Senior Security Engineer (Azure)

Nava Public Benefit Corp.

Northern (KY)

Remote

USD 136,000 - 153,000

Full time

2 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Health coverage
Disability insurance
Life insurance
Vacation and holidays
Annual bonus
Parental leave
Wellness program
Remote-friendly
Home office setup
401(k) match
Flexible work
Learning opportunities
Referral bonus
Commuter benefits

Job summary

Nava Public Benefit Corp. is seeking a Security Engineer to design and implement a secure Azure cloud environment for a large government modernization effort.

This role focuses on identity management, monitoring, policy enforcement, and secure cloud architecture in collaboration with cloud architects, engineers, and client stakeholders. Responsibilities include implementing IAM models, Defender for Cloud, Azure Policy guardrails, centralized logging, and secure CI/CD practices.

Qualifications

  • Experience with Azure cloud security and Entra ID.
  • Knowledge of IAM including RBAC and privileged access controls.
  • Familiarity with HIPAA, state security standards, and ATO processes.
  • Experience implementing cloud security monitoring, logging, and incident detection.
  • Knowledge of Azure Policy governance for enforcing standards.
  • Experience with key management and secrets handling (Azure Key Vault).
  • Understanding secure network architecture and hybrid/on-prem integrations.
  • Experience with IaC and secure CI/CD pipelines.
  • Ability to document security architecture, standards, and runbooks.
  • Strong collaboration with engineers, architects, and stakeholders.

Responsibilities

  • Design and implement IAM models (RBAC, privileged access).
  • Configure Defender for Cloud and related security tools.
  • Define and enforce security policies using Azure Policy.
  • Set up centralized logging, monitoring, and threat detection.
  • Design key management and secrets handling (Azure Key Vault).
  • Support HIPAA alignment and ATO readiness activities.
  • Collaborate to identify risks and remediation approaches.
  • Contribute to secure cloud architecture decisions including networking.
  • Support IaC and CI/CD to ensure secure deployments.
  • Create security documentation, runbooks, and client guidance.

Skills

Azure security
IAM RBAC
Defender for Cloud
Azure Policy
Azure Key Vault
Security monitoring
Threat detection
Hybrid/on-prem networks
IaC security
CI/CD security
Documentation runbooks

Tools

Microsoft Defender for Cloud
Entra ID
Azure Key Vault

Job description

Nava is a consultancy and public benefit corporation working to make government services simple and effective. Since 2015, federal, state, and local agencies have trusted Nava to help solve highly scrutinized technology modernization challenges.

As a client services company, we guide agencies constrained by legacy systems to a future with sharp user experiences built on secure, reliable, fault-tolerant cloud infrastructure. We bill for our time, offering our expertise and problem-solving approach to help our government partners enhance their digital products and services. People are at the heart of our work, from members of the public who rely on benefit programs to government agency staff. Through human-centered design and modern engineering best practices, we help our government partners understand user needs and deliver on their missions more effectively. This focus gives everyone at Nava the opportunity to do work that is meaningful, impactful, and deeply connected to public good.

This role is open for multiple levels and titles. Final title/compensation will be determined by how your interview weighs against our core competencies during your interview cycle

Position summary

We are seeking a Security Engineer to support the design and implementation of a secure Azure cloud environment for a large-scale government modernization effort. This role will focus on establishing strong security and compliance foundations, including identity and access management, monitoring, and policy enforcement across the tenant. The Security Engineer will partner closely with cloud architects, engineers, and client stakeholders to define and implement security best practices aligned with federal and state requirements.

What you'll do
  • Design and implement identity and access management (IAM) models, including RBAC and privileged access controls
  • Configure and advise on security tools such as Microsoft Defender for Cloud
  • Define and enforce security policies and governance guardrails using Azure Policy
  • Set up and guide centralized logging, monitoring, and threat detection capabilities
  • Design key management and secrets handling solutions (e.g., Azure Key Vault)
  • Support compliance efforts, including HIPAA alignment and ATO preparation activities
  • Collaborate with teams to identify security risks and define remediation approaches
  • Contribute to secure cloud architecture decisions, including networking and access patterns
  • Support Infrastructure-as-Code (IaC) and CI/CD practices to ensure secure deployments
  • Create security documentation, runbooks, and provide guidance to enable client teams to operate securely
Required skills

Experience with Azure cloud security, including Microsoft Entra ID and Defender for Cloud

Strong knowledge of Identity and Access Management (IAM), including RBAC and privileged access controls

Familiarity with security and compliance frameworks (e.g., HIPAA, state security standards, ATO processes)

Experience implementing cloud security monitoring, logging, and incident detection

Knowledge of Azure Policy and governance guardrails for enforcing security standards

Experience with key management and secrets handling (e.g., Azure Key Vault)

Understanding of secure network architecture and connectivity (including hybrid/on-prem integrations)

Experience supporting Infrastructure-as-Code (IaC) and secure CI/CD pipeline practices

Ability to define and document security architecture, standards, and operational runbooks

Strong collaboration skills to work with engineers, architects, and stakeholders on security design and remediation

Compensation

$135,900 - $153,000 USD

Other requirements

Legal authorization to work in the United States

Ability to meet any other requirements for government contracts for which candidates are hired

Work authorization that doesn’t require visa sponsorship, now or in the future

May be subject to a government background check or security clearance, depending on the contract

Perks working with Nava
  • Health coverage— comprehensive medical, dental, and vision plans to support your overall health needs
  • Insurance coverage— Nava provides disability, life, and accidental death insurance at no cost
  • Time off— vacation, holidays (including Juneteenth), and floating holidays to rest and recharge
  • Company holidays— enjoy 12 paid federal holidays each year on top of your regular PTO
  • Annual bonus— when Nava meets its goals, eligible employees receive a performance-based annual bonus
  • Parental leave— paid time off for new parents, plus weekly meals delivered to your home
  • Wellness program— full platform offering physical, mental, & emotional health resources & support tools
  • Virtual care — see doctors online with no copay through a virtual visit program (depending on available providers)
  • Sabbatical leave— earn extended unpaid leave after continuous service for personal growth or rest
  • 401(k) match— Nava matches 4% of your salary to support your retirement savings plan
  • Flexible work— remote-first environment with flexibility built around your schedule and responsibilities
  • Home office setup— company laptop & setup assistance provided via Staples for remote work needs
  • Utility support— monthly reimbursement to help offset eligible home office utility expenses
  • Learning opportunities— internal training programs and resources to help grow your professional skills
  • Development opportunities— LinkedIn Learning access & an annual allowance for courses, tuition, & certs
  • Referral bonus— get rewarded when you refer great people who join the Nava team
  • Commuter benefits— pre-tax commuter programs to support in-office travel when applicable
  • Supportive culture— A collaborative and remote-friendly team environment where people genuinely care
Location

We have fully remote options if you reside in one of the following states:

If you are not living in one of the states listed above, unfortunately, you will not be considered for a position at this time.

Stay in touch

Sign up for our newsletter to find out about career opportunities, new partnerships, and news from the broader civic tech community.

Please contact the recruiting team at recruiting@navapbc.com if you would like to request any form of reasonable accommodation during the application or interviewing process.

We participate in E-Verify. Upon hire, we will provide the federal government with your Form I-9 information to confirm that you are authorized to work in the U.S. This role requires you to work from the contiguous United States.

Nava is committed to providing equal employment opportunities without discrimination or harassment on the basis of race, gender and/or gender identity or expression, color, creed, religion, religious creed, age, national origin, ethnicity, disability, veteran or military status, sex, sexual orientation, reproductive health autonomy, pregnancy, childbirth, and medical conditions related to pregnancy or childbirth, genetic information, domestic violence victim status, marital status, citizenship status, or any other characteristic protected by law. Nava prohibits any such discrimination or harassment. This policy applies to all employees, applicants, contractors, and temporary workers of Nava.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Security Engineer (Azure)Remote
Senior Security Engineer (Azure)Remote

Nava Public Benefit Corp • United States

Remote
USD 136,000 - 153,000
Health coverage
Disability insurance
Vacation & holidays
+10
Senior Software Engineer (Salesforce) Remote
Senior Software Engineer (Salesforce) Remote

Nava Public Benefit Corp • United States

Remote
USD 153,000 - 171,000
Health coverage
Insurance coverage
Time off
+15
Principal Manager, People Operations Business PartnerRemote
Principal Manager, People Operations Business PartnerRemote

Nava Public Benefit Corp • United States

Remote
USD 132,000 - 149,000
Health coverage
Disability and life insurance
Generous paid time off & holidays
+2
Business Development Analyst
Business Development Analyst

Nava • United States

On-site
USD 63,000 - 75,000
Comprehensive health coverage
Disability and life insurance
Vacation and paid holidays
+2
Sr. Software Engineer (Eng Lead/Manager)
Sr. Software Engineer (Eng Lead/Manager)

Nava • United States

On-site
USD 135,900 - 153,000
Health coverage
Insurance coverage
Time off
+15
Project Manager
Project Manager

Nava • United States

On-site
USD 126,000 - 140,000
Comprehensive medical, dental, and vision plans
Disability and life insurance
Vacation and holidays
+5
1099 Workday Administrator | Payroll, Benefits & Talent
1099 Workday Administrator | Payroll, Benefits & Talent

Abundance Network • United States

Remote
USD 76,000 - 103,000
Health coverage
401(k) match
Remote-first
+3
Principal Manager, People Operations Business Partner
Principal Manager, People Operations Business Partner

Nava Public Benefit Corp. • Northern (KY)

Hybrid
USD 132,000 - 149,000
Health coverage
Insurance coverage
Time off
+15
Product Manager
Product Manager

Praxy • Northern (KY)

Hybrid
USD 118,000 - 148,000
Health coverage
Insurance coverage
Time off
Financial Analyst
Financial Analyst

Nava • United States

On-site
USD 100,000 - 110,000
Comprehensive health coverage
401(k) match
Flexible work environment
+3