Sidley Austin LLP-posted 3 months ago
$127,000 - $147,000/Yr
Mid Level
Chicago, IL
1,001-5,000 employees

The Cloud Security Engineer is primarily responsible for designing, implementing, and supporting secure Microsoft Azure cloud environments for the Firm. This individual will ensure that cloud-based development platforms, APIs, and applications follow best practices, regulatory requirements, and Firm-specific policies to protect sensitive Client and Firm data. The Cloud Security Engineer acts as a subject matter expert, collaborating with cross-functional teams to establish secure coding, deployment, and data management processes. This role also participates in security incident response activities related to cloud infrastructure and applications, ensuring timely detection, containment, and remediation of potential threats. This person will also contribute to our overall Cloud Security Strategy.

  • Design, configure, and maintain secure Microsoft Azure environments aligned with industry best practices and Firm policies.
  • Implement and manage cloud security controls, including identity and access management, network segmentation, encryption, and security monitoring.
  • Protect sensitive data stored or processed in the cloud through encryption, access controls, and secure key management.
  • Develop, enforce, and maintain secure API management processes, including authentication, authorization, rate limiting, and auditing.
  • Build and maintain secure DevSecOps pipelines, ensuring that only reviewed, tested, and approved code is promoted to production.
  • Integrate automated security testing and vulnerability scanning into Continuous Integration / Continuous Delivery (CI/CD) workflows.
  • Collaborate with application developers, infrastructure engineers, and security teams to ensure secure design and deployment practices.
  • Create and maintain documentation, standards, and procedures for cloud security configurations, incident handling, and code promotion processes.
  • Monitor and respond to security alerts from cloud-native tools and third-party monitoring solutions.
  • Participate in risk assessments, audits, and compliance efforts related to cloud security (e.g., ISO 27001, GDPR, CCPA).
  • Stay current with emerging cloud security threats, vulnerabilities, and evolving best practices, especially within the Microsoft Azure ecosystem.
  • Bachelor’s degree with a preference for those with a degree in Computer Science, Information Security, Technology or a related field.
  • Minimum of 3 years of experience in cloud security engineering, with a strong focus on Microsoft Azure.
  • Hands-on experience with Azure security services (e.g., Azure Security Center, Defender for Cloud, Key Vault, Azure AD, Application Gateway, API Management).
  • Experience designing and managing secure DevSecOps pipelines using Azure DevOps or equivalent tools.
  • Strong understanding of cloud-based network security, encryption, and identity management best practices.
  • Demonstrated ability to assess, troubleshoot, and remediate security issues in cloud environments.
  • Relevant cloud and security certifications (e.g., Microsoft Certified: Azure Security Engineer Associate (AZ 500), Microsoft Certified: Azure Solutions Architect Expert, CISSP, CCSP, Security+).
  • Experience in the legal, financial, or other highly regulated industries.
  • Familiarity with AWS and Google a plus.
  • Comprehensive benefits program including bonus eligibility.
  • Salaries vary by location and are based on numerous factors, including market, skills, experience, and education.
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service