Cloud and Application Security Specialist
LingaTech · Middletown, PA · 1 mo ago
Information TechnologyFull-time
Job Duties
- Azure Security Engineering
- Design, implement, and maintain security controls across Microsoft Azure environments.
- Develop and enforce Azure security baselines, governance standards, and cloud security architecture requirements.
- Implement and manage Azure Policy, Management Groups, Resource Locks, Role-Based Access Control (RBAC), Privileged Identity Management (PIM), and Conditional Access policies.
- Support the development and maintenance of secure Azure Landing Zones and cloud governance frameworks.
- Cloud Threat Detection and Response
- Administer and optimize Microsoft Defender for Cloud, Microsoft Sentinel, Microsoft Entra ID Protection, and other Azure-native security tools.
- Investigate cloud security alerts, suspicious activity, and indicators of compromise affecting Azure resources and workloads.
- Support cloud-focused incident response activities, including containment, forensic analysis, and remediation.
- Develop and enhance cloud monitoring, threat detection, and alerting capabilities to improve security visibility.
- Cloud Security Assessments and Risk Management
- Conduct security assessments of Azure resources to identify vulnerabilities, misconfigurations, and compliance gaps.
- Evaluate security risks associated with cloud deployments and recommend mitigation strategies.
- Support vulnerability management activities by reviewing cloud security findings and coordinating remediation efforts.
- Perform security architecture reviews for new cloud services, applications, and infrastructure deployments.
- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Engineering, or a related technical field; or an equivalent combination of education and experience.
- 3+ years of experience administering, engineering, or securing Microsoft Azure environments.
- Strong understanding of Azure IaaS, PaaS, networking, identity management, storage services, and cloud security architecture.
- Experience with Microsoft Defender for Cloud, Microsoft Sentinel, Microsoft Entra ID, Azure Policy, Azure RBAC, and cloud governance frameworks.
- Knowledge of Zero Trust Architecture, the NIST Cybersecurity Framework, CIS Benchmarks, and cloud security best practices.
- Strong analytical, troubleshooting, communication, and technical documentation skills.
- MSCSA (AZ-500) certification.
- MSCAP (AZ-104) certification.
- CISSP, CCSP, Security+, CySA+, or equivalent cybersecurity certification.
- Experience with Infrastructure as Code (Terraform, Bicep, ARM Templates), Azure Landing Zones, or cloud automation.
- Experience securing Azure Kubernetes Service (AKS), Azure App Services, Azure SQL, and other cloud-native services.
- Experience supporting public sector, transportation, or critical infrastructure environments.