Get AI-powered advice on this job and more exclusive features.
Position Overview: We are seeking a seasoned Cloud Security Engineer with a strong focus on securing Microsoft Azure environments through automation, vulnerability management, and advanced detection capabilities. The ideal candidate will bring hands-on experience with Microsoft Defender solutions, Qualys, and Infrastructure as Code (IaC) tools such as Terraform and ARM templates. While a foundational understanding of Zscaler (ZPA/ZIA) remains valuable, the role emphasizes secure automation, scalable policy enforcement, and deep analytics using tools like KQL and Qualys Query Language (QL).
Key Responsibilities:
- Design, deploy, and manage Azure security configurations using Defender for Cloud, Defender for Endpoint, Azure Policy, and Sentinel.
- Perform comprehensive vulnerability and risk assessments using Qualys, leveraging Qualys Query Language (QL) to identify gaps and drive remediation efforts.
- Implement security controls and workflows through automated pipelines using Infrastructure as Code (Terraform, ARM templates) and scripting languages.
- Collaborate with development and DevOps teams to embed security into CI/CD workflows and cloud-native applications.
- Develop automation scripts and tooling using PowerShell, Python, and .NET to streamline security operations, reporting, and compliance tracking.
- Utilize Kusto Query Language (KQL) to analyze security event data from Azure Monitor, Log Analytics, and Sentinel for threat detection and incident investigation.
- Support Zscaler ZPA and ZIA deployments in hybrid environments (basic deployment, policy tuning, integration).
- Maintain cloud infrastructure security baselines and ensure compliance with industry frameworks such as NIST, ISO 27001, PCI-DSS, and HIPAA.
- Participate in disaster recovery planning and execution, documenting DR processes and testing security readiness.
- Author and maintain technical documentation, SOPs, and security architecture diagrams.
Technical Skills & Qualifications:
- 5+ years of experience in cloud security and engineering, with a strong emphasis on Microsoft Azure.
- Expert-level experience with Microsoft Defender for Endpoint, Defender for Cloud, Sentinel, and Azure-native security controls.
- Advanced proficiency with Infrastructure as Code tools—Terraform (standalone and cloud-based) (required), ARM templates (preferred), Bicep (a plus).
- Experience with GitHub, including GitHub Actions and GitHub Pipelines, for secure and automated deployment workflows.
- Strong scripting and automation skills using PowerShell, Python, and .NET (C# or equivalent) in security and DevOps contexts.
- Demonstrated ability to operate beyond GUI-based administration; must be comfortable with CLI tools, scripting, and automation to avoid reliance on manual, click-driven operations.
- Proficient in using KQL for deep threat hunting, monitoring, and reporting in Azure environments.
- Experience with Qualys VMDR platform, including asset tagging, policy definition, and reporting using Qualys QL.
- Knowledge of cloud networking, firewalls, VPNs, NSGs, and security architecture in Azure.
- Understanding of Zero Trust principles, cloud identity and access management, and encryption strategies.
- Familiarity with regulatory compliance frameworks and how they apply to cloud security operations.
Preferred Skills:
- Zscaler ZPA/ZIA deployment experience (not primary but beneficial).
- Microsoft security certifications (e.g., SC-100, AZ-500).
- Familiarity with CASB, SWG, and API security best practices.
- Experience integrating IaC security validation tools (e.g., Checkov, tfsec) into CI/CD pipelines.
- Exposure to Kubernetes security and container hardening strategies in cloud environments.
Seniority level
Seniority level
Mid-Senior level
Employment type
Job function
Job function
Information TechnologyIndustries
IT Services and IT Consulting
Referrals increase your chances of interviewing at Qumodity LLC by 2x
Sign in to set job alerts for “Security Engineer” roles.
United States $90,000.00-$110,000.00 2 months ago
Security Detection Engineer, Insider Trust
United States $147,000.00-$208,000.00 1 week ago
Security Engineer, Vulnerability Response
Columbus, OH $95,000.00-$128,000.00 1 week ago
United States $160,000.00-$190,000.00 7 hours ago
Washington, DC $110,000.00-$165,000.00 5 months ago
Security Engineer (SIEM/SOAR/SOC Optimization) - Mid-Atlantic region (Remote in NC, VA, WV, MD, DC, DE, NJ, or PA)
Cybersecurity Principal Engineer – IAM / Data Science (Remote)
United States $163,100.00-$244,700.00 3 weeks ago
Senior Security Engineer - Enterprise Security
We’re unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.