Role & responsibilities
Job Description
Position: Cloud Security Engineer Department: IT Security / Cloud Governance
Role Overview
We are seeking a highly skilled Cloud Security Engineer (DevSecOps) responsible for strengthening the organization's cloud, network, and enterprise security posture across hybrid environments.
The role will focus on cloud security architecture, identity governance, network security controls, and enterprise security operations across Microsoft Azure, Amazon Web Services, Microsoft 365, and on-premises infrastructure.
The ideal candidate will have strong experience in security platform administration, hybrid infrastructure security, and enterprise security governance, with the ability to support ongoing security operations, risk mitigation, and cloud security optimization initiatives.
Key Responsibilities
Cloud Security Architecture & Governance
- Design, implement, and maintain cloud security frameworks across Microsoft Azure, AWS, and Microsoft 365 environments.
- Develop and maintain cloud security architecture and governance standards.
- Ensure secure deployment of cloud infrastructure, services, and applications.
- Prepare and maintain security architecture diagrams, policies, and technical documentation.
Security Platform Administration
- Perform end-to-end administration of the ManageEngine security suite.
- Manage and administer enterprise security platforms including: IAM (Identity & Access Management)
- PAM (Privileged Access Management)
- SIEM monitoring platforms
- Endpoint Protection Platform (EPP)
- Email Security / Extended Detection & Response (XDR)
Email Security & XDR
- Administer and manage email security platforms (e.g., Microsoft Defender for Office 365, Mimecast, Proofpoint, or equivalent), including anti-phishing, anti-malware, and safe attachments/links policies.
- Configure and maintain email authentication protocols (SPF, DKIM, DMARC) to prevent spoofing, phishing, and business email compromise (BEC).
- Deploy, tune, and manage XDR platforms to correlate threat signals across endpoint, identity, email, and cloud workloads for unified detection.
- Investigate and respond to advanced/multi-stage threats using XDR-driven analytics, correlation rules, and automated response playbooks.
- Integrate email security and XDR telemetry with SIEM for centralized visibility and reporting.
Identity & Data Security
- Implement and manage enterprise identity security solutions including: Single Sign-On (SSO)
- Multi-Factor Authentication (MFA)
- Conditional Access policies
- Manage and enforce Data Loss Prevention (DLP) policies across enterprise systems.
- Administer and secure Mobile Device Management (MDM) platforms.
- Implement identity governance controls across hybrid environments.
Cloud & Network Security
- Design and implement secure cloud network architectures across Azure and AWS environments.
- Configure and manage cloud network security controls including: Azure Network Security Groups
- Azure Firewall
- AWS Security Groups
- AWS Web Application Firewall
- Implement Zero Trust security architecture principles.
- Secure hybrid connectivity between on-premises environments and cloud infrastructure.
- Monitor and analyze network security events and traffic patterns.
On-Premises Infrastructure Security
- Design and manage secure on-premises network security architecture.
- Configure and maintain enterprise firewalls and network security policies.
- Support and secure core switching infrastructure and network segmentation.
- Implement network access control policies and secure routing architectures.
- Configure and maintain site-to-site VPNs and secure connectivity between data center and cloud environments.
- Monitor firewall logs, network security alerts, and intrusion detection systems.
Security Operations & Incident Response
- Monitor and respond to security alerts and incidents across cloud and enterprise environments.
- Support vulnerability management, patch management, and asset security monitoring.
- Conduct security investigations and coordinate remediation activities.
Security Optimization & Continuous Improvement
- Identify opportunities for security automation and operational improvements.
- Strengthen security governance frameworks and operational resilience.
- Work closely with infrastructure and DevOps teams to ensure secure system deployments.
Required Skills & Experience
Cloud Security Platforms
Strong hands-on experience with:
- Microsoft 365 Security & Compliance
- Microsoft Azure security services
- AWS security controls
Security Platform Administration
Proven experience with:
- ManageEngine security solutions
- SIEM platforms
- Endpoint Protection Platforms (EPP)
Identity & Access Security
Expertise in:
- IAM and PAM solutions
- Single Sign-On (SSO)
- Multi-Factor Authentication (MFA)
- Conditional Access
- Identity governance frameworks
Network & Infrastructure Security
Strong knowledge of:
- Enterprise firewall administration
- Core switching security architecture
- Network segmentation and secure routing
- VPN technologies and hybrid connectivity
- Zero Trust network architecture
Cloud Network Security
Experience securing cloud networking using:
- Azure Network Security Groups
- Azure Firewall
- AWS Security Groups
- AWS WAF
- Secure hybrid cloud networking architectures
Endpoint & Data Protection
Knowledge of:
- Endpoint security platforms
- MDM solutions
- Data Loss Prevention (DLP)
- Patch management and asset security monitoring
Email Security & XDR
Hands-on experience with:
- Email security platforms (Barracuda, Checkpoint, Microsoft Defender, Mimecast, Proofpoint, or equivalent)
- Email authentication protocols (SPF, DKIM, DMARC)
- Extended Detection and Response (XDR) platforms (e.g., Microsoft Defender XDR, CrowdStrike Falcon, SentinelOne Singularity, or equivalent)
- Threat correlation, alert triage, and automated response/playbook design
Documentation & Architecture
Ability to create technical security architecture diagrams and documentation.
Experience developing security policies and governance frameworks.
Preferred Certifications
Security certifications such as:
- CISSP
- Microsoft Security Certifications (SC-200 / SC-300)
- AWS Security Specialty