Cloud Security Engineer
Listed on 2026-08-12
-
IT/Tech
Cybersecurity, Cloud Computing: Infrastructure & Operations, Information Security & Data Protection
Company Overview
Every firm has a culture – the values, beliefs, methodology, attitudes and standards that reflect an organization’s DNA. But the truly inspiring firms – the game-changers, the industry leaders and the disruptors – have cultures that propel them to innovate and stand out. At Brown Advisory, we aim to be one of those inspired firms. Over the years, we have purposefully built and nurtured our client-first culture.
Brown Advisory is an independent investment management and strategic advisory firm committed to delivering a combination of first-class performance, strategic advice and the highest level of client service. The firm’s clients—including individuals, families, family offices, endowments, foundations, charities, institutions, consultants, and financial intermediaries—are served by over 1,000 colleagues worldwide, all of whom are equity owners of the firm.
Primary emphasis:
Cloud Security Engineer with a specific focus on secure Azure management, application hosting, and cloud control maturity. Blended coverage:
Application Security / Dev Sec Ops Analyst, SaaS security administration, cloud tool operations, SIEM integration support, and third-party application-development security guidance.
- Own day-to-day security engineering for Azure environments, including secure configuration, cloud control hardening, logging, monitoring, and remediation follow-through.
- Partner with Infrastructure and Engineering teams to implement Azure security baselines, secure networking patterns, key management practices, storage protections, and workload guardrails.
- Support Microsoft Defender for Cloud, Azure Policy, Entra-adjacent cloud controls, conditional access inputs, and other Microsoft security capabilities as part of the broader cloud security stack.
- Review Brown Advisory-hosted applications and third-party-developed cloud solutions for secure architecture, authentication, authorization, logging, data protection, and operational readiness.
- Configure and improve security controls for SaaS platforms such as Salesforce, Box, Microsoft 365, and other business-critical cloud applications.
- Support limited Dev Sec Ops activities, including static and dynamic application-security testing coordination, vulnerability triage, and practical remediation guidance for internal and third-party development teams.
- Integrate cloud, SaaS, and application telemetry into SIEM and detection workflows, and partner with Security Operations on actionable alerting and response procedures.
- Maintain sanctioned application lists, cloud security standards, exception records, and implementation documentation in partnership with GRC and technology owners.
- Execute immediate remediation actions where appropriate and coordinate more complex fixes across platform, application, and vendor teams.
- Develop clear reporting on cloud security posture, open risks, remediation progress, and control maturity for security and technology leadership.
- Bachelor's degree in cyber security, computer science, engineering, information systems, or a relevant field, or equivalent professional experience.
- 4-8 years of experience in information security, cloud security, infrastructure security, application security, or a related technical discipline.
- Hands-on experience securing Microsoft Azure environments; financial services or other regulated-industry experience preferred.
- Ability to work independently in a lean team while coordinating across technology, vendor, risk, and business stakeholders.
- Microsoft Azure security certifications, CISSP, CCSP, or other relevant professional designations preferred.
- Azure security architecture, Defender for Cloud, Azure Policy, logging, monitoring, and secure configuration practices.
- Microsoft 365 security and compliance concepts, including integration points with Entra , Purview, Defender, and conditional access.
- SaaS security administration for platforms such as Salesforce, Box, and other enterprise cloud applications.
- Static and dynamic application-security testing concepts, vulnerability triage, and secure SDLC practices.
- SIEM…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).