Job Title: Senior Cloud Security Engineer
Location: Warren, NJ (Hybrid, 3 days onsite)
Duration: Temp - 12 months
Only locals from 60 miles to Warren NJ
Job Description
We are seeking a Senior Cloud Security Engineer to join our dynamic team. The ideal candidate will have strong experience in Azure cloud security engineering, Microsoft Entra ID, policy-as-code, and identity and access hardening and a proven ability to remediate findings, implement durable controls, and prevent recurrence through automation and secure baselines.
Responsibilities:
- Own end-to-end remediation of security findings from triage through verification and closure.
- Root-cause recurring issues and implement systemic fixes using policy-as-code, automated guardrails, and secure baselines.
- Track remediation SLAs and report on risk reduction and posture trends.
- Secure and govern modern authentication flows including OIDC, OAuth 2.0 with PKCE, JWT, and mTLS.
- Administer and harden Microsoft Entra ID, including app registrations, Enterprise Applications, permissions and consent governance, service principals, managed identities, and least privilege.
- Design, implement, and tune Conditional Access policies.
- Build and enforce Azure guardrails with Azure Policy and Terraform; maintain secure-by-default IaC baselines and detect or remediate drift.
- Operate Microsoft Defender for Cloud to improve secure score, remediate recommendations, and manage CSPM.
- Contribute to security governance including standards, control definitions, exceptions, and audit evidence.
- Secure cloud and SaaS admin portals; strengthen privileged access with MFA, PIM, minimized roles, and break-glass procedures.
- Apply security controls to AI workloads and agents, including identities, permission scoping, and data exposure risk management.
Required Skills & Qualifications:
- 5+ years in cloud security or security engineering with deep hands-on Azure experience.
- Strong Microsoft Entra ID expertise: app registrations, Enterprise Apps, permissions and consent, Conditional Access.
- Proficiency with OIDC, OAuth 2.0/PKCE, JWT, and mTLS.
- Proficiency with Terraform and Azure Policy for policy-as-code and automated guardrails.
- Experience with Microsoft Defender for Cloud and CSPM practices.
- Demonstrated ability to permanently close security findings through root-cause remediation.
- Working understanding of AI, AI agents, and AI security considerations.
Preferred Skills:
- Multi-cloud exposure (AWS, Google Cloud Platform).
- Relevant certifications such as Microsoft SC-100, AZ-500, SC-300, or CISSP.
- Experience with CI/CD pipeline security, secrets management, and SIEM/SOAR.
- Scripting and automation with PowerShell or Python.
- Hands-on experience securing LLM-based or agentic systems in production.