Salary
💰 $160,000 - $185,000 per year
About the role
- Conduct in-depth security assessments across Azure, M365, Entra ID, and AWS environments to evaluate configurations, data protection, and access controls.
- Design and implement secure cloud architectures across Azure, M365, and AWS, integrating security controls for scalability and resilience.
- Detect and remediate vulnerabilities (IAM, MFA, M365 weaknesses, unsecured endpoints, data loss risks) using manual and automated techniques.
- Assess, design, and implement data classification and Data Loss Prevention (DLP) strategies across Microsoft, AWS, and on-premises environments.
- Develop and execute cloud-focused threat simulations using Microsoft and AWS security tools and OSINT techniques.
- Prepare comprehensive security reports detailing vulnerabilities, exploitation methods, and prioritized remediation recommendations.
- Translate complex cloud security findings into actionable insights and present to clients and stakeholders.
- Provide remediation guidance and support implementation of identity management, access controls, and DLP strategies.
- Stay updated on certifications, emerging cloud security threats, vulnerabilities, and Zero Trust best practices.
Requirements
- 3-5 years of experience in cloud security, with a focus on Microsoft Azure, M365, and AWS security.
- Deep understanding of Microsoft Entra ID, Azure AD, Microsoft Defender Suite, Microsoft Sentinel, and DLP strategies.
- Strong knowledge of AWS security services, including IAM, Security Hub, GuardDuty, and VPC security configurations.
- Experience conducting security assessments, risk analysis, and remediation in M365, Azure, and AWS cloud environments.
- Hands-on skills in cloud security architecture, risk management, incident response, and business email compromise.
- Understanding of exploitation of misconfigurations within cloud platforms.
- Relevant certifications such as Microsoft AZ-500, MS-500, SC-100, SC-200, SC-400; CISSP or CCSP a plus.
- Bachelor’s degree in Computer Science, Information Security or a related field.
- Uphold ethical standards and maintain strict confidentiality.
- Must be located in the U.S. (Remote US Only)