29 Aug
|
Robert Half
|
Oakville
29 Aug
Robert Half
Oakville
Position Summary
Our client is seeking a highly skilled Cloud Security Engineer to design, secure, automate, and operate our Microsoft Azure environment while supporting enterprise applications, cloud platforms, and modernization initiatives.
This role combines cloud engineering, security engineering, infrastructure-as-code, identity and access management, networking, DevSecOps, data platform engineering, and operational support. The successful candidate will work closely with Information Security, Infrastructure, Application Development, Platform Engineering, ERP, and Data teams to deliver secure, scalable, and resilient cloud solutions that support critical business operations and digital transformation initiatives.
The ideal candidate is equally comfortable designing cloud architectures, implementing security controls, building automation, supporting Azure workloads, troubleshooting complex platform issues, and partnering with stakeholders to reduce risk while enabling business outcomes.
Key Responsibilities
Cloud Architecture & Platform Engineering
- Design, implement, and support secure, scalable, and resilient cloud-native solutions in Microsoft Azure.
- Develop cloud architecture patterns and standards that align with enterprise security and governance requirements.
- Evaluate and support current Azure services, platform modernization initiatives, cloud migrations, and application transformations.
- Configure and support Azure services including:
- Virtual Machines
- App Service
- Storage Accounts
- Key Vault
- Azure SQL
- Service Bus
- Azure Front Door
- Application Gateway
- Application Insights
- Azure Data Services
- Troubleshoot platform issues and coordinate resolution with internal teams and Microsoft support.
- Cloud Security & Governance
- Design and implement Azure security controls, guardrails, and secure engineering standards in alignment with Azure Well Architected Framework
- Operate and enhance Microsoft Defender for Cloud, Azure Policy, Secure Score, and cloud security posture management capabilities.
- Investigate excessive permissions, misconfigurations, exposed resources, and compliance gaps.
- Implement Zero Trust principles, least privilege access, and secure-by-default cloud configurations.
- Support compliance initiatives aligned to NIST, CIS, ISO 27001, SOC 2, and corporate security standards.
- Conduct vulnerability management activities using Microsoft Defender, Tenable, and related security platforms.
- Identity & Access Management
- Administer Microsoft Entra ID and hybrid identity services.
- Implement and maintain:
- Role-Based Access Control (RBAC)
- Conditional Access Policies
- Privileged Identity Management (PIM)
- Managed Identities
- Service Principals
- Access Reviews
- Support enterprise application integrations and Microsoft Graph permissions.
- Manage certificates, secrets, key management, and Azure Key Vault.
- Establish governance and security standards for identity and privileged access management.
Infrastructure as Code & Automation
- Develop and maintain reusable Terraform modules and deployment patterns.
- Build and support Infrastructure-as-Code solutions using Terraform, ARM, Ansible and Bicep.
- Create and optimize CI/CD pipelines using Azure DevOps and Git-based workflows.
- Automate cloud provisioning, configuration management, monitoring, and operational processes.
- Reduce configuration drift and improve deployment consistency across environments.
- Develop automation using PowerShell and Python
- DevSecOps & Application Security
- Integrate security controls into DevOps and CI/CD pipelines.
- Collaborate with developers and platform engineers to embed security throughout the software development lifecycle.
- Support:
- Vulnerability remediation
- Dependency scanning
- Container image scanning
- Secret scanning
- Code security analysis
- Security quality gates
- Help define practical security standards and exception processes that balance protection and business agility
- Kubernetes & Container Platforms
- Deploy, manage, secure, and scale Azure Kubernetes Service (AKS) environments.
- Support containerized workloads using Docker and cloud-native deployment patterns.
- Assist with container orchestration strategies and platform automation.
- Integrate container security controls into deployment and operational processes.
Cloud Networking & Connectivity
- Design and support Azure networking services including:
- Virtual Networks
- Hub-and-Spoke Architectures
- Azure Firewall
- Network Security Groups
- Private Endpoints
- VPN Connectivity
- ExpressRoute
- Front Door
- Application Gateway
- Configure and troubleshoot DNS, certificates, routing, and hybrid connectivity.
- Support secure integration between Azure, on-premises infrastructure, and third-party platforms including Zscaler.
- Review and optimize firewall and network security configurations
- Enterprise Applications & Data Platforms
- Support and optimize Microsoft Dynamics 365 Finance & Operations and Customer Engagement platforms.
- Design and support integrations between Dynamics 365, Azure services, and enterprise applications.
- Design and maintain Azure-based data platforms, including:
- Azure Data Lake
- Azure Synapse Analytics
- Azure SQL
- Data Factory
- Build and support secure ETL/ELT pipelines and analytics platforms.
- Ensure governance, performance, and security controls are implemented across cloud data environments.
- Collaboration & Productivity Platforms
- Support security, governance,
and operations for Microsoft Teams, SharePoint Online, and Microsoft 365 services.
- Assist with implementation of collaboration platform controls, compliance requirements, and operational support processes.
- Partner with business stakeholders to improve platform security and user experience.
Technical Leadership & Collaboration
- Develop architecture documentation, standards, operational procedures, and knowledge articles.
- Lead technical workshops and troubleshooting sessions.
- Mentor junior engineers, co-op students, and technical staff.
- Communicate technical risks, opportunities, and recommendations to both technical and non-technical stakeholders.
- Collaborate effectively across Information Security, Infrastructure, Platform Engineering, ERP, Application Development, and Data teams.
- Required Qualifications
- Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or related field.
- 5 years of experience in Microsoft Azure cloud engineering, infrastructure, or platform engineering.
- 3 years of experience in cloud security, security engineering, governance, or vulnerability management.
- Strong knowledge of Azure architecture, networking, governance, and security services.
- Hands-on experience with:
- Terraform
- Azure DevOps
- Git
- CI/CD Pipelines
- PowerShell
- Python
- Experience administering Microsoft Entra ID and hybrid identity environments.
- Strong understanding of enterprise networking, DNS, firewalls, routing, load balancing, VPNs, and hybrid-cloud connectivity.
- Experience with AKS, Docker, and containerized workloads.
- Experience supporting Windows Server, Linux, Azure Virtual Machines, and virtualization technologies.
- Working knowledge of Microsoft Dynamics 365 and Azure integration services.
- Strong troubleshooting, documentation, communication, and stakeholder management skills
- Preferred Qualifications
- Microsoft Certified: Azure Security Engineer Associate (AZ-500)
- Microsoft Certified: Azure Administrator Associate (AZ-104)
- Microsoft Certified: Azure Solutions Architect Expert (AZ-305)
- HashiCorp Terraform Associate
- CISSP, CCSP, Security , or equivalent cloud/security certifications
- Experience with:
- Microsoft Defender Suite
- Microsoft Purview
- Tenable
- Zscaler
- Azure Synapse
- Data Factory
- Secure development and DevSecOps practices
- Familiarity with NIST, CIS, ISO 27001, and SOC 2 frameworks
- Ideal Candidate Profile A hands-on Cloud Security Engineer who combines deep Microsoft Azure expertise with strong security engineering fundamentals, infrastructure automation experience, identity and access management knowledge, networking proficiency, and a passion for secure cloud transformation. The successful candidate thrives in a highly collaborative environment and can move seamlessly between architecture, implementation, troubleshooting, governance, and operational support
📌 Cloud Engineer (Oakville)
🏢 Robert Half
📍 Oakville