Security Engineer - Azure Government

xAI xAI · AI Frontier · Palo Alto, CA +1 · Information Security

Seeking an Azure Security Engineer to design, implement, and maintain security controls in Azure Gov Cloud, focusing on threat detection, incident response, and compliance with government regulations like FedRAMP and CMMC. The role involves hands-on configuration of Microsoft security tools and collaboration with engineering teams.

What you'd actually do

  1. Implement, design, and manage security architecture for Azure Government and Commercial deployments (with considerations for DoD IL5\IL6 and FedRAMP High controls)
  2. Configure and optimize Microsoft Defender for Cloud, Microsoft Sentinel, Microsoft Defender for Endpoint, and related services for threat detection, vulnerability management, and automated response
  3. Design and enforce identity & access management using Microsoft Entra ID, Privileged Identity Management (PIM), Conditional Access policies, RBAC, and just-in-time access
  4. Secure network architectures with Azure Firewall, Network Security Groups (NSGs), DDoS Protection, Web Application Firewall (WAF), Network Watcher, and private endpoints
  5. Protect data at rest and in transit via Azure Key Vault, encryption strategies, data classification, and information protection controls

Skills

Required

  • Active U.S. security clearance (e.g., Secret, Top Secret) or eligibility to obtain one.
  • 3+ years of experience in cloud security, cybersecurity engineering, or related roles (with strong Azure focus)
  • Deep hands-on expertise with core Azure security services: Microsoft Defender suite, Sentinel, Intune, Entra ID, Key Vault, Azure Policy, Firewall, Network Watcher, and Purview
  • Strong understanding of DLP implementation both in cloud and on endpoints utilizing Purview and other Microsoft native controls
  • Experience implementing security in hybrid/multi-cloud environments
  • Proficiency in scripting/automation (PowerShell, Azure CLI, Bicep/ARM templates, Terraform)
  • Strong understanding of identity federation, zero-trust principles, encryption, network security, and vulnerability management
  • Familiarity with compliance frameworks (NIST, FedRAMP, CMMC, STIGs, etc.) and regulatory requirements
  • Excellent problem-solving, analytical, and communication skills
  • Strong verbal and written communication skills and the ability to stay composed under pressure.

Nice to have

  • Microsoft Certified: Azure Security Engineer Associate (AZ-500), Microsoft Cybersecurity Architect (SC-100)
  • Additional relevant certifications (e.g., CISSP, CCSP, Microsoft Certified: Azure Administrator, AWS Security Specialty, SANS GCPS, SANS GCAD)
  • Deep experience with detection and response engineering and SOC operations
  • Knowledge of container security (Docker, AKS), secure DevOps, or AI/ML workload protection
  • Prior experience in government regulations frameworks such as FedRAMP and CMMC.

What the JD emphasized

  • Azure Government
  • FedRAMP
  • CMMC
  • Microsoft Defender
  • Microsoft Sentinel
  • Microsoft Entra ID
  • Azure Firewall
  • Azure Key Vault
  • Azure Policy
  • Microsoft Purview
  • NIST
  • STIGs
  • Active U.S. security clearance
  • 3+ years of experience in cloud security, cybersecurity engineering, or related roles (with strong Azure focus)