Description
At Sequoia Connect, we are a Talent-First Technology Ecosystem that redefines how elite professionals interact with the global digital landscape. We move beyond traditional models to act as a catalyst for the top 1% of global talent, connecting human potential with complex industrial execution. By joining our inner circle, you are not simply taking a position; you are aligning with a strategic partner dedicated to updating your "Human OS" and accelerating your growth through world-class, high-impact projects.
We are currently partnering with a global IT powerhouse that represents the connected world through innovative, customer-centric experiences. As a USD 6 billion organization and one of the top 7 IT service providers globally, our client empowers over 1,200 global customers—including several Fortune 500 companies—to "Rise™." With a massive network of 163,000+ professionals across 90 countries, they are at the absolute forefront of digital transformation, leveraging next-generation technologies such as 5G, AI, Blockchain, and Quantum Computing.
This is your chance to thrive in a workplace recognized as one of the most sustainable corporations in the world. You will join an environment that values innovation and societal impact, working on end-to-end digital transformation projects for global leaders. If you are a driven professional looking for global career opportunities and exposure to high-impact projects within an international network of expertise, this is where you belong.
We are currently searching for a Cloud Security Engineer T&M:
The Challenge (Responsibilities)
- Own the full lifecycle of security findings and recommendations—from Our Client's security team, Microsoft Defender for Cloud, or other tooling—through triage, remediation, verification, and closure.
- Root-cause recurring issues and implement systemic fixes (policy-as-code, automated guardrails, secure baselines) to prevent findings from reappearing.
- Track remediation SLAs and report on risk reduction and posture trends over time.
- Secure and govern modern authentication flows across the estate: OIDC, OAuth 2.0 with PKCE, JWT validation and handling, and mTLS.
- Administer and harden Microsoft Entra ID: app registrations and Enterprise Application permissions, consent governance, service principals and managed identities, credential and secret hygiene, and least-privilege scoping.
- Design, implement, and continuously tune Conditional Access policies.
- Build and enforce guardrails using Azure Policy and Terraform; maintain secure-by-default infrastructure-as-code baselines and detect/remediate configuration drift.
- Operate Microsoft Defender for Cloud to drive secure-score improvement, remediate recommendations, and manage cloud security posture (CSPM).
- Contribute to security governance: standards, control definitions, exception handling, and audit evidence.
- Secure all cloud and SaaS administrative portals, including Azure, Microsoft 365 admin, and identity providers.
- Strengthen privileged access through MFA enforcement, Privileged Identity Management (PIM) / just-in-time elevation, role minimization, and break-glass procedures.
- Apply security controls to AI workloads, services, and AI agents, including agent/workload identities, tool and permission scoping, and mitigating data-exposure and prompt-injection risks.
Your Profile (Requirements)
- 5+ years in cloud security or security engineering, with deep, hands-on Azure experience.
- Strong, hands-on Microsoft Entra ID expertise: app registrations, Enterprise Apps, permissions and consent, and Conditional Access.
- Solid working knowledge of modern authentication: OIDC, OAuth 2.0 / PKCE, JWT, and mTLS.
- Proficiency with Terraform and Azure Policy for policy-as-code and automated guardrails.
- Experience with Microsoft Defender for Cloud and cloud security posture management.
- A demonstrable track record of root-causing and permanently closing security findings—not just patching them.
- Working understanding of AI, AI agents, and AI security considerations.
- High-Performance Mindset: Resilience, emotional intelligence, and a focus on agile delivery.
- Technologist DNA: A deep understanding of the difference between "coding" and "engineering."
Desired
- Multi-cloud exposure (AWS, GCP).
- Relevant certifications (e.g., Microsoft SC-100, AZ-500, SC-300; CISSP).
- Experience with CI/CD pipeline security, secrets management, and SIEM/SOAR.
- Scripting/automation proficiency with PowerShell or Python.
- Hands-on experience securing LLM-based or agentic systems in production.
- Familiarity with cloud-native foundations or AI coding assistants.
Languages
- Advanced Oral English: For seamless collaboration with global teams.
- Advanced Spanish.
Special Notes
- This is a hands-on engineering and remediation role, not an advisory position. Success is measured by a measurably more secure environment and a shrinking backlog of recurring findings enforced by design.
Work Arrangement
We value flexibility to support your lifestyle. This position is available as:
If you meet these qualifications and are pursuing new challenges, start your application on our website to join an award-winning employer. Explore all our job openings | Sequoia Career’s Page: https://www.sequoia-connect.com/careers/
Requirements
- 5+ years in cloud security or security engineering, with deep, hands-on Azure experience.
- Strong, hands-on Microsoft Entra ID expertise: app registrations, Enterprise Apps, permissions and consent, and Conditional Access.
- Solid working knowledge of modern authentication: OIDC, OAuth 2.0 / PKCE, JWT, and mTLS.
- Proficiency with Terraform and Azure Policy for policy-as-code and automated guardrails.
- Experience with Microsoft Defender for Cloud and cloud security posture management.
- A demonstrable track record of root-causing and permanently closing security findings.
- Working understanding of AI, AI agents, and AI security considerations.