Azure Cloud Security Expert

Hudson Data LLC

New York (NY)

On-site

USD 120,000 - 180,000

Full time

10 days ago
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Hudson Data LLC is seeking a hands-on Cloud Security & ESO Engineer to design, implement, and operate security controls across cloud platforms and enterprise security tools. The role integrates security engineering with ESO platform administration and continuous improvement.

You will work with Infrastructure, Architecture, Dev, Identity, Risk, and Regulators to protect customer information, ensure resilient services, and align with bank policies and regulatory obligations.

Qualifications

  • Strong hands-on knowledge of Azure security, Microsoft Entra ID, networking, logging and monitoring, encryption, vulnerability management, security-tool administration, platform integrations, and operational troubleshooting.
  • Hands-on ability to implement conditional access, multifactor authentication, privileged access management, service principles, workload and managed identities, and role-based access control.
  • Experience with Microsoft Defender for Cloud, Microsoft Sentinel, Azure Policy, Key Vault, cloud security posture management, SIEM use cases, alert tuning, and telemetry integration.
  • Ability to automate technical and operational tasks using PowerShell, Python, Azure CLI, Terraform, Bicep, APIs, or similar tools.
  • Working knowledge of NIST Cybersecurity Framework, NIST SP 800-53, CIS Benchmarks, FFIEC guidance, GLBA Safeguards, NYDFS Part 500, and applicable privacy requirements.
  • Knowledge of change management, incident response, problem management, vendor escalation, evidence preservation, secure architecture, and technology lifecycle practices in a regulated environment.
  • Ability to translate technical findings into clear risk statements, remediation plans, procedures, and concise communications for engineers, management, auditors, and regulators.

Responsibilities

  • Engineer and maintain secure cloud architectures, landing-zone controls, preventive guardrails, identity-first controls across Microsoft Azure and other approved clouds.
  • Administer and engineer ESO platforms supporting email, endpoint and mobile, secure web access, data protection, privileged access, vulnerability management, and monitoring; ensure operational health.
  • Integrate cloud, identity, application, network, and security-tool telemetry into the SIEM and detection program; develop use cases, tune alerts, reduce false positives.
  • Automate ESO and cloud-security tasks using PowerShell, Python, Azure CLI, Terraform, Bicep, APIs, or similar technologies.
  • Perform architecture reviews, threat modeling, risk assessments, and control validation for new systems, changes, vendors, and data flows.
  • Partner with technology owners to remediate vulnerabilities, excessive access, control gaps, and misconfigurations; track risk and validate compensating controls.
  • Support incident response, security-platform upgrades and migrations, change management, data protection, audit evidence, and on-call support.

Skills

Azure security
Microsoft Entra ID
Networking
Logging & monitoring
Encryption
Vulnerability management
Security-tool administration
Platform integrations
Operational troubleshooting
NIST CSF
NIST SP 800-53
CIS Benchmarks

Tools

Terraform
Bicep
Azure CLI
PowerShell
Python

Job description

|-------------------------------------------|
| Job Title: Cloud Security & ESO Engineer |
| Department: Information Security |
| Division: Technology |

POSITION SUMMARY

The Cloud Security & Enterprise Security Operations (ESO) Engineer is a hands-on member of Provident Bank's Information Security team responsible for designing, implementing, integrating, and operating security controls across cloud platforms and the enterprise security technology stack. The role combines cloud security engineering with day-to-day ESO engineering, including security-tool administration, platform health, telemetry integration, control validation, automation, incident support, and lifecycle management. The engineer partners with Infrastructure, Architecture, Application Development, Identity, Risk Management, Internal Audit, managed security providers, and third parties to protect customer information, sustain resilient banking services, and align security capabilities with the Bank's risk appetite, policies, and regulatory obligations.

KEY RESPONSIBILITIES
  • 20% - Engineer and maintain secure cloud architectures, landing-zone controls, preventive guardrails, identity-first controls, and cloud-native security capabilities across Microsoft Azure and other approved cloud or SaaS platforms.
  • 20% - Administer and engineer ESO platforms supporting email, endpoint and mobile, secure web access, data protection, privileged access, vulnerability management, security monitoring, and related protective controls; monitor operational health and readiness.
  • 15% - Integrate cloud, identity, application, network, and security-tool telemetry into the SIEM and detection program; develop use cases, tune alerts, reduce false positives, and validate end-to-to-end visibility.
  • 15% - Engineer secure integrations and automate repeatable ESO and cloud-security tasks using PowerShell, Python, Azure CLI, Terraform, Bicep, APIs, or similar technologies.
  • 10% - Perform architecture reviews, threat modeling, risk assessments, and control validation for new systems, major changes, vendors, integrations, and data flows before production use.
  • 10% - Partner with technology owners to remediate vulnerabilities, unsupported components, excessive access, control gaps, and misconfigurations; track risk exceptions and validate compensating controls.
  • 10% - Support incident response, security-platform upgrades and migrations, formal change management, data protection, audit evidence, metrics, runbooks, operational handoffs, and on-call or after-hours support as required.
SKILLS AND TRAINING REQUIRED
  • Strong hands-on knowledge of Azure security, Microsoft Entra ID, networking, logging and monitoring, encryption, vulnerability management, security-tool administration, platform integrations, and operational troubleshooting.
  • Hands-on ability to implement conditional access, multifactor authentication, privileged access management, service principles, workload and managed identities, and role-based access control.
  • Experience with Microsoft Defender for Cloud, Microsoft Sentinel, Azure Policy, Key Vault, cloud security posture management, SIEM use cases, alert tuning, and telemetry integration.
  • Ability to automate technical and operational tasks using PowerShell, Python, Azure CLI, Terraform, Bicep, APIs, or similar tools.
  • Working knowledge of NIST Cybersecurity Framework, NIST SP 800-53, CIS Benchmarks, FFIEC guidance, GLBA Safeguards, NYDFS Part 500, and applicable privacy requirements.
  • Knowledge of change management, incident response, problem management, vendor escalation, evidence preservation, secure architecture, and technology lifecycle practices in a regulated environment.
  • Ability to translate technical findings into clear risk statements, remediation plans, procedures, and concise communications for engineers, management, auditors, and regulators.
WORK EXPERIENCE
  • Five or more years of information security or infrastructure engineering experience, including hands-on responsibility for production cloud environments or enterprise security platforms.
  • Experience managing security controls or platforms across at least two areas such as SIEM, email security, endpoint or mobile security, secure web access, data loss prevention, privileged access management, cloud security posture management, or vulnerability management.
  • Experience supporting operational troubleshooting, platform integrations, production changes, incident response, and technology lifecycle activities in a regulated environment.
  • Banking, financial services, or other highly regulated industry experience is preferred.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Azure Security Engineer - Entra/Intune/Defender Permanent Job Hybrid 3 days a week pn site in Sacramento 2 days a week remote
Azure Security Engineer - Entra/Intune/Defender Permanent Job Hybrid 3 days a week pn site in Sacramento 2 days a week remote

Zeektek • Sacramento (CA)

Hybrid
USD 150,000 - 190,000
Cloud Security Engineer
Cloud Security Engineer

Greenberg Traurig, LLP • Charlotte (NC)

Hybrid
USD 100,000 - 130,000
Azure Application Security Engineer
Azure Application Security Engineer

Tech Talent Link, Inc • Portland (OR)

On-site
USD 100,000 - 130,000
Information Security Officer
Information Security Officer

City First Bank • Inglewood (CA)

On-site
USD 100,000 - 140,000
Security Engineer
Security Engineer

Compunnel, Inc. • Chicago (IL), Northern (KY)

Hybrid
USD 120,000 - 160,000
Cyber Security Engineer
Cyber Security Engineer

FutureRecruit.net • New York (NY)

Hybrid
USD 90,000 - 130,000
Azure Cloud Security & ESO Engineer
Azure Cloud Security & ESO Engineer

Hudson Data LLC • New York (NY)

On-site
USD 120,000 - 180,000
Security Engineer
Security Engineer

Gravity IT Resources • Salt Lake City (UT)

On-site
USD 120,000 - 160,000
Senior Cloud Security Engineer
Senior Cloud Security Engineer

Compunnel, Inc. • Pittsburgh

Remote
USD 100,000 - 130,000
Cloud Security Engineer
Cloud Security Engineer

Prestige Staffing • Dallas (TX)

Hybrid
USD 110,000 - 140,000
Career growth in a stable organization
Collaborative and innovative team atmosphere
Comprehensive benefits package