Cloud Security Engineer / Architect (Azure)
Job Description
A large healthcare system in the Philadelphia area is seeking a Cloud Security Engineer/Architect with deep expertise in Azure security governance, Azure Policy, and cloud architecture. This individual will lead the design and enforcement of cloud security controls, drive remediation of security findings, and implement preventative guardrails that reduce future risk. The ideal candidate has a strong infrastructure engineering background and can speak in detail about identifying security issues, remediating them, and designing long-term solutions to prevent them from recurring. This role requires both hands-on technical expertise and architectural foresight to build secure, compliant, and scalable Azure environments.
Key Responsibilities
- Design and maintain Azure security policies, governance standards, and preventative controls.
- Own the remediation lifecycle for Azure security findings, from identification through validation and long-term prevention.
- Leverage Azure Policy and policy-as-code frameworks to enforce security requirements at scale.
- Partner with cloud engineering teams to implement secure architectures and sustainable fixes for security risks.
- Develop guardrails that shift the organization from reactive remediation to proactive enforcement.
- Translate compliance and security requirements into actionable technical controls.
- Ensure Azure environments align with organizational security standards and regulatory frameworks (HIPAA, NIST, PCI, CIS).
- Support security governance for emerging AI and cloud-based technologies.
Required Qualifications
- 7+ years of experience in Cloud Security Engineering, Cloud Security Architecture, or Cloud Infrastructure Engineering with a security focus.
- Deep expertise with Azure Policy, governance, and security controls.
- Proven experience identifying, remediating, and preventing cloud security findings at scale.
- Strong knowledge of Azure security services, including Azure Policy, RBAC, Management Groups, and Defender for Cloud.
- Experience designing secure cloud architectures and implementing preventative guardrails.
- Experience partnering with both technical and non-technical stakeholders to drive security initiatives.
- Familiarity with Terraform, Infrastructure as Code (IaC), and policy-as-code concepts.
- Understanding of security and compliance frameworks such as HIPAA, NIST, PCI, and CIS.
- Bachelor's Degree
Preferred Qualifications
- Experience with Cloud Security Posture Management tools (e.g., Wiz)
