Senior Azure Cloud Security Engineer (Argentina)

Senior Azure Cloud Security Engineer (Argentina)

21 ago
|
Group 107
|
Argentina

21 ago

Group 107

Argentina

Project overview

We are looking for a Senior Azure Cloud Security Engineer to join Group107 project. You will strengthen and scale the cloud network and identity security of a mature, cloud-native fintech platform serving institutional fixed-income clients across the US, Europe, and Latin America. Working directly with engineering leadership and the client CTO, you will own the Azure network architecture, deepen the zero-trust posture, and keep the security program aligned with the expectations of enterprise clients and regulatory auditors.

This is a high-ownership role within an established security practice, with a defined two-year-plus roadmap and a strong voice in client-facing security reviews and enterprise onboarding.

Requirements

- Advanced knowledge of Microsoft Azure, with 6+ years in cloud infrastructure or security engineering and at least 3 years focused on Azure.
- Deep hands-on expertise with Azure Firewall Premium, NSGs, Private Link, VNet peering, and hub-spoke / VWAN topology.
- Strong working knowledge of Entra ID (Azure AD), Conditional Access, Privileged Identity Management (PIM), and managed identities.
- Proven experience integrating external identity providers (Okta, Ping Identity, Auth0) with Entra ID via SAML, OIDC, or OAuth 2.0.
- Solid grounding in zero-trust architecture principles and their practical implementation in an Azure-native environment.
- Hands-on delivery of infrastructure changes through Infrastructure as Code (Terraform, Bicep, or ARM), including day-to-day Git workflow — branching, merging, conflict resolution, and PR-based code review.




- Comfortable operating within a CI/CD-driven change process — able to read and modify pipeline definitions (GitHub Actions or Azure DevOps YAML) for network and identity work.
- Experience working in a fast-paced, distributed engineering team using agile methodologies and DevOps practices.
- Advanced English (C1+), with the ability to participate in client interview and security-review meetings.
- Clear written and verbal communication — able to explain technical decisions to non-engineering stakeholders.
- Ownership mindset — comfortable making a design decision and living with its operational consequences.
- Strong collaboration across time zones — works effectively through PR review and asynchronous decision-making.
- Pragmatic — favors incremental, testable changes over big-bang rewrites.
- Mentorship and knowledge sharing within a senior, cross-functional team.

Nice to have

- Background in financial services, FinTech, or other regulated industries.
- Relevant certifications: AZ-500, AZ-700, SC-300, SC-100, SC-200, CISSP, or CCSP.
- Experience supporting enterprise client security reviews or completing vendor due-diligence questionnaires (DDQs).

Responsibilities





- Own and continuously improve the Azure network architecture — VNet topology (hub-spoke or VWAN), NSGs, Azure Firewall Premium, and Private Link / Private Endpoints.
- Drive maturation of the zero-trust model across the Azure environment, including Entra ID Conditional Access, PIM, and workload identity management.
- Design and manage integrations with external identity providers (Okta, Ping Identity, Auth0), including SAML, OIDC, and OAuth 2.0 federation with Entra ID.
- Evaluate and govern ExpressRoute / VPN Gateway configurations for client-dedicated connectivity.
- Maintain and evolve network security controls supporting the SOC 2 Type II program, in partnership with the internal compliance function; provide technical input to SOC 2 audits and client DDQs.
- Codify network and identity configuration through Infrastructure as Code (Terraform, Bicep, or ARM), with clean Git workflows and peer-reviewed pull requests, and embed this work into existing CI/CD pipelines.
- Produce and maintain technical documentation — network diagrams and data-flow maps — and communicate controls clearly to non-engineering stakeholders, including participation in client security conversations.
- Proactively assess and advance the cloud network and identity posture as scale and infrastructure complexity grow.

We offer

- 20 vacation days (workdays)
- 7 sick days
- Personalized career growth
- Internal English classes
- Education reimbursement
- Corporate events and team buildings
- Equipment provided

📌 Senior Azure Cloud Security Engineer (Argentina)
🏢 Group 107
📍 Argentina

Postulate a este anuncio

Muestra tus habilidades a la empresa, rellenar el formulario y deja un toque personal en la carta, ayudará el reclutador en la elección del candidato.

Suscribete a esta alerta:

Recibe por email las nuevas ofertas de trabajo para: senior azure cloud security engineer (argentina) / argentina

Suscribete a esta alerta:

Recibe por email las nuevas ofertas de trabajo para: senior azure cloud security engineer (argentina) / argentina