- 5+ years in cloud security or security engineering, with deep, hands-on Azure experience.
- Strong, hands-on Microsoft Entra ID expertise: app registrations, Enterprise Apps, permissions and consent, and Conditional Access
- Solid working knowledge of modern authentication: OIDC, OAuth 2.0 / PKCE, JWT, and mTLS.
- Proficiency with Terraform and Azure Policy for policy-as-code and automated guardrails.
- Experience with Microsoft Defender for Cloud and cloud security posture management.
- A demonstrable track record of root-causing and permanently closing security findings—not just patching them.
- Working understanding of AI, AI agents, and AI security considerations.
Nice to Have
- Multi-cloud exposure (AWS, GCP).
- Relevant certifications (e.g., Microsoft SC-100, AZ-500, SC-300; CISSP).
- Experience with CI/CD pipeline security, secrets management, and SIEM/SOAR.
- Scripting/automation (PowerShell, Python).
Hands-on experience securing LLM-based or agentic systems in production.