Senior Cloud Security Engineer

Maestro Technologies, Inc.

Santa Monica (CA)

Hybrid

USD 150,000 - 210,000

Full time

11 hours ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Maestro Technologies, Inc. seeks a Security Engineer to own Azure security engineering, enforce least-privilege access, and secure Snowflake/Databricks/Dynamics within cloud and data-platform contexts.

You will partner with data engineering and application teams to review configurations, implement governance, and monitor security postures. The role requires hands-on Azure security experience, knowledge of identity governance, and incident response readiness, with on-site presence in Santa Monica

Qualifications

  • 7+ years of information security experience or related fields.
  • Hands-on Azure security architecture and integration experience.
  • Experience securing cloud data platforms and ecosystems.

Responsibilities

  • Serve as the security engineering point of contact for Azure cloud environment.
  • Secure data platform stack (Snowflake, Databricks, Dynamics) from infrastructure/security perspective.
  • Review security configurations for new Azure/data-platform integrations before go-live.
  • Support identity governance and least-privilege access reviews.
  • Contribute to security monitoring using Sentinel/Defender/Purview and extend tooling.
  • Support IaC (ARM/Bicep/Terraform) to enforce security configurations.

Skills

Azure security
Entra ID
Conditional access
Private endpoints
Key Vault
Defender for Cloud
Azure Policy
VNet security
NSGs
Identity governance
Audit logging
Secrets management
Snowflake security
Databricks security
Microsoft Dynamics security
Endpoint investigations
Vulnerability management
Patch management
Asset inventory
Windows administration
PowerShell
MDM
Security frameworks
Incident response
On-site presence

Job description

  • Serve as the security engineering point of contact for the Azure cloud environment — reviewing architecture, integrations, and configurations for security posture (network segmentation, private endpoints, Key Vault, managed identities, RBAC, Defender for Cloud, Azure Policy).
  • Partner with the data engineering team to secure the data platform stack — Snowflake, Databricks, and Microsoft Dynamics — from an infrastructure and access-control perspective: authentication, network access, encryption at rest and in transit, key management, audit logging, and secrets management. (This role supports the security of these platforms; it does not own data engineering or pipeline development.)
  • Review and validate security configurations for new Azure and data-platform integrations before go-live, in partnership with data engineering and application owners.
  • Support identity governance and least-privilege access reviews across Azure resources and connected data platforms (service principals, managed identities, OAuth/API integrations).
  • Contribute to cloud security monitoring and alerting using Microsoft Sentinel, Defender for Cloud, and Purview, and help extend existing security tooling (DLP, DGE) into cloud and data-platform contexts.
  • Support use of Infrastructure-as-Code (ARM templates, Bicep, or Terraform) to enforce consistent, reviewable security configurations across Azure resources.
Security Operations & Incident Response
  • Monitor, investigate, and respond to security alerts across endpoint, email, identity, cloud, vulnerability management, data loss prevention (DLP), and managed detection platforms.
  • Analyze suspected security incidents and determine appropriate containment, remediation, and recovery actions.
  • Coordinate incident response activities with internal teams, managed service providers, and business stakeholders.
  • Maintain accurate incident documentation, evidence collection, root cause analysis, and remediation records.
  • Support ongoing improvements to incident response processes, automation, and user communications.
  • Participate in on-call or after-hours incident response activities as needed.
Vulnerability & Patch Management
  • Administer and continuously improve vulnerability management processes and reporting, including cloud resource and container/workload scanning.
  • Identify, prioritize, and track remediation of security vulnerabilities and configuration issues across on-premises and Azure-hosted assets.
  • Coordinate operating system and application patching activities across enterprise systems.
  • Maintain accurate asset inventories — including cloud resources and data platform integrations — and ensure proper lifecycle management of technology assets.
Endpoint, Identity & Mobile Security
  • Manage and support endpoint security technologies and investigations.
  • Administer and enhance operations for Windows, iOS, and device management.
  • Support Active Directory, Microsoft Entra ID, conditional access, security groups, and identity governance processes across on-premises and cloud.
  • Ensure endpoint security controls align with operational and business requirements.
Email Security & Data Protection
  • Support email security operations, including phishing investigations, message analysis, and user-facing communications.
  • Review and respond to security events related to sensitive data handling and policy violations, including within cloud data platforms.
  • Collaborate with IT, security, and data engineering teams to test, validate, and deploy security policy changes.
Security Assessments & Third-Party Risk

Support security assessments, penetration tests, and due diligence reviews — including assessments of cloud and data platform vendors.

  • Develop and maintain vendor information security review questionnaires and assessment procedures for high-risk vendors and service providers.
  • Perform internal and vendor risk assessments to validate control effectiveness and recommend risk mitigation actions.
  • Partner with third-party security vendors and managed service providers to establish monitoring, escalation plans, and workflows — and to investigate issues and implement corrective actions.
  • Review security documentation, vendor responses, and assessment findings, escalating identified risks where appropriate.
  • Support the overall third-party/vendor risk management program and due-diligence process.
Governance, Risk & Compliance
  • Maintain a risk register for identification, evaluation, and monitoring of risk findings, reported to executive stakeholders.
  • Develop dashboards, reports, and alerts providing real-time visibility into the state of security controls and policies.
  • Establish data classification and information protection policies and controls across email, chat, and sensitive file repositories.
  • Partner with other departments to establish consistent review and approval workflows for exceptions to security policies and controls.
  • Contribute to the continuous improvement of security program goals, objectives, policies, standards, and procedures.
  • Support internal and external audit and regulatory processes relevant to applicable compliance frameworks (e.g., CIS, SOC 2, PCI, NIST, CCPA, GLBA).
  • Participate in business impact analysis, business continuity, and disaster recovery planning and testing.
  • Work with business units to ensure security controls are adequate, appropriate, and effective.
  • Stay current on developing regulatory requirements and evolving IT and information security trends.
Required Qualifications
  • 7+ years of experience in information security, security operations, systems engineering, systems administration, or a related field.
  • Substantial hands-on experience securing Microsoft Azure environments — including identity (Entra ID, conditional access, managed identities), network security (VNets, NSGs, private endpoints), Key Vault, Defender for Cloud, and Azure Policy — from an integration and architecture perspective, not just administration.
  • Experience securing or supporting cloud data platforms such as Snowflake, Databricks, and/or Microsoft Dynamics from an infrastructure and security standpoint (access control, network security, encryption, audit logging, secrets management). Direct data engineering experience is not required, but the ability to work fluently alongside a data engineering team is.
  • Hands-on experience investigating endpoint, email, identity, cloud, or data security events.
  • Experience with vulnerability management, patch management, asset inventory, and remediation tracking.
  • Strong knowledge of Microsoft 365, Active Directory, Microsoft Entra ID, Windows administration, and PowerShell.
  • Familiarity with common security and compliance frameworks (CIS, SOC 2, PCI, NIST, CCPA, GLBA) and with business impact analysis, BC/DR planning, and DR testing.
  • Experience administering endpoint management or mobile device management (MDM) platforms.
  • Experience working with managed security providers, technology vendors, or outsourced IT partners.
  • Strong analytical, troubleshooting, and problem-solving skills.
  • Excellent written and verbal communication skills, with the ability to interact effectively across technical and business teams, including engineering.
  • Ability to manage multiple priorities in a fast-paced environment while maintaining attention to detail.
  • Ability to work on-site in Santa Monica, CA on a hybrid schedule for the duration of the engagement.
Preferred Qualifications
  • Experience with Microsoft Purview, Microsoft Sentinel, and the broader Defender suite (Defender for Cloud, Defender for Cloud Apps).
  • Experience with Infrastructure-as-Code (ARM/Bicep, Terraform) for enforcing security configuration at scale.
  • Experience with technologies such as CrowdStrike Falcon, eSentire, Proofpoint, and Fortra Digital Guardian.
  • Experience supporting financial services, investment management, or other highly regulated environments.
  • Experience coordinating penetration tests, security assessments, and vendor risk reviews — particularly for cloud/SaaS and data platform vendors.
  • Familiarity with hybrid infrastructure and modern endpoint management solutions.
  • Knowledge of incident response planning, business continuity, disaster recovery, and audit support processes.
  • Professional certifications such as CISSP, CISA, CISM, Security+, GIAC, or Azure Security Engineer Associate (AZ- 500) — preferred but not required.
  • Prior consulting or contract engagement experience within an embedded client team.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Cloud Security Engineer
Senior Cloud Security Engineer

Eleven Recruiting • Santa Monica (CA)

On-site
USD 140,000 - 190,000
Sr. Cloud Security Engineer (Remote)
Sr. Cloud Security Engineer (Remote)

inspiracareers • Oak Brook (IL)

Hybrid
USD 160,000 - 190,000
Azure Security Engineer
Azure Security Engineer

Zeektek • Sacramento (CA)

On-site
USD 140,000 - 170,000
Security Analyst
Security Analyst

Perfict • Massachusetts

On-site
USD 120,000 - 170,000
Security Engineer
Security Engineer

Cortavo, Inc. • Atlanta (GA)

On-site
USD 100,000 - 130,000
Competitive salary
Health benefits
Company cell phone plan
+2
Senior Cloud Security Engineer
Senior Cloud Security Engineer

Cream City Cyber • Milwaukee (WI)

On-site
USD 120,000 - 160,000
Systems Engineer Azure Identity
Systems Engineer Azure Identity

Career Listings • Fort Belvoir (VA)

On-site
USD 140,000 - 190,000
401(k)
401(k) matching
Dental insurance
+6
Sr Security Engineer
Sr Security Engineer

Leeds Professional Resources • Illinois

On-site
USD 140,000 - 180,000
Manager – Cyber Security
Manager – Cyber Security

Jobtailor • Los Angeles (CA)

On-site
USD 140,000 - 190,000
Journeyman Cloud Security Engineer (Q Clearance)
Journeyman Cloud Security Engineer (Q Clearance)

ShorePoint • Las Vegas (NV)

On-site
USD 120,000 - 180,000
144 hours PTO
11 holidays
Insurance premiums covered 85%
+3