SECURITY ENGINEER - AZURE | VULNERABILITY REMEDIATION | DEVSECOPS
Location: Remote
Experience: 5+ Years
Employment Type: Contract
Shift: 2PM - 11PM
Key skills: Azure, Azure Security, GitHub Enterprise, Azure DevOps, Automation skills, Vulnerability, and security management skills. Basic Database and Windows management skills and Azure AI skills
Job Description
Job Title:
Security Engineer
Role Summary
We are seeking a hands-on Security Engineer to lead vulnerability remediation across a multi-subscription Azure environment. The role spans infrastructure, application, platform, and identity related findings, including access reviews and exposed credentials. The person will track remediation against defined timelines, support audits and compliance reviews, and report on risk trends from internal, external, and vendor sources. Automation and repeatable processes are central to the work, and the role requires enough technical depth to build and maintain that automation. The person will also support broader security initiatives as priorities shift.
Key Responsibilities
Cloud & Infrastructure Security Remediation
Remediate vulnerabilities across multiple Azure subscriptions. Address findings from: Wiz (CSPM/CNAPP) External scanning platforms (RiskRecon, Security Scorecard, etc.) Investigate and resolve infrastructure-level security risks across: Cloud resources (IaaS / PaaS) Networking components Storage and supporting services.
Vulnerability Management & Patching
Assist in remediation of OS and infrastructure vulnerabilities, including: OS patching and hardening (Windows / Linux) VM OS updates and lifecycle management Identify and address end-of-life (EOL) systems and dependencies. Establish repeatable processes for: Patch management Vulnerability tracking and reporting. Risk prioritization
Application Security Remediation
Partner with development teams to remediate: SAST findings (e.g., Snyk) DAST findings (e.g., Invicti) Open-source library vulnerabilities Penetration Testing Findings Support secure configuration of application environments.
DevSecOps & Automation
Integrate security into Azure DevOps CI/CD pipelines where applicable. Improve overall DevSecOps maturity.
Security Program Support (New)
Support assigned security program initiatives as directed by leadership. Assist with security review documentation for client and audit requests. Contribute to remediation tracking and reporting across security workstreams.
Observability & Reporting
Analyze and prioritize vulnerabilities based on: Severity (CVSS) Exploitability Business impact Provide regular updates on: Remediation progress Risk reduction trends. Outstanding issues
Required Skills & Experience
Core Technical Skills
Strong experience in Microsoft Azure PaaS and IaaS resources, networking, identity, storage Hands-on expertise with: Systems administration and patching (Windows, Linux, etc.) Infrastructure vulnerability remediation Familiarity with: Wiz or similar CSPM/CNAPP tools Vulnerability scanners (Nessus, Qualys, etc.) Azure Policy
Security & DevOps
Experience with: SAST/DAST tools (Snyk, Invicti, etc.) Dependency and open-source vulnerability remediation Understanding of: Cloud security best practices Secure configuration standards (CIS, NIST, etc.)
Nice to Have
Experience with: Azure Automation / Update Management Infrastructure as Code (Terraform, ARM, Bicep, etc.) CI/CD pipelines (Azure DevOps, GitHub Actions, etc.) Penetration Testing Familiarity with: Risk scoring platforms (Security Scorecard, RiskRecon) Monitoring Tools (Data Dog, Grafana, etc.)