Haystack
← Back to Jobs
Technology
AC

Senior Cloud Security Engineer

A3N consulting LlcIndependence Township, NJ🇺🇸United StatesPosted 19 Aug 2026

Quick Overview

Work Type
On Site
Level
Mid Senior

Job Description

Job : Senior Cloud Security Engineer
Location: Warren, NJ (Onsite)

Required Skills
1. Identity & Access Management
Mandatory
  • Microsoft Entra ID: Administer and harden Microsoft Entra ID: app registrations and Enterprise Application permissions, consent governance, service principals and managed identities, credential and secret hygiene, and least-privilege scoping.
  • Privileged Access Security: MFA enforcement, Privileged Identity Management (PIM) / just-in-time elevation, role minimization, and break-glass procedures.
Good to Have
  • Modern Authentication: Secure and govern modern authentication flows across the estate: OIDC, OAuth 2.0 with PKCE, JWT validation and handling, and mTLS.
  • Conditional Access: Design, implement, and continuously tune Conditional Access policies.
  • App Registrations & Enterprise Applications: App registrations and Enterprise Application permissions, consent governance, service principals and managed identities, credential and secret hygiene, and least-privilege scoping.
2. Cloud Security
Mandatory
  • Security Findings Remediation: Own the full lifecycle of security findings and recommendations through triage, remediation, verification, and closure.
  • Recurrence Prevention: Root-cause recurring issues and implement systemic fixes using policy-as-code, automated guardrails, and secure baselines.
  • Microsoft Defender for Cloud: Drive secure-score improvement, remediate recommendations, and manage cloud security posture (CSPM).
  • Security Governance: Contribute to standards, control definitions, exception handling, and audit evidence.
  • Cloud & SaaS Admin Portal Security: Secure all cloud and SaaS administrative portals, including Azure, Microsoft 365 admin, identity providers, and additional cloud platforms in use.
Good to Have
  • Azure Policy: Build and enforce guardrails using Azure Policy; maintain secure-by-default baselines and detect or remediate configuration drift.
3. Terraform for IaC
Optional
  • Terraform & Secure IaC Baselines: Build and enforce guardrails using Terraform; maintain secure-by-default infrastructure-as-code baselines and detect or remediate configuration drift.
4. AI Security
Mandatory
  • AI Workloads, Services & Agents: Apply security controls to AI workloads, services, and AI agents.
  • AI Identities, Permissions & Risk: Agent and workload identities, tool and permission scoping, data-exposure and prompt-injection risk, and emerging AI security best practices.

Skills

MFA
OAuth
Azure
JWT
Terraform

Similar jobs