CybersecurityJobs.io
← Back to all jobs

Job Description

ArdentMills is hiring a Cloud Security Engineer to design, implement, and operate security controls across Microsoft Azure environments, with possible expansion to other leading cloud platforms.

Responsibilities

  • Own the design and implementation of cloud landing zones, including identity and network controls (VPC/VNet, security groups/NSGs, private endpoints).
  • Configure and operate cloud-native security services, including Microsoft Defender for Cloud, Microsoft Sentinel, and Defender XDR.
  • Build posture management (CSPM) and workload protection (CWPP) using policy-as-code and automated remediation.
  • Implement key management, encryption at rest and in transit, and certificate governance using KMS/Key Vault/Cloud KMS.
  • Establish logging, telemetry, and alerting with Azure Monitor and integrate to SIEM/XDR; collaborate with IT and Security teams to test and validate detection coverage and maturity from cloud-native sources.
  • Harden serverless, containers, and managed services using baseline controls, including Functions, Logic Apps, Container Apps, AKS, and ACI.
  • Conduct threat modeling and security reviews for cloud architectures and application designs.
  • Partner with platform and product teams to deliver IaC guardrails, image baselines, and patch/vulnerability workflows.
  • Serve as a point of escalation for cloud incidents: perform triage and containment, drive post-incident improvements, and develop automation architecture to improve cloud detection and response.
  • Document standards and runbooks; run enablement sessions with dev and ops teams.
  • Design and support the cloud security strategy and program maturity.

Requirements

  • Bachelor’s in computer science/engineering or equivalent experience.
  • 4–7 years in cloud security engineering across at least one major CSP.
  • Strong knowledge of IAM, networking, encryption, and cloud-native security tooling.
  • Experience securing hybrid environments spanning on-premises and Azure cloud.
  • Scripting/automation skills: Python, Bash, or PowerShell.
  • Infrastructure as Code experience using Terraform, Bicep, or ARM.
  • Certifications: CCSP OR AWS Certified Security – Specialty OR Azure Security Engineer Associate (AZ-500) OR Google Professional Cloud Security Engineer.

Technologies

  • Microsoft Azure; VPC/VNet; security groups/NSGs; private endpoints
  • Microsoft Defender for Cloud; Microsoft Sentinel; Defender XDR; CSPM; CWPP; policy-as-code
  • KMS; Key Vault; Cloud KMS; encryption at rest/in transit; certificate governance
  • Azure Monitor; SIEM; XDR
  • Functions; Logic Apps; Container Apps; AKS; ACI
  • IaC; image baselines; patch/vulnerability workflows
  • Automation; AI-assisted capabilities
  • Python; Bash; PowerShell; Terraform; Bicep; ARM
  • CCSP; AWS Certified Security – Specialty; Azure Security Engineer Associate (AZ-500); Google Professional Cloud Security Engineer

Benefits

  • Medical, Dental and Vision Coverage
  • Health and Dependent Savings Accounts
  • Life and Disability Programs
  • Voluntary Benefit Programs
  • Company Sponsored Wellness Programs
  • Retirement Savings with Company Match
  • Team Member and Family Assistance Program (EAP)
  • Paid Time Off and Paid Holidays
  • Employee Recognition Program with Rewards (RAVE)

Good to Have

  • Experience with CIEM solutions and multi-cloud governance.
  • Certifications: GIAC Cloud (GCSA/GPCS); CNCF CKA/CKS; vendor pro-level architect certs.

Work Location and Schedule

  • Denver, CO (remote); remote eligible
  • Occasional after-hours support for incidents
  • On-call rotation for major incidents

Other Considerations

  • May support cloud migration programs and control design reviews.

Salary: USD 140,000 - 200,000 per yearly

Similar Jobs