Summary
What you’ll impact
The Senior Security Engineer at the organization will serve as the dedicated security owner for the Azure platform, handling security reviews, posture management, detection and incident response, identity and endpoint security, and day‑to‑day SOC 2 compliance. Reporting to the Security Lead, the role is a senior individual contributor focused on security and compliance, partnering with engineering, IT, and compliance teams.
Responsibilities
What you'll do
- Security reviews & posture. Review architecture and changes for security impact, keep our security baselines and policies current, and run posture management across the environment (Defender for Cloud), driving findings through to remediation.
- Detection & incident response. Own detection engineering and IR day to day — KQL detections in Log Analytics, Azure Monitor dashboards, SIEM forwarding via Event Hub, and incident.io alerting and runbooks. The Security Lead steps in as incident commander for major events.
- Identity & endpoint security. Own Entra ID Conditional Access (device-based policies, Enterprise SSO) and our EDR estate — SentinelOne (primary on macOS), Microsoft Defender (Windows), and the remaining Sophos footprint. Define the device-security baselines that compliant endpoints must meet.
- Compliance (SOC 2 / Drata). Own our SOC 2 Type II program day to day in Drata — evidence collection, control monitoring, customer security questionnaires, and vendor / third-party risk — partnering with security, IT, and engineering. This is the security–to–compliance bridge, and may grow into a dedicated compliance role as we scale.
- Cloud & Azure security. Shape posture, guardrails, and Defender for Cloud coverage together with the Security Lead.
- Security as code. Define the security requirements and guardrails that get implemented in our Pulumi (Go) IaC, and review and contribute to that code. Building and operating the infrastructure is owned by the team today, with a future DevSecOps hire — you set and verify the security bar, you don’t own the build.
- Device management. A separate IT hire owns Microsoft Intune and patching; you set the device-security baselines (compliance policies, LAPS, BitLocker/FileVault, ASR rules, removable-media controls) and partner on patch posture.
Requirements
What you’ll bring
- Cloud security depth (Azure). Hands-on securing Azure — identity (Entra ID, RBAC, managed identities, PIM), network, and secrets / key management (Key Vault, customer-managed keys).
- Identity & endpoint. Practical experience with Entra Conditional Access and at least one major EDR platform (SentinelOne, Microsoft Defender, or equivalent).
- Detection & IR. Detection-engineering and incident-response experience, including writing KQL against Log Analytics or a comparable SIEM, and running investigations end to end.
- Security reviews & policy. Experience running security and architecture reviews and maintaining security policies and posture.
- Compliance. SOC 2 Type II experience, ideally hands-on with Drata or a comparable platform — comfortable owning evidence, controls, and customer security questionnaires.
- Ownership. A senior IC who can run the security function independently and partner across engineering, IT, and compliance.