Principal Cybersecurity Engineer
As a Cybersecurity Principal Engineer, you will
- Design, implement, and own the Azure Landing Zone security architecture, including:
- Azure Policies and Policy Initiatives
- Guardrails, RBAC models, management groups, and subscription architecture
- Lead implementation and day‑to‑day management of enterprise security platforms, including:
- CrowdStrike (endpoint protection, detection, and response)
- Proofpoint (email security, phishing protection, and threat intelligence)
- Rapid7 (vulnerability management, exposure analytics, and threat detection)
- Checkmarx (SAST, DAST, SCA, code security governance)
- Wiz (CNAPP / CSPM / workload and cloud risk visibility)
- Implement and operationalize Azure Policy for:
- Resource tagging, region restrictions, SKU allowlists
- Encryption, data residency, and compliance guardrails
- Deploy, tune, and manage:
- Microsoft Defender for Cloud (CSPM/CWPP)
- Defender for Identity
- Container and AKS security controls
- Stand up and evolve Microsoft Sentinel (SIEM/SOAR):
- Data connectors, analytics rules, UEBA
- Threat enrichment and automated response playbooks
- Implement Policy‑as‑Code and Security Baselines‑as‑Code using GitOps practices.
- Maintain enterprise risk register, report security KPIs to leadership, and partner with risk, compliance, and audit teams.
- Run purple‑team style control validation, lead incident response runbooks, and drive post‑incident improvements.
- Establish and govern network security architectures:
- Hub‑spoke / vWAN
- Private Endpoints, Azure Firewall, WAF, DDoS
What would your day look like?
- Partner with Engineering, Network, and Platform teams to design and operate a secure, compliant Azure platform and Snowflake tenant.
- Analyze and audit platform and application codebases using Checkmarx and related tooling to identify vulnerabilities and compliance gaps.
- Act as a security authority on the Architecture Review Board, shaping approved application and cloud design patterns.
- Collaborate with vendors and partners on security assessments and remediation strategies (CrowdStrike, Proofpoint, Rapid7, Wiz).
- Continuously monitor threats and alerts; define SOPs and train L1/L2 teams for effective triage and escalation.
- Drive sprint delivery for security initiatives with high quality and on‑time execution.
Who are we looking for?
- 10+ years of cybersecurity experience with 5+ years focused on Azure cloud security architecture.
- Deep expertise in:
Azure RBAC, Microsoft Entra ID, Conditional Access
PIM / PIM for Groups, Identity Governance
Strong hands‑on experience with:
CrowdStrike, Proofpoint, Rapid7, Checkmarx, Wiz
Defender for Cloud, Microsoft Sentinel, Azure Firewall, WAF
- Proven experience delivering Azure Landing Zones aligned to Microsoft Cloud Adoption Framework and Well‑Architected principles.
- Strong identity federation knowledge (SAML, OAuth2/OIDC), SCIM provisioning, and B2B integrations.
- Automation‑first mindset with PowerShell, Python, Terraform, Bicep, Git, YAML, and CI/CD workflows.
Required Skills:
- Expert‑level Microsoft Entra ID, Conditional Access, PIM, RBAC, and identity governance
- Enterprise‑scale Azure network security and private connectivity design
- Deep experience implementing CNAPP, EDR, email security, vuln management, and code security platforms
- Strong DevSecOps background including SAST/DAST, IaC scanning, and API security
- Mature incident response, observability, and alert tuning experience
- Familiarity with AI/LLM security patterns (Azure OpenAI, RAG architectures)
- Strong experience with Azure network security, including VNet architecture, private endpoints, DDoS, WAF, and Azure Firewall
- Hands-on experience implementing Defender for Cloud, Sentinel SIEM/SOAR, and cloud threat-detection pipelines
- Demonstrated ability to design Azure Policy, policy-as-code, and compliance automation for SOC2/ISO/HIPAA
- Deep understanding of Key Vault, CMK encryption, data protection, and secure data pipelines
- Proven background in DevSecOps, secure CI/CD, IaC (Terraform/Bicep), SAST/DAST, and API security
- Strong capability in observability, logging, alert tuning, and incident response automation
- Experience building secure Azure Landing Zones and enterprise cloud architecture.