The Engineer, Security specializes in designing, implementing, and operating security controls for Azure and Microsoft cloud services. This role is responsible for protecting systems and applications that process, store, or transmit Protected Health Information (PHI), ensuring compliance with HIPAA Security Rule requirements through secure design, monitoring, and continuous risk management. This role focuses on reducing risk through secure architecture, security automation, and continuous monitoring across IaaS, PaaS, and identity workloads. The Engineer partners closely with Infrastructure, DevOps, and Software Engineering teams to embed security-by-design into platforms and delivery pipelines. This role also serves as the primary application security engineering function, partnering with Software Engineering and DevOps to identify, prevent, and remediate application-layer risks throughout the SDLC. This includes secure design reviews, threat modeling, CI/CD security controls, vulnerability remediation, and runtime protection of cloud-native applications.
In addition, the Engineer, Security supports security operations by tuning detections, investigating alerts, and coordinating incident response using Microsoft Defender (including Defender for Cloud and Microsoft Defender XDR) and SIEM/SOAR capabilities such as Microsoft Sentinel. The Engineer helps protect internet-facing applications through Web Application Firewall (WAF) controls and Azure Front Door (AFD) security features, aligning protections to OWASP Top 10 risks. This position contributes to audit readiness and continuous compliance with regulatory standards (e.g., HIPAA, SOC 2, ISO 27001) through evidence collection, control validation, and policy-as-code practices.
How do I make an impact on my team?
What our team expects from you?
What can you expect from Archimedes?
Software Powered by iCIMS
www.icims.com