Security Controls and Automation Engineer
Join a financial services organization in a full-time, office-based engineering role connecting security policy and regulations to automated technical controls. Build and operate cloud security configurations as code, CI/CD safeguards, and integrations for continuous compliance monitoring.
Responsibilities
- Develop and maintain Terraform modules, Azure Policy definitions, and pipeline templates that enforce cloud security baselines.
- Manage infrastructure changes through Git, pull requests, and code review; detect configuration drift against deployed resources.
- Integrate security checks into GitHub Actions and Azure DevOps pipelines, including secret, dependency, container, and infrastructure-as-code scanning and environment approval gates.
- Build API-based automations and integrations that collect security-system data in a centralized control platform, and operate the platform infrastructure.
- Translate policies and regulatory requirements into measurable controls and define baselines for Azure, Microsoft 365, SaaS applications, data protection, networks, and endpoints.
- Monitor identities, access, and cloud and application configurations against approved baselines.
- Identify policy-to-implementation gaps, coordinate remediation with system owners, and develop KPIs, KRIs, and management dashboards.
Requirements
- At least four years of experience in DevOps, cloud engineering, security engineering, or IAM.
- Strong hands-on Terraform experience, including module design, state management, and multi-environment deployments.
- Experience building and maintaining CI/CD pipelines in GitHub Actions or Azure DevOps, including automated cloud infrastructure deployment.
- Python development experience, plus PowerShell or Bash scripting and REST API and systems integration experience.
- Experience operating production environments in Azure, AWS, or GCP, including cloud networking, containers, and application security.
- Hands-on experience with identity and access management, including RBAC, least privilege, PIM, PAM, and access governance.
- Understanding of security controls, governance, compliance, and risk management, with the ability to turn business and regulatory requirements into measurable technical controls.
Nice to have
- Experience with Microsoft Entra ID, Microsoft 365, Microsoft Graph API, Defender, Sentinel, Azure Policy, or Azure Landing Zones.
- Familiarity with DevSecOps tools such as Defender for Cloud, GitHub Advanced Security, Checkov, tfsec, or Trivy.
- GitOps experience with Flux or Argo CD and production Kubernetes or AKS experience.
- Experience with CSPM/SSPM or identity governance platforms such as Entra ID Governance, SailPoint, or Saviynt.
- C#/.NET or Java development experience.
- Familiarity with SOC operations, data protection and DLP, network security, or endpoint security.
- Terraform Associate, AZ-400, or AZ-500 certification.
- Experience in a financial or regulated environment.