Clean Power Alliance logo
Clean Power AlliancePosted 1 month ago

Engineer, Cloud Security

HybridLos Angeles, California, United States

Full TimeSenior LevelBachelors DegreeSmall

Job Summary

Architect, implement, and administer enterprise security solutions across Microsoft platforms including Entra ID, Defender XDR, Intune, Sentinel, and Purview. Lead cybersecurity architecture and incident response operations, developing detection content, response playbooks, and automation to reduce mean time to detect and respond. Direct vulnerability management, threat intelligence, and security monitoring programs while managing managed security service providers and vendor oversight. Develop and maintain cybersecurity policies, standards, and technical roadmaps aligned with the NIST Cybersecurity Framework. Serve as the advisor on cybersecurity risk and emerging threats, partnering with departments to evaluate security implications of new tools and business processes. Secure CPA's public-facing web properties and customer portals by managing secure configuration, vulnerability remediation, and third-party vendor risk. Create, enhance, and manage continuous improvement initiatives across the security program to enable team scaling and system optimization.

Required Qualifications

  • Proficient with Microsoft Office Suite
  • Ability to act with integrity, professionalism, and confidentiality
  • Ability to fully own tasks and processes with minimal oversight
  • Ability to handle multiple priorities to meet deadlines and escalate key issues
  • Proficient with data visualization tools and software (i.e., Tableau, Power BI)
  • Strong hands-on experience administering Microsoft Entra ID, including identity governance, conditional access, and privileged identity management
  • Deep expertise with Microsoft Defender XDR (Defender for Endpoint, Identity, Office 365, and Cloud) for threat detection and response
  • Proven experience designing and operating Microsoft Sentinel for SIEM, including KQL, analytics rules, workbooks, and automation
  • Hands-on experience with Microsoft Intune for endpoint management, configuration profiles, compliance policies, and application protection
  • Working knowledge of Microsoft Purview for data classification, data loss prevention (DLP), insider risk, and information protection
  • Strong understanding of cloud security posture management, including Microsoft Defender for Cloud and secure configuration baselines
  • Practical experience applying the NIST Cybersecurity Framework and supporting controls aligned to NIST 800-53 or 800-171
  • Experience with vulnerability management, threat intelligence, and incident response operations
  • Well-versed in cloud environments, identity and access management, endpoint security, network security, best-practice security governance, data privacy regulations, and zero-trust architecture principles
  • Deep understanding of the interactions between systems and how business processes are enabled and impacted by those systems
  • Experience or coursework with cloud platform security services, especially Amazon Web Services; cloud-native security tooling; Windows and Linux endpoint hardening; SQL databases
  • Candidates must have a bachelor's degree in information technology, computer science, information systems, cybersecurity, or a related field
  • Must have a minimum of 5 years of experience in cybersecurity, cloud security, or enterprise IT security work
  • Must hold at least one relevant industry cybersecurity certification (e.g., Microsoft SC-100, SC-200, SC-300, AZ-500, CISSP, CISM, or GIAC) or obtain one within 6–12 months of hire
  • Maintain current, relevant security certifications and stay abreast of evolving Microsoft security platforms, threat trends, and regulatory requirements through ongoing professional development
  • Must be able to work at a desk and on a computer for prolonged periods
  • This position is eligible for either Hybrid or Remote options. The Hybrid option requires 2-3 assigned full-time days in the Downtown Los Angeles office and includes a transportation allowance
  • The Remote & Hybrid options require full-time in-person attendance at organization or team-wide events 3 times per year for 3-5 days per event
  • All staff are required to work during CPA's office hours Monday-Friday 8:30am-5:30pm PST

Desired Qualifications

  • Experience supporting a regulated industry (energy, utilities, financial services, healthcare, or public sector) and start-up experience is highly desired
  • Additional certifications across these tracks are highly desired

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce