GROUP 107
Senior Azure Cloud Security Engineer
Remote Senior $4.7k–$12.8k/moest.
Summary
IMTC is seeking a Senior Azure Cloud Security Engineer to strengthen and scale cloud network security capabilities across a distributed organization operating in the US, Europe, and Latin America. This role offers meaningful ownership within a mature, Azure-native security practice focused on advancing network architecture, deepening zero-trust posture, and meeting enterprise and regulatory requirements.
What you'll do
- Own and continuously improve Azure network architecture, including VNet topology (hub-spoke or VWAN), NSGs, Azure Firewall Premium, and Private Link/Private Endpoints
- Drive maturation of zero-trust security model across Azure environment, including Entra ID Conditional Access, PIM, and workload identity management
- Operate and enhance Microsoft Defender for Cloud and Microsoft Sentinel, including tuning detection, managing incidents, and improving coverage
- Maintain and strengthen network security controls aligned with SOC 2 Type II requirements
- Produce and maintain security documentation, network diagrams, data flow maps, and evidence packs for auditors and enterprise DDQs
- Evaluate and govern ExpressRoute/VPN Gateway configurations for client-dedicated connectivity
- Design and manage integrations with external identity and authentication providers using SAML, OIDC, and OAuth 2.0 federation
- Partner with engineering teams to embed security practices into CI/CD pipelines and DevOps workflows
- Serve as technical authority on cloud security architecture in client security reviews and enterprise onboarding engagements
Requirements
- 5+ years of experience in cloud infrastructure or security engineering, with at least 3 years focused on Microsoft Azure
- Deep hands-on expertise with Azure Firewall Premium, NSGs, Private Link, VNet peering, and hub-spoke/VWAN topology
- Strong working knowledge of Entra ID (Azure AD), Conditional Access, and Privileged Identity Management (PIM), and managed identities
- Proven experience integrating external identity providers (Okta, Ping Identity, Auth0) with Azure AD/Entra ID using SAML, OIDC, or OAuth 2.0
- Experience operating Microsoft Defender for Cloud and Microsoft Sentinel (SIEM/SOAR)
- Solid grounding in zero-trust architecture principles and practical implementation in Azure-native environment
- Hands-on experience with SOC 2 (producing evidence, working with auditors, owning control domains)
- Experience supporting enterprise client security reviews or completing vendor DDQs
- Comfortable working in fast-paced, distributed engineering team using agile methodologies and DevOps practices
- Advanced English (C1)+
- Nice to have: Experience with IaC tools (Terraform, Bicep, ARM templates), background in financial services/FinTech/regulated industries, relevant certifications (AZ-500, SC-100, SC-200, CISSP, CCSP)
Conditions
- 20 vacation days (workdays)
- 7 sick days
- Personalized career growth
- Internal English classes
- Education reimbursement
- Corporate events and team buildings
- Equipment provided