Cloud Security Engineer
Azure
Azure Developer Associate
Azure Functions
Azure Networking
Cloud
Cloud Infrastructure
Cloud Operations
Cloud Platform
Cloud Platforms
Cloud Security
Cloud Security Architecture
Cloud Security Assurance
Cloud Security Posture Management
Cloud Workload Protection Platform
Data Security
Defender For Cloud
Engineer
Facilities Management
Identity and Access Management
Information Security
Information Technology (IT)
InfoSec
Microsoft Azure
Microsoft Sentinel
Project Management
Risk Governance
Risk Management
Security
Security Automation
Security Compliance
Security Operations
Security Standards
Security Testing
Solution Architecture
Job Description
ArdentMills is hiring a Cloud Security Engineer to design, implement, and operate security controls across Microsoft Azure environments, with possible expansion to other leading cloud platforms.
Responsibilities
- Own the design and implementation of cloud landing zones, including identity and network controls (VPC/VNet, security groups/NSGs, private endpoints).
- Configure and operate cloud-native security services, including Microsoft Defender for Cloud, Microsoft Sentinel, and Defender XDR.
- Build posture management (CSPM) and workload protection (CWPP) using policy-as-code and automated remediation.
- Implement key management, encryption at rest and in transit, and certificate governance using KMS/Key Vault/Cloud KMS.
- Establish logging, telemetry, and alerting with Azure Monitor and integrate to SIEM/XDR; collaborate with IT and Security teams to test and validate detection coverage and maturity from cloud-native sources.
- Harden serverless, containers, and managed services using baseline controls, including Functions, Logic Apps, Container Apps, AKS, and ACI.
- Conduct threat modeling and security reviews for cloud architectures and application designs.
- Partner with platform and product teams to deliver IaC guardrails, image baselines, and patch/vulnerability workflows.
- Serve as a point of escalation for cloud incidents: perform triage and containment, drive post-incident improvements, and develop automation architecture to improve cloud detection and response.
- Document standards and runbooks; run enablement sessions with dev and ops teams.
- Design and support the cloud security strategy and program maturity.
Requirements
- Bachelor’s in computer science/engineering or equivalent experience.
- 4–7 years in cloud security engineering across at least one major CSP.
- Strong knowledge of IAM, networking, encryption, and cloud-native security tooling.
- Experience securing hybrid environments spanning on-premises and Azure cloud.
- Scripting/automation skills: Python, Bash, or PowerShell.
- Infrastructure as Code experience using Terraform, Bicep, or ARM.
- Certifications: CCSP OR AWS Certified Security – Specialty OR Azure Security Engineer Associate (AZ-500) OR Google Professional Cloud Security Engineer.
Technologies
- Microsoft Azure; VPC/VNet; security groups/NSGs; private endpoints
- Microsoft Defender for Cloud; Microsoft Sentinel; Defender XDR; CSPM; CWPP; policy-as-code
- KMS; Key Vault; Cloud KMS; encryption at rest/in transit; certificate governance
- Azure Monitor; SIEM; XDR
- Functions; Logic Apps; Container Apps; AKS; ACI
- IaC; image baselines; patch/vulnerability workflows
- Automation; AI-assisted capabilities
- Python; Bash; PowerShell; Terraform; Bicep; ARM
- CCSP; AWS Certified Security – Specialty; Azure Security Engineer Associate (AZ-500); Google Professional Cloud Security Engineer
Benefits
- Medical, Dental and Vision Coverage
- Health and Dependent Savings Accounts
- Life and Disability Programs
- Voluntary Benefit Programs
- Company Sponsored Wellness Programs
- Retirement Savings with Company Match
- Team Member and Family Assistance Program (EAP)
- Paid Time Off and Paid Holidays
- Employee Recognition Program with Rewards (RAVE)
Good to Have
- Experience with CIEM solutions and multi-cloud governance.
- Certifications: GIAC Cloud (GCSA/GPCS); CNCF CKA/CKS; vendor pro-level architect certs.
Work Location and Schedule
- Denver, CO (remote); remote eligible
- Occasional after-hours support for incidents
- On-call rotation for major incidents
Other Considerations
- May support cloud migration programs and control design reviews.
Salary: USD 140,000 - 200,000 per yearly