We are a specialized technology staffing agency supporting professional and financial services companies. Why do we stand out in technology staffing? We listen and act as advisors for our candidates on how they can best add value, find interesting projects, and pave a path for career advancement. We advocate for the best pay, diversity in tech, and the best job fit for every candidate we place.
Our client, a global investment firm, is seeking a Senior Cloud Security Engineer to join their team in Los Angeles, CA!
This role is responsible for supporting and enhancing the firm's cybersecurity program through security operations, incident response, vulnerability management, endpoint security, identity and access management, data protection, and security engineering initiatives — with particular emphasis on securing our Microsoft Azure cloud environment and the data platforms (Snowflake, Databricks, MS Dynamics) that support our data engineering and analytics functions.
Responsibilities
- Serve as the security engineering point of contact for the firm's Azure cloud environment —reviewing architecture, integrations, and configurations for security posture (network segmentation, private endpoints, Key Vault, managed identities, RBAC, Defender for Cloud, Azure Policy).
- Partner with the data engineering team to secure the data platform stack — Snowflake, Databricks, and MS Dynamics — from an infrastructure and access-control perspective: authentication, network access, encryption at rest/in transit, key management, audit logging, and secrets management. (This role supports the security of these platforms; it does not own data engineering or pipeline development.)
- Review and validate security configurations for new Azure and data-platform integrations before go-live, in partnership with data engineering and application owners.
- Support identity governance and least-privilege access reviews across Azure resources and connected data platforms (service principals, managed identities, OAuth/API integrations).
- Contribute to cloud security monitoring and alerting using Microsoft Sentinel, Defender for Cloud, and Purview, and help extend existing security tooling (DLP, DGE) into cloud and data platform contexts.
- Support use of Infrastructure-as-Code (ARM templates, Bicep, or Terraform) to enforce consistent, reviewable security configurations across Azure resources.
Security Operations & Incident Response
- Monitor, investigate, and respond to security alerts across endpoint, email, identity, cloud, vulnerability management, data loss prevention (DLP), and managed detection platforms.
- Analyze suspected security incidents and determine appropriate containment, remediation, and recovery actions.
- Coordinate incident response activities with internal teams, managed service providers, and business stakeholders.
- Maintain accurate incident documentation, evidence collection, root cause analysis, and remediation records.
- Support ongoing improvements to incident response processes, automation, and user communications.
- Participate in on-call or after-hours incident response activities as needed.
Vulnerability & Patch Management
- Administer and continuously improve vulnerability management processes and reporting, including cloud resource and container/workload scanning.
- Identify, prioritize, and track remediation of security vulnerabilities and configuration issues across on-prem and Azure-hosted assets.
- Coordinate operating system and application patching activities across enterprise systems.
- Maintain accurate asset inventories — including cloud resources and data platform integrations — and ensure proper lifecycle management of technology assets.
Endpoint, Identity & Mobile Security
- Manage and support endpoint security technologies and investigations.
- Administer and enhance operations for Windows, iOS, and device management.
- Support Active Directory, Microsoft Entra ID, conditional access, security groups, and identity governance processes across on-prem and cloud.
- Ensure endpoint security controls align with operational and business requirements.
Email Security & Data Protection
- Support email security operations, including phishing investigations, message analysis, and user-facing communications.
- Review and respond to security events related to sensitive data handling and policy violations, including within cloud data platforms.
- Collaborate with IT, security, and data engineering teams to test, validate, and deploy security policy changes.
Security Assessments & Third-Party Risk
- Support security assessments, penetration tests, and due diligence reviews — including assessments of cloud and data platform vendors.
- Develop and maintain vendor information security review questionnaires and assessment procedures for high-risk vendors and service providers.
- Perform internal and vendor risk assessments to validate control effectiveness and recommend risk mitigation actions.
- Partner with third-party security vendors and managed service providers to establish monitoring, escalation plans, and workflows — and to investigate issues and implement corrective actions.
- Review security documentation, vendor responses, and assessment findings, escalating identified risks where appropriate.
- Support the firm's overall third-party/vendor risk management program and due-diligence process.
- Maintain a risk register for identification, evaluation, and monitoring of risk findings, reported to the Executive Committee.
- Develop dashboards, reports, and alerts providing real‑time visibility into the state of security controls and policies.
- Establish data classification and information protection policies and controls across email, chat, and sensitive file repositories.
- Partner with other departments to establish consistent review and approval workflows for exceptions to security policies and controls.
- Contribute to the continuous improvement of security program goals, objectives, policies, standards, and procedures.
- Support internal and external audit/regulatory processes relevant to applicable compliance frameworks (e.g., CIS, SOC 2, PCI, NIST, CCPA, GLBA).
- Participate in business impact analysis, business continuity, and disaster recovery planning and testing.
- Work with various business units to ensure security controls are adequate, appropriate, and effective.
- Stay current on developing regulatory requirements and evolving IT/information security trends.
Required Qualifications
- 7+ years of experience in information security, security operations, systems engineering, systems administration, or a related field.
- Substantial hands‑on experience securing Microsoft Azure environments — including identity (Entra ID, conditional access, managed identities), network security (VNets, NSGs, private endpoints), Key Vault, Defender for Cloud, and Azure Policy — from an integration and architecture perspective, not just administration.
- Experience securing or supporting cloud data platforms such as Snowflake, Databricks, and/or MS Dynamics from an infrastructure/security standpoint (access control, network security, encryption, audit logging, secrets management) direct data engineering experience is not required, but the ability to work fluently alongside a data engineering team is.
- Hands‑on experience investigating endpoint, email, identity, cloud, or data security events.
- Experience with vulnerability management, patch management, asset inventory, and remediation tracking.
- Strong knowledge of Microsoft 365, Active Directory, Microsoft Entra ID, Windows administration, and PowerShell.
- Familiarity with common security and compliance frameworks (CIS, SOC 2, PCI, NIST, CCPA, GLBA) and with business impact analysis, BC/DR planning, and DR testing.
- Experience administering endpoint management or mobile device management (MDM) platforms.
- Experience working with managed security providers, technology vendors, or outsourced IT partners.
- Strong analytical, troubleshooting, and problem‑solving skills.
- Excellent written and verbal communication skills with the ability to interact effectively across technical and business teams, including engineering.
- Ability to manage multiple priorities in a fast‑paced environment while maintaining attention to detail.
Preferred Qualifications
- Experience with Microsoft Purview, Microsoft Sentinel, and the broader Defender suite (Defender for Cloud, Defender for Cloud Apps).
- Experience with Infrastructure-as-Code (ARM/Bicep, Terraform) for enforcing security configuration at scale.
- Experience with technologies such as CrowdStrike Falcon, eSentire, Proofpoint, Fortra Digital Guardian.
- Experience supporting financial services, investment management, or other highly regulated environments.
- Experience coordinating penetration tests, security assessments, and vendor risk reviews —particularly for cloud/SaaS and data platform vendors.
- Familiarity with hybrid infrastructure and modern endpoint management solutions.
- Knowledge of incident response planning, business continuity, disaster recovery, and audit support processes.
- Professional certifications such as CISSP, CISA, CISM, Security+, GIAC, Azure Security Engineer Associate (AZ-500), or equivalent experience are preferred but not required.