Job description
Job Purpose The Azure Network & Security Engineer will be a key technical resource for Azure network and security functions, supporting the organization's strategy for network segmentation, perimeter defense, identity-centric security, and threat detection. The Azure Network & Security Engineer will collaborate closely with cloud engineering, application development, compliance, and business stakeholders to enforce a zero-trust security posture, maintain regulatory compliance, and deliver a resilient and auditable network infrastructure across the enterprise Azure environment.
Duties & Responsibilities
Design, deploy, and manage Azure network architectures including Hub-and-Spoke, Virtual WAN, VNets, subnets, peering, routing, and hybrid connectivity (ExpressRoute, Site-to-Site/Point-to-Site VPNs)
Implement and manage Azure network security services including Azure Firewall, Web Application Firewall (WAF), DDoS Protection, NSGs, Private Endpoints, Private DNS, and Service Endpoints to secure cloud connectivity
Deploy and manage Microsoft Defender for Cloud, Defender for Endpoint, and Microsoft Sentinel, developing detection rules, automation, threat hunting, and incident response capabilities
Implement Azure security governance through Azure Policy, RBAC, security baselines, and compliance controls aligned with HIPAA, SOC 2, PCI-DSS, and NIST requirements
Monitor and troubleshoot network and security environments using Azure Monitor, Network Watcher, Log Analytics, and Connection Monitor to ensure performance, availability, and security
Conduct vulnerability assessments, support threat modeling, and coordinate remediation efforts across infrastructure and application teams
Develop and maintain network security documentation, including architecture diagrams, firewall standards, data flows, and operational runbooks
Partner with DevOps and cloud engineering teams to integrate security into CI/CD pipelines and advance DevSecOps practices
Evaluate emerging Azure networking and security technologies to continuously strengthen the organization's cloud security posture
Support internal and external audits by providing security evidence, documentation, risk assessments, and compliance artifacts
Other duties as assigned
Use, protect and disclose patients’ protected health information (PHI) only in accordance with Health Insurance Portability and Accountability Act (HIPAA) standards
Understand and comply with Information Security and HIPAA policies and procedures at all times
Limit viewing of PHI to the absolute minimum as necessary to perform assigned duties
Required Qualifications
Bachelor's Degree in Computer Science, Information Technology, Cybersecurity, Engineering, or a related field, or equivalent professional experience
5+ years of IT experience with 3+ years in an Azure network engineering or cloud security engineering role
Solid expertise in Azure networking: Virtual Networks, NSGs, Azure Firewall, Application Gateway, Azure Front Door, Load Balancers, Traffic Manager, ExpressRoute, and VPN Gateway
Proficiency in Azure Private Endpoint, Private DNS, Service Endpoints, and network segmentation strategies
Hands-on experience with Microsoft Defender for Cloud, Microsoft Sentinel (SIEM/SOAR), and Azure Security Center for threat detection and security posture management
Working knowledge of Microsoft Entra ID (Azure AD): Conditional Access, PIM, Identity Protection, MFA, and SSO/federation
Understanding of zero-trust architecture principles and their practical implementation within Azure environments
Experience with Azure DDoS Protection Standard, Web Application Firewall (WAF) policies, and bot protection configurations
Familiarity with regulatory and compliance frameworks: HIPAA, SOC 2, PCI-DSS, NIST CSF, and CIS Azure Benchmarks
Proficiency in scripting and automation: PowerShell, Azure CLI, and/or Python for security and network operations tasks
Experience with Infrastructure-as-Code (IaC) using Terraform or Bicep for network and security resource deployment
Proficiency in Microsoft Office Suite
Strong interpersonal skills, ability to communicate well at all levels of the organization
Strong problem solving and creative skills and the ability to exercise sound judgment and make decisions based on accurate and timely analyses
High level of integrity and dependability with a strong sense of urgency and results oriented
Excellent written and verbal communication skills required
Preferred Qualifications
Microsoft certifications
Experience with Microsoft Sentinel SOAR playbooks (Logic Apps) and automated incident response orchestration
Familiarity with multi-cloud network and security architectures spanning Azure and AWS.
Experience implementing DevSecOps practices — integrating security scanning, policy-as-code, and network compliance checks into CI/CD pipelines
Knowledge of SIEM/SOAR platforms beyond Sentinel (e.g., Splunk, QRadar) and experience with log ingestion and correlation
Experience with Azure Virtual Desktop (AVD) network and security design considerations
Familiarity with CIS Azure Benchmarks, Azure Security Benchmark, and NIST 800-53 control mapping
Experience with certificate lifecycle management, PKI, and Azure Key Vault for secrets and cryptographic key management
Familiarity with Jira, Confluence, or similar project management and documentation tools
Working Conditions
Ability to work outside of normal business hours and/or be on call as needed
Occasional travel to other company locations required
Must possess a smart-phone or electronic device capable of downloading applications, for multifactor authentication and security purposes
Physical Demands: While performing the duties of this job, the employee is occasionally required to move around the work area; Sit; perform manual tasks; operate tools and other office equipment such as computer, computer peripherals and telephones; extend arms; kneel; talk and hear
Mental Demands: The employee must be able to follow directions, collaborate with others, and handle stress
Work Environment: The noise level in the work environment is usually minimal
Med-Metrix will not discriminate against any employee or applicant for employment because of race, color, religion, sex (including pregnancy, gender identity, and sexual orientation), parental status, national origin, age, disability, genetic information (including family medical history), political affiliation, military service, veteran status, other non-merit based factors, or any other characteristic protected by federal, state or local law.
Originally posted on Himalayas
Who can apply
The source lists worldwide eligibility. Accepted UTC offsets: UTC-11, UTC-10, UTC-9.5, UTC-9, UTC-8, UTC-7, UTC-6, UTC-5, UTC-4, UTC-3.5, UTC-3, UTC-2, UTC-1, UTC+0, UTC+1, UTC+2, UTC+3, UTC+3.5, UTC+4, UTC+4.5, UTC+5, UTC+5.5, UTC+5.75, UTC+6, UTC+6.5, UTC+7, UTC+8, UTC+8.75, UTC+9, UTC+9.5, UTC+10, UTC+10.5, UTC+11, UTC+12, UTC+12.75, UTC+13, UTC+14. Review the full description for employer-specific work authorization, residency and schedule requirements.