EngineerJobs.io
← Back to all jobs

Job Description

ArdentMills is hiring a Cloud Security Engineer to build and operate security controls in Microsoft Azure, with room to expand across other major cloud platforms.

Responsibilities

  • Design and deliver security landing zones, including identity and network controls (VPC/VNet, security groups/NSGs, private endpoints).
  • Configure and operationalize cloud-native protection services such as Microsoft Defender for Cloud, Microsoft Sentinel, and Defender XDR.
  • Implement posture management (CSPM) and workload protection (CWPP) using policy-as-code and automated remediation.
  • Set up key management and enforce encryption at rest and in transit, including certificate governance via KMS/Key Vault/Cloud KMS.
  • Establish logging, telemetry, and alerting using Azure Monitor and integrate with SIEM/XDR; collaborate with IT and Security to validate detection coverage and maturity from cloud-native sources.
  • Harden security posture for serverless, containers, and managed services including Functions, Logic Apps, Container Apps, AKS, and ACI using baseline controls.
  • Conduct threat modeling and security reviews for cloud architectures and application designs.
  • Work with platform and product teams to deliver IaC guardrails, image baselines, and patch/vulnerability workflows.
  • Serve as an escalation point for cloud incidents: perform triage, containment, and post-incident improvements; design automation to optimize cloud detection and response.
  • Use automation and AI-assisted capabilities where applicable to improve detection and response effectiveness.
  • Document standards and runbooks; run enablement sessions with dev and ops teams.
  • Partner on cloud security strategy and program maturity development.
  • Support cloud migration programs and perform control design reviews as needed.

Requirements

  • Bachelor’s in computer science/engineering or equivalent experience.
  • 4–7 years in cloud security engineering across at least one major CSP.
  • Strong knowledge of IAM, networking, encryption, and cloud-native security tooling.
  • Experience securing hybrid environments spanning on-premises and Azure cloud.
  • Scripting/automation experience with Python/Bash/PowerShell and IaC tooling such as Terraform/Bicep/ARM.
  • Certifications: CCSP; AWS Certified Security – Specialty; Azure Security Engineer Associate (AZ-500); or Google Professional Cloud Security Engineer.

Technologies

  • Microsoft Azure, VPC/VNet, security groups/NSGs, private endpoints
  • Microsoft Defender for Cloud, Microsoft Sentinel, Defender XDR
  • CSPM, CWPP, policy-as-code
  • KMS, Key Vault, Cloud KMS; encryption at rest/in transit; certificate governance
  • Azure Monitor, SIEM, XDR
  • Functions, Logic Apps, Container Apps, AKS, ACI
  • IaC, image baselines, patch/vulnerability workflows
  • Automation, AI-assisted capabilities
  • Python, Bash, PowerShell; Terraform, Bicep, ARM
  • CCSP; AWS Certified Security – Specialty; Azure Security Engineer Associate (AZ-500); Google Professional Cloud Security Engineer

Benefits

  • Medical, Dental and Vision Coverage
  • Health and Dependent Savings Accounts
  • Life and Disability Programs
  • Voluntary Benefit Programs
  • Company Sponsored Wellness Programs
  • Retirement Savings with Company Match
  • Team Member and Family Assistance Program (EAP)
  • Paid Time Off and Paid Holidays
  • Employee Recognition Program with Rewards (RAVE)

Good to have

  • Experience with CIEM solutions and multi-cloud governance.
  • Certifications: GIAC Cloud (GCSA/GPCS), CNCF CKA/CKS, vendor pro-level architect certs.

Working conditions

  • Remote eligible; occasional after-hours support for incidents.
  • On-call rotation for major incidents.

Location: Denver, CO (remote)

Compensation: USD 140,000 - 200,000 per yearly

Minimum experience: 4 years

Similar Jobs