Cybersecurity Engineer

Kirkhill Inc.

Brea (CA)

On-site

USD 110,000 - 160,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Kirkhill, Inc. is seeking a Cybersecurity Engineer to own the Azure cloud environment, enforce security posture, and lead hybrid cloud migrations. The role focuses on cloud and network infrastructure with strong emphasis on Entra ID, Defender, Intune, and automation.

Responsibilities include designing secure network architecture, implementing zero-trust concepts, and coordinating with the compliance team for classified environments. On-site with after-hours support may be required.

Qualifications

  • Experience with hybrid cloud migration and Azure networking.
  • Active Secret security clearance and U.S. citizenship.
  • Hands-on experience with Azure Entra ID, VMs, vNet, Defender, Intune.

Responsibilities

  • Own and mature the Azure cloud environment including governance and security posture.
  • Lead cloud migration and hybrid-cloud integration for on-prem workloads.
  • Implement cloud security configurations and monitoring tooling.
  • Manage Intune configurations and endpoint management.
  • Maintain patch/configuration management and automation tasks.

Skills

Azure networking
Hybrid cloud migration
Security mindset
Communication skills

Tools

PowerShell
Intune
Entra ID/AD

Job description

Cybersecurity Engineer- Cloud & Network Infrastructure
Position Summary

We are seeking a Systems Administrator with strong Azure and networking expertise.

Key Responsibilities
Cloud Infrastructure
  • Own and mature our Azure cloud environment: architecture, storage, identity (Entra ID), governance, cost management, and security posture
  • Lead cloud migration and hybrid-cloud integration efforts for on-prem workloads where appropriate
  • Implement and enforce cloud security configuration, CA policy, Defender security tooling, monitoring and logging
  • Intune configurations, package deployment, and endpoint management
  • Maintain monitoring, backup/DR, and patch/configuration management practices for cloud-hosted systems
  • Use AI, copilot, and PowerShell to automate repetitive administration and security tasks
Network Architecture
  • Design, document, and continuously improve network architecture, including segmentation between CUI-scoped enclaves and general business networks
  • Manage firewall, VLAN, and ACL configurations (including CUI subnet access control lists) and maintain accurate network documentation/diagrams
  • Lead network hardening initiatives and access control requirements (e.g., AC, SC control families)
  • Evaluate and implement zero-trust and micro-segmentation strategies
Classified Environment (training provided)
  • Maintain secure configurations, audits, and documentation for the classified workstations;
  • Maintain active Security+ certification
  • Maintain System Security Plans (SSPs), POA&Ms, and supporting documentation
  • Support periodic government inspections, self-inspections, vulnerability scans, and audit log reviews for the classified system
  • Serve as day-to-day POC for the classified environment, coordinating with the Facility Security Officer (FSO) and compliance team as needed
General Systems Administration
  • Administer Windows Server, Active Directory/Entra ID, endpoint management, and core virtual infrastructure services
  • Participate in security assessments, incident response testing, risk assessments, and 3rd party audits
  • Execute vulnerability scans, system patching, configuration deployments
  • Support configuration and software management controls (e.g., application allow-listing, nonessential functionality restrictions) in coordination with compliance staff
  • Participate in change management processes for IT systems affecting CUI/classified scope
  • Prioritize and resolve escalated technical issues and mentor junior IT staff, manage ticketing systems, and address chronic or persistent issues
  • Own and support all critical security incidents, interruptions/outages, and end-user issues with flexible evening/weekend work when required
  • Maintain system documentation, diagrams, project plans, asset inventory
Required Qualifications
  • Hands-on expertise in hybrid cloud migration, Microsoft Azure networking, cloud technologies, protocols, and authentication, and WAN network architecture
  • Experience administering Azure: identity (Entra ID), virtual machines, vnet, CA policy, Azure Foundry, Purview, Defender, Intune, etc.
  • Design and manage basic network architecture: routing, switching, segmentation, firewall/ACL configuration, VLANs, RADIUS, etc.
  • Excellent writing skills, conceptual thinking skills, and communication skills needed to learn/implement GenAI tools
  • Active Secret security clearance
  • U.S. citizenship required.
  • CompTIA Security+ (CE)
Preferred Qualifications
  • Cloud or Microsoft Azure Certifications
  • Experience with cybersecurity compliance frameworks similar to CMMC/NIST 800-171
  • Implementing simple AI solutions in Azure Foundry and/or Copilot
  • Strong PowerShell skills
Work Environment
  • On-site role
  • Some after-hours/on-call availability required to support maintenance windows and incident response

Kirkhill, Inc. is proud to be an equal opportunity employer, and all qualified applicants will receive consideration for employment without regard to race, color, age, religion, sex, sexual orientation, gender identity, national origin, disability status, protected veteran status, or any other characteristic protected by law. All successful candidates must submit to post offer pre-employment physical examination, drug/alcohol screen and background check as a condition of employment.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Systems Administrator
Systems Administrator

Kirkhill Inc. • Downtown Brea (CA)

On-site
USD 120,000 - 160,000
On-site role
Systems Administrator
Systems Administrator

Kirkhill, Inc. • Brea (CA)

On-site
USD 95,000 - 125,000
Systems Administrator
Systems Administrator

kirkhill • Brea (CA)

On-site
USD 90,000 - 140,000
Systems Administrator Secret clearance
Systems Administrator Secret clearance

StaffSource • Brea (CA)

On-site
USD 100,000 - 150,000
Cloud & IT Infrastructure Engineer
Cloud & IT Infrastructure Engineer

Executive 1 Holding Company, LLC • McLean (VA)

On-site
USD 95,000 - 135,000
Medical, Dental and Vision coverage
401(k) Matching
PTO
Azure Cloud & Network Security Engineer - On-site
Azure Cloud & Network Security Engineer - On-site

Kirkhill Inc. • Brea (CA)

On-site
USD 110,000 - 160,000
Cloud Security Engineer
Cloud Security Engineer

DANASTAR Professional Services, LLC • Washington

Hybrid
USD 140,000 - 200,000
Medical, dental, and vision insurance
Three weeks of paid time off (PTO)
Paid Federal holidays
+1
Azure Cloud & Network Engineer — On‑Site, Secret Clearance
Azure Cloud & Network Engineer — On‑Site, Secret Clearance

Kirkhill Inc. • Downtown Brea (CA)

On-site
USD 120,000 - 160,000
On-site role
Network Security Engineer
Network Security Engineer

Liquid Environmental Solutions Corporation • Irving (TX)

On-site
USD 110,000 - 160,000
Cloud Security Engineer
Cloud Security Engineer

Booz Allen Hamilton • Alexandria (VA)

On-site
USD 99,000 - 225,000
Health, life, and disability insurance
Retirement plans
Paid leave