onsite
US LBM Cybersecurity Engineer - Azure DevSecOps - US LBM Holdings
Security Engineer
We're looking for a Security Engineer focused on designing and building scalable technical solutions. This mid level role requires 4+ years of relevant experience.
About the role
- Implement and manage Microsoft Defender for Cloud (CNAPP) across Azure workloads, covering both cloud security posture management (CSPM) and cloud workload protection (CWPP) for virtual machines, Azure Kubernetes Service (AKS) containers, and serverless functions.
- Own the DevSecOps program using Snyk for SAST, DAST, and software composition analysis (SCA), integrated directly into CI/CD pipelines (Azure DevOps, GitHub Actions).
- Write and maintain Infrastructure as Code (Terraform, Bicep, ARM templates) with security controls embedded by default - policy-as-code and guardrails rather than after-the-fact review.
- Secure data platform integrations between Azure workloads and downstream data services, including Azure-native platforms (Cosmos DB), third-party managed databases (MongoDB Atlas), streaming platforms (RedPanda), and SaaS data warehouses (Snowflake), covering identity/access boundaries, encryption, and data flow security.
- Secure containerized workloads running on Azure Kubernetes Service (AKS), including cluster hardening, workload identity, network policy, and image scanning integrated into the CI/CD pipeline.
- Partner directly with application developers to embed security into the software development lifecycle - code review participation, secure coding guidance, and remediation support for vulnerabilities identified by Snyk.
- Build and maintain custom tooling, scripts, and APIs to automate security checks, policy enforcement, and reporting across the cloud-native environment.
- Conduct threat modeling for cloud-native workloads and their data integrations, developing corresponding detection and automation use cases.
- Evaluate and integrate new cloud-native and data platform technologies as the organization's architecture evolves, including technology integration from mergers and acquisitions.
- Secure the adoption of AI-assisted development tools (e.g., Cursor, Claude Code) and AI agent/model platforms (e.g., Azure AI Foundry), including governance of code and secrets exposure, access scoping for AI coding agents, and safe integration of AI-generated code into the CI/CD pipeline.
- Ensure DevSecOps and cloud-native practices align with Zero Trust and NIST Cybersecurity Framework principles.
- May design and build internal web applications for the Cybersecurity Solutions team, such as security reporting dashboards, self-service tooling, and workflow automation portals.
- Prior experience as a software engineer, DevOps engineer, or platform engineer - hands-on coding experience is required, not just security tooling experience.
- Proficiency in at least one modern programming language (Python, C#/.NET, Go, or JavaScript/TypeScript) - able to read, write, and debug application code.