← Back to jobs
B

Security Controls and Automation Engineer

BlackEdge·Tel Aviv, Israel·en
On-siteFull-timeSecurity EngineeringFinancial Services

Join a financial services organization in a full-time, office-based engineering role connecting security policy and regulations to automated technical controls. Build and operate cloud security configurations as code, CI/CD safeguards, and integrations for continuous compliance monitoring.

Responsibilities

  • Develop and maintain Terraform modules, Azure Policy definitions, and pipeline templates that enforce cloud security baselines.
  • Manage infrastructure changes through Git, pull requests, and code review; detect configuration drift against deployed resources.
  • Integrate security checks into GitHub Actions and Azure DevOps pipelines, including secret, dependency, container, and infrastructure-as-code scanning and environment approval gates.
  • Build API-based automations and integrations that collect security-system data in a centralized control platform, and operate the platform infrastructure.
  • Translate policies and regulatory requirements into measurable controls and define baselines for Azure, Microsoft 365, SaaS applications, data protection, networks, and endpoints.
  • Monitor identities, access, and cloud and application configurations against approved baselines.
  • Identify policy-to-implementation gaps, coordinate remediation with system owners, and develop KPIs, KRIs, and management dashboards.

Requirements

  • At least four years of experience in DevOps, cloud engineering, security engineering, or IAM.
  • Strong hands-on Terraform experience, including module design, state management, and multi-environment deployments.
  • Experience building and maintaining CI/CD pipelines in GitHub Actions or Azure DevOps, including automated cloud infrastructure deployment.
  • Python development experience, plus PowerShell or Bash scripting and REST API and systems integration experience.
  • Experience operating production environments in Azure, AWS, or GCP, including cloud networking, containers, and application security.
  • Hands-on experience with identity and access management, including RBAC, least privilege, PIM, PAM, and access governance.
  • Understanding of security controls, governance, compliance, and risk management, with the ability to turn business and regulatory requirements into measurable technical controls.

Nice to have

  • Experience with Microsoft Entra ID, Microsoft 365, Microsoft Graph API, Defender, Sentinel, Azure Policy, or Azure Landing Zones.
  • Familiarity with DevSecOps tools such as Defender for Cloud, GitHub Advanced Security, Checkov, tfsec, or Trivy.
  • GitOps experience with Flux or Argo CD and production Kubernetes or AKS experience.
  • Experience with CSPM/SSPM or identity governance platforms such as Entra ID Governance, SailPoint, or Saviynt.
  • C#/.NET or Java development experience.
  • Familiarity with SOC operations, data protection and DLP, network security, or endpoint security.
  • Terraform Associate, AZ-400, or AZ-500 certification.
  • Experience in a financial or regulated environment.

Relevance

More opportunities

Similar jobs

The newest open roles in Security Engineering.

Questions, answered

Frequently asked questions