Cloud Security Engineer
Azure
Azure Developer Associate
Azure Functions
Azure Networking
Cloud
Cloud Infrastructure
Cloud Operations
Cloud Platform
Cloud Platforms
Cloud Security
Cloud Security Architecture
Cloud Security Assurance
Cloud Security Posture Management
Cloud Workload Protection Platform
Data Security
Defender For Cloud
Facilities Management
Identity and Access Management
Information Security
Information Technology (IT)
InfoSec
Microsoft Azure
Microsoft Sentinel
Project Management
Risk Governance
Risk Management
Security
Security Automation
Security Compliance
Security Operations
Security Standards
Security Testing
Solution Architecture
Job Description
ArdentMills is hiring a Cloud Security Engineer to build and operate security controls in Microsoft Azure, with room to expand across other major cloud platforms.
Responsibilities
- Design and deliver security landing zones, including identity and network controls (VPC/VNet, security groups/NSGs, private endpoints).
- Configure and operationalize cloud-native protection services such as Microsoft Defender for Cloud, Microsoft Sentinel, and Defender XDR.
- Implement posture management (CSPM) and workload protection (CWPP) using policy-as-code and automated remediation.
- Set up key management and enforce encryption at rest and in transit, including certificate governance via KMS/Key Vault/Cloud KMS.
- Establish logging, telemetry, and alerting using Azure Monitor and integrate with SIEM/XDR; collaborate with IT and Security to validate detection coverage and maturity from cloud-native sources.
- Harden security posture for serverless, containers, and managed services including Functions, Logic Apps, Container Apps, AKS, and ACI using baseline controls.
- Conduct threat modeling and security reviews for cloud architectures and application designs.
- Work with platform and product teams to deliver IaC guardrails, image baselines, and patch/vulnerability workflows.
- Serve as an escalation point for cloud incidents: perform triage, containment, and post-incident improvements; design automation to optimize cloud detection and response.
- Use automation and AI-assisted capabilities where applicable to improve detection and response effectiveness.
- Document standards and runbooks; run enablement sessions with dev and ops teams.
- Partner on cloud security strategy and program maturity development.
- Support cloud migration programs and perform control design reviews as needed.
Requirements
- Bachelor’s in computer science/engineering or equivalent experience.
- 4–7 years in cloud security engineering across at least one major CSP.
- Strong knowledge of IAM, networking, encryption, and cloud-native security tooling.
- Experience securing hybrid environments spanning on-premises and Azure cloud.
- Scripting/automation experience with Python/Bash/PowerShell and IaC tooling such as Terraform/Bicep/ARM.
- Certifications: CCSP; AWS Certified Security – Specialty; Azure Security Engineer Associate (AZ-500); or Google Professional Cloud Security Engineer.
Technologies
- Microsoft Azure, VPC/VNet, security groups/NSGs, private endpoints
- Microsoft Defender for Cloud, Microsoft Sentinel, Defender XDR
- CSPM, CWPP, policy-as-code
- KMS, Key Vault, Cloud KMS; encryption at rest/in transit; certificate governance
- Azure Monitor, SIEM, XDR
- Functions, Logic Apps, Container Apps, AKS, ACI
- IaC, image baselines, patch/vulnerability workflows
- Automation, AI-assisted capabilities
- Python, Bash, PowerShell; Terraform, Bicep, ARM
- CCSP; AWS Certified Security – Specialty; Azure Security Engineer Associate (AZ-500); Google Professional Cloud Security Engineer
Benefits
- Medical, Dental and Vision Coverage
- Health and Dependent Savings Accounts
- Life and Disability Programs
- Voluntary Benefit Programs
- Company Sponsored Wellness Programs
- Retirement Savings with Company Match
- Team Member and Family Assistance Program (EAP)
- Paid Time Off and Paid Holidays
- Employee Recognition Program with Rewards (RAVE)
Good to have
- Experience with CIEM solutions and multi-cloud governance.
- Certifications: GIAC Cloud (GCSA/GPCS), CNCF CKA/CKS, vendor pro-level architect certs.
Working conditions
- Remote eligible; occasional after-hours support for incidents.
- On-call rotation for major incidents.
Location: Denver, CO (remote)
Compensation: USD 140,000 - 200,000 per yearly
Minimum experience: 4 years