Work Arrangement: Hybrid – 2 days onsite / 3 days remote, with the ability to transition to 5 days onsite if required by the client.
Senior Cloud Security Engineer
Work Arrangement: Hybrid – 2 days onsite / 3 days remote, with the ability to transition to 5 days onsite if required by the client.
About EastBay Systems
EastBay Systems is a cybersecurity and IT consulting firm supporting Federal civilian agencies. Our work spans Security Engineering, SOC operations, Cloud Security, GRC, Cybersecurity Program Management, and Continuous Monitoring.
Position Summary
EastBay Systems is seeking a Senior Cloud Security Engineer to join an established cybersecurity engineering team supporting a complex Federal hybrid-cloud environment.
This is a hands-on role for an experienced engineer who can quickly contribute across cloud security, networking, logging, security tools, and automation. The engineer will support Azure, AWS, on-premises, and hybrid environments; troubleshoot complex technical issues; improve existing security configurations and integrations; and participate in architecture and SOC technology assessments.
The ideal candidate is comfortable working independently on senior-level technical assignments while collaborating with Security Engineering, SOC, Cloud, DevSecOps, GRC, and Federal stakeholders.
Key Responsibilities Cloud & Network Security
- Support Azure, AWS, on-premises, and hybrid security environments.
- Configure and troubleshoot Azure VNets, subnets, route tables, NSGs, Azure Firewall, load balancers, Application Gateway, VPNs, and related services.
- Apply strong knowledge of routing, DNS, TCP/IP, segmentation, traffic flows, and firewall controls.
- Support firewall rule reviews, access-control changes, network hardening, and secure cloud configurations.
- Participate in cloud and network security architecture reviews and recommend practical improvements.
Sentinel, Logging & Monitoring
- Configure, support, and optimize Microsoft Sentinel.
- Develop and maintain analytics rules, detections, dashboards/workbooks, alerts, and automation.
- Onboard and troubleshoot log sources using Syslog, CEF, agents, APIs, native connectors, and custom ingestion methods.
- Support centralized logging across cloud, network, endpoint, server, application, and security platforms.
- Configure and troubleshoot RHEL/Linux Syslog or rsyslog forwarding to Sentinel.
- Identify logging and monitoring gaps that affect detection, incident response, and Continuous Monitoring.
Security Tools & Automation
- Support ExtraHop or comparable NDR technology.
- Administer and troubleshoot Cisco WSA.
- Support CrowdStrike, Microsoft Defender XDR, Forescout, and related security technologies.
- Integrate security tools with Sentinel and enterprise monitoring platforms.
- Develop and support Azure Logic Apps, PowerShell, REST APIs, JSON, and scripts for security automation and integration.
- Participate in reviews of SOC tool configurations, integrations, coverage, and effectiveness.
Identity & Federal Security
- Support Microsoft Entra ID, Conditional Access, PIM, RBAC, managed identities, and cloud IAM controls.
- Apply Zero Trust and least-privilege principles.
- Support FISMA, NIST RMF, NIST SP 800-53, FedRAMP, and Continuous Monitoring activities.
- Assist with technical control implementation, assessments, audits, and POA&M remediation.
- Work with GRC and ISSO teams to translate compliance requirements into technical solutions.
Required Qualifications
- Bachelor’s degree in Computer Science, Computer Engineering, IT, Cybersecurity, or a related technical field.
- 8+ years of cybersecurity, cloud security, network security, or security engineering experience.
- 5+ years of hands-on Azure and/or AWS security experience.
- Strong Azure networking knowledge, including VNets, subnets, route tables, NSGs, firewalls, and hybrid connectivity.
- Strong understanding of routing, DNS, TCP/IP, segmentation, traffic flows, and firewall technologies.
- Hands-on Microsoft Sentinel experience, including connectors, analytics rules, detections, automation, and log ingestion.
- Experience with Linux/RHEL Syslog or rsyslog.
- Experience with Azure Logic Apps, PowerShell, REST APIs, JSON, and scripting.
- Experience with Microsoft Defender XDR, CrowdStrike, ExtraHop or comparable technologies, and Cisco WSA or similar web security platforms.
- Experience with Microsoft Entra ID, Conditional Access, PIM, IAM, and RBAC.
- Strong troubleshooting and analytical skills.
- Experience supporting Federal cybersecurity requirements such as FISMA, RMF, NIST SP 800-53, FedRAMP, or ISCM.
- Ability to work independently on complex technical issues and make immediate contributions with minimal ramp-up.
- Ability and willingness to work onsite 2 days per week and transition to 5 days onsite if required by the client.
Preferred Qualifications
- CISSP, CCSP, AZ-500, SC-100, AWS Security Specialty, or similar certifications.
- Experience with Forescout and Microsoft Defender for Cloud.
- Experience supporting FedRAMP Moderate or High environments.
- Experience participating in cloud, network, SOC, or enterprise security architecture reviews.
- Experience evaluating security-tool effectiveness, integration, and monitoring coverage.
Benefits
- Medical, dental, and vision insurance
- Three weeks of paid time off (PTO)
- Paid Federal holidays
- 401(k) retirement plan with employer contribution
- Additional employer-sponsored benefits in accordance with company policy
Equal Employment Opportunity
EastBay Systems is an Equal Opportunity Employer. Employment decisions are based on qualifications, merit, business needs, and job-related requirements.
EastBay Systems does not discriminate on the basis of race, color, ethnicity, national origin, religion, sex, pregnancy, sexual orientation, gender identity or expression, age, disability, genetic information, protected veteran status, marital status, or any other characteristic protected by applicable Federal, state, or local law.
Reasonable accommodations will be provided to qualified individuals in accordance with applicable law.