401(k) retirement plan participation.
  • Paid time off along with designated paid holidays.
Full Job Description
Cloud Security Engineer

Location: Orlando, FL or Tampa, FL (Onsite, Full-Time)

Work Arrangement: This is an in-office position, open to local candidates only.
About the Role

Our firm is a large, multi-state law practice with a sophisticated technology environment and a deep responsibility to protect highly sensitive client and matter data. We are seeking a Cloud Security Engineer to strengthen and mature our Microsoft-centered security program. This is a hands-on engineering role for someone who thrives on threat detection, tenant hardening, identity modernization, and security automation - and who can clearly communicate risk and remediation to both technical teams and firm leadership.
Key Responsibilities
Detection and Response
  • Engineer, tune, and operate detections and response workflows across Microsoft Defender XDR and Microsoft Sentinel, including authoring and optimizing KQL queries, analytics rules, workbooks, and hunting content.
Tenant and Endpoint Hardening
  • Lead and execute M365 tenant hardening initiatives across the E5 stack, establishing and maintaining secure baselines and configuration standards.
  • Administer and harden endpoint security through Microsoft Defender for Endpoint and Intune, including device compliance, configuration profiles, and attack surface reduction.
Security Automation and Vulnerability Management
  • Build and maintain security automation (e.g., Logic Apps, automation rules/playbooks, PowerShell, Azure Functions) to reduce manual effort and accelerate response.
  • Own vulnerability assessment and remediation tracking, partnering with IT and infrastructure teams to close gaps.
Cloud, Identity, and Data Governance
  • Secure and govern Azure infrastructure, applying cloud security best practices across resources and workloads.
  • Configure and manage Microsoft Purview for data governance, information protection, data loss prevention, insider risk, and compliance.
  • Strengthen identity and access management (IAM) practices firm-wide, including least-privilege enforcement and access reviews.
AI Security and Documentation
  • Secure and govern AI and AI agents across the firm, addressing data exposure, identity and access for agents, acceptable-use controls, and the confidentiality and privilege concerns unique to a legal environment.
  • Document standards, procedures, and runbooks; communicate security posture, incidents, and recommendations clearly to technical staff and firm leadership.
  • Manage application security assessments and lifecycle oversight to retire applications that are inactive or pose security risks.
Qualifications
  • Strong hands-on expertise across: Defender XDR enterprise defense suite and Microsoft Sentinel with proficient KQL; M365 tenant hardening (Entra ID, Exchange, Teams, SharePoint); Azure infrastructure security; security automation (SOAR); Entra ID and Conditional Access; vulnerability assessment; Defender for Endpoint, Intune, Application Control; and Microsoft Purview (DSPM, IP, DLP, IRM, DLM, AI).
  • Strong technical, organizational, time-management, and communication skills.
  • Participate in scheduled after-hours changes as needed.
Education and Experience
  • Experience at a law firm or in a similarly regulated, confidentiality-driven environment.
  • Demonstrated experience securing AWS and/or GCP environments in enterprise settings.
  • Experience designing and implementing security controls for AI and agent-based workloads.
  • 4-7+ years of experience as a Security Engineer at a large, multi-state organization.

#LI-MB1

Benefits

Morgan & Morgan is a leading personal injury law firm dedicated to protecting the people, not the powerful. This success starts with our staff. For full-time employees, we offer an excellent benefits package including medical and dental insurance, 401(k) plan, paid time off and paid holidays.

Similar Jobs

More Jobs at Morgan & Morgan, P.A.

More Information Technology Jobs

Find similar Cloud Security Engineer jobs: