Lead Security Engineer
Duration: 2 Months
Location: New York, NY
Work Arrangement: Hybrid – 3 Days Onsite / 2 Days Remote per Week
Job Description
The Lead Security Engineer will be responsible for implementing, configuring, validating, and documenting security controls across Azure and SaaS environments. The role will focus on identity and access management, vulnerability management, security monitoring, cloud security architecture, and security tooling.
Security Engineering & Implementation
- Implement and configure security controls within Azure and SaaS environments.
- Configure identity, access management, and role-based access controls (RBAC).
- Implement encryption, logging, monitoring, and audit controls.
- Review and validate secure configurations across Azure networking, compute, storage, and application services.
- Ensure security configurations meet established organizational standards.
Identity & Access Management
- Configure and validate SSO, MFA, and Active Directory/Azure AD integrations.
- Implement role-based access models and least-privilege access controls.
- Configure privileged access workflows and administrative access controls.
- Support user provisioning and access lifecycle management.
- Perform access validation testing and remediate identity-related issues.
Vulnerability Management & Security Operations
- Configure and operate vulnerability scanning and assessment tools.
- Review vulnerability scan results and coordinate remediation with infrastructure and application teams.
- Configure and validate security logging, alerting, and dashboards.
- Configure SIEM, monitoring, and alerting rules.
- Track security findings and validate remediation and closure of vulnerabilities and misconfigurations.
Security Architecture Implementation
- Participate in technical implementation and security design sessions.
- Review and validate security architecture for cloud, SaaS, APIs, and integrations.
- Apply security-by-design principles throughout development and deployment.
- Validate secure network architecture, including:
- Network segmentation
- Private endpoints
- Firewalls
- Secure connectivity
- Review vendor security configurations and ensure alignment with approved security requirements.
Security Tooling & Platform Configuration
- Configure security tools across cloud and enterprise environments.
- Implement endpoint protection, monitoring, and vulnerability management solutions.
- Configure logging, alerting, and security telemetry collection.
- Work with Log Analytics and SIEM platforms.
- Integrate and configure Microsoft security technologies, including:
- Microsoft Defender
- Microsoft Sentinel
- Microsoft 365 Security
- Configure security alerts and monitoring rules.
Technical Documentation
- Create and maintain as-built security documentation.
- Document security configurations, implementation activities, and operational procedures.
- Maintain security configuration baselines and technical documentation.
Deliverables
- Configured SSO, MFA, RBAC, and IAM controls.
- Security monitoring, logging, and alerting configurations.
- Security configuration baselines for Azure and integrated SaaS environments.
- Security readiness assessment and go-live validation documentation.
- Comprehensive security configuration and as-built documentation.
Mandatory Skills & Experience
5+ years of experience in the following areas:
- Azure Security, including:
- Microsoft Defender for Cloud
- Microsoft Sentinel
- Security baselines
- Identity & Access Management, including:
- Azure AD / Microsoft Entra ID
- SSO
- MFA
- RBAC
- PAM
- Vulnerability Management using tools such as:
- Rapid7
- Qualys
- Equivalent enterprise vulnerability management platforms
- SIEM and Log Analytics, including:
- Microsoft Sentinel
- Log Analytics Workspace
- Cloud Security Architecture, including:
- Azure networking
- Private endpoints
- Network segmentation
- Firewalls
- Security Tooling, including:
- CrowdStrike
- Microsoft 365 Security Stack
- Cisco security technologies
- Incident Response & Security Operations, including:
- SOC processes
- Security triage
- Escalation
- Security incident investigation
- DevSecOps and secure CI/CD integration.
- Experience with Azure DevOps and CI/CD pipelines.
- Encryption and Key Management, including Azure Key Vault and data protection controls.
- Strong hands-on implementation, troubleshooting, and security engineering experience in cloud environments.
Core Skills
- Azure Security
- Microsoft Defender for Cloud
- Microsoft Sentinel
- Azure AD / Microsoft Entra ID
- SSO / MFA / RBAC / PAM
- Vulnerability Management
- Rapid7 / Qualys
- SIEM / SOC
- Log Analytics
- Azure Networking
- Private Endpoints
- Network Segmentation
- CrowdStrike
- Microsoft 365 Security
- Cisco Security
- Incident Response
- DevSecOps
- Azure DevOps / CI/CD
- Encryption / Key Management
- Azure Key Vault
- Cloud Security Architecture
- Security Monitoring & Alerting
- Security Documentation