Design, implement, and centrally manage advanced security tooling (SAST, DAST, SCA, Secrets Management) directly within high-volume GitHub Actions and GitLab CI/CD pipelines.
Engineer and enforce security controls for our Azure-native services with a strong emphasis on Managed Identities, Azure Policy, Defender for Cloud, and securing the networking perimeter.
Lead threat modeling sessions and security design reviews for net-new, large-scale applications.
Drive the end-to-end vulnerability lifecycle, from discovery to defining clear, actionable security-focused remediation guidance for development teams.
Embed security checks and best practices into our Infrastructure-as-Code workflows, primarily using Terraform or Bicep.
Define and implement robust access controls and key management strategies utilizing Azure Key Vault and cloud-native identity solutions.
Other duties as assigned.
Requirements
Typically, 5+ years with bachelor's or equivalent.
Hands-on experience securing production workloads in the Microsoft Azure ecosystem.
Deep familiarity with key services like AKS, Azure Functions, App Services, and Azure Firewall/WAF.