Azure Security Engineer Job at Openkyber, New Mexico

Z3VQRTJUZlNFQVBmZExwYmdQdGpYYi9N
  • Openkyber
  • New Mexico

Job Description

Senior Cloud Security Engineer Location: Warren, NJ (Hybrid) contract

We re hiring a Senior Cloud Security Engineer to serve as the dedicated owner of cloud security remediation and hardening across our environment. Our organization already has an established security team that identifies risks and issues recommendations. This role does not sit on that team. Instead, you are the engineer who turns those recommendations into durable, well-architected fixes and, just as importantly, makes sure the same findings don t come back.

This is a hands-on engineering role, not an advisory one. Success means a measurably more secure environment, a shrinking backlog of recurring findings, and security controls that are enforced by design rather than by manual effort or one-off patches.

What You ll Do

Remediation & recurrence prevention (the core of this role)

  • Own the full lifecycle of security findings and recommendations whether they come from the security team, Microsoft Defender for Cloud, or other tooling through triage, remediation, verification, and closure.
  • Root-cause recurring issues and implement systemic fixes (policy-as-code, automated guardrails, secure baselines) so the same findings don t reappear quarter after quarter.
  • Track remediation SLAs and report on risk reduction and posture trends over time.

Identity & authentication

  • Secure and govern modern authentication flows across the estate: OIDC, OAuth 2.0 with PKCE, JWT validation and handling, and mTLS .
  • Administer and harden Microsoft Entra ID (Azure Entra) : app registrations and Enterprise Application permissions, consent governance, service principals and managed identities, credential and secret hygiene, and least-privilege scoping.
  • Design, implement, and continuously tune Conditional Access policies.

Cloud security engineering & governance

  • Build and enforce guardrails using Azure Policy and Terraform ; maintain secure-by-default infrastructure-as-code baselines and detect/remediate configuration drift.
  • Operate Microsoft Defender for Cloud drive secure-score improvement, remediate recommendations, and manage cloud security posture (CSPM).
  • Contribute to security governance : standards, control definitions, exception handling, and audit evidence.

Admin portal & privileged access security

  • Secure all cloud and SaaS administrative portals Azure and other admin consoles (e.g., Microsoft 365 admin, identity providers, and any additional cloud platforms in use).
  • Strengthen privileged access: MFA enforcement, Privileged Identity Management (PIM) / just-in-time elevation, role minimization, and break-glass procedures.

AI security

  • Apply security controls to AI workloads, services, and AI agents : agent and workload identities, tool and permission scoping, data-exposure and prompt-injection risk, and emerging AI security best practices.
What You Bring (Required)
  • 8+ years in cloud security or security engineering, with deep, hands-on Azure experience.
  • Strong, hands-on Microsoft Entra ID expertise: app registrations, Enterprise Apps, permissions and consent, and Conditional Access.
  • Solid working knowledge of modern authentication: OIDC, OAuth 2.0 / PKCE, JWT, and mTLS .
  • Proficiency with Terraform and Azure Policy for policy-as-code and automated guardrails.
  • Experience with Microsoft Defender for Cloud and cloud security posture management.
  • A demonstrable track record of root-causing and permanently closing security findings not just patching them.
  • Working understanding of AI, AI agents, and AI security considerations.
Nice to Have
  • Multi-cloud exposure (AWS, Google Cloud Platform).
  • Relevant certifications (e.g., Microsoft SC-100, AZ-500, SC-300 ; CISSP).
  • Experience with CI/CD pipeline security, secrets management, and SIEM/SOAR.
  • Scripting/automation (PowerShell, Python).
  • Hands-on experience securing LLM-based or agentic systems in production.

For applications and inquiries, contact: hirings@openkyber.com

Job Tags

Contract work

Similar Jobs

Federal Management Systems

Junior Compliance Officer Job at Federal Management Systems

 ...We are seeking a detail-oriented Junior Compliance Officer to support crucial federal compliance operations. This role focuses on extensive data entry, database research, and compliance auditing. You will work closely with Auditors and Criminal Investigators to maintain... 

Senior Helpers - Denver North

Corporate Pilot with AgingCare Do Not Delete Job at Senior Helpers - Denver North

Exciting New Part-Time Personal Caregiver Position Job Summary:Senior Helpers - Denver...  ...in their homes, helping them with daily tasks and activities. The Personal Caregiver...  ...:$18.50 to $22.50 per hour with Daily Pay available (paid biweekly)We offer BOTH... 

Mastercard

Senior Project Management Analyst - Cards & Payments Job at Mastercard

 ...Summary Senior Project Management Analyst Cards & Payments Responsible for ensuring coordination with all MasterCard teams including...  ... Availability to be in the office 3 times per week. Corporate Security Responsibility All activities involving access to Mastercard... 

Jazz Pharmaceuticals

Associate Medical Director, Medical Safety Job at Jazz Pharmaceuticals

If you are a current Jazz employee please apply via the Internal Career site. Jazz Pharmaceuticals is a global biopharma company whose purpose is to innovate to transform the lives of patients and their families. We are dedicated to developing life-changing medicines...

Gpac

Compliance Officer Job at Gpac

Compliance Officer: The Compliance Officer is responsible for various compliance areas including training, monitoring reviews, policy and procedures, and product development with each department of the bank. The Compliance Officer helps ensure the Bank maintains a strong...