Azure Network and Security Engineer
Job Purpose The Azure Network & Security Engineer will be a key technical resource for Azure network and security functions, supporting the organization's strategy for network segmentation, perimeter defense, identity-centric security, and threat detection. The Azure Network & Security Engineer will collaborate closely with cloud engineering, application development, compliance, and business stakeholders to enforce a zero-trust security posture, maintain regulatory compliance, and deliver a resilient and auditable network infrastructure across the enterprise Azure environment.
Duties & Responsibilities
- Design, deploy, and manage Azure network architectures including Hub-and-Spoke, Virtual WAN, VNets, subnets, peering, routing, and hybrid connectivity (ExpressRoute, Site-to-Site/Point-to-Site VPNs)
- Implement and manage Azure network security services including Azure Firewall, Web Application Firewall (WAF), DDoS Protection, NSGs, Private Endpoints, Private DNS, and Service Endpoints to secure cloud connectivity
- Deploy and manage Microsoft Defender for Cloud, Defender for Endpoint, and Microsoft Sentinel, developing detection rules, automation, threat hunting, and incident response capabilities
- Implement Azure security governance through Azure Policy, RBAC, security baselines, and compliance controls aligned with HIPAA, SOC 2, PCI-DSS, and NIST requirements
- Monitor and troubleshoot network and security environments using Azure Monitor, Network Watcher, Log Analytics, and Connection Monitor to ensure performance, availability, and security
- Conduct vulnerability assessments, support threat modeling, and coordinate remediation efforts across infrastructure and application teams
- Develop and maintain network security documentation, including architecture diagrams, firewall standards, data flows, and operational runbooks
- Partner with DevOps and cloud engineering teams to integrate security into CI/CD pipelines and advance DevSecOps practices
- Evaluate emerging Azure networking and security technologies to continuously strengthen the organization's cloud security posture
- Support internal and external audits by providing security evidence, documentation, risk assessments, and compliance artifacts
- Other duties as assigned
- Use, protect and disclose patients’ protected health information (PHI) only in accordance with Health Insurance Portability and Accountability Act (HIPAA) standards
- Understand and comply with Information Security and HIPAA policies and procedures at all times
- Limit viewing of PHI to the absolute minimum as necessary to perform assigned duties
Required Qualifications
- Bachelor's Degree in Computer Science, Information Technology, Cybersecurity, Engineering, or a related field, or equivalent professional experience
- 5+ years of IT experience with 3+ years in an Azure network engineering or cloud security engineering role
- Solid expertise in Azure networking: Virtual Networks, NSGs, Azure Firewall, Application Gateway, Azure Front Door, Load Balancers, Traffic Manager, ExpressRoute, and VPN Gateway
- Proficiency in Azure Private Endpoint, Private DNS, Service Endpoints, and network segmentation strategies
- Hands-on experience with Microsoft Defender for Cloud, Microsoft Sentinel (SIEM/SOAR), and Azure Security Center for threat detection and security posture management
- Working knowledge of Microsoft Entra ID (Azure AD): Conditional Access, PIM, Identity Protection, MFA, and SSO/federation
- Understanding of zero-trust architecture principles and their practical implementation within Azure environments
- Experience with Azure DDoS Protection Standard, Web Application Firewall (WAF) policies, and bot protection configurations
- Familiarity with regulatory and compliance frameworks: HIPAA, SOC 2, PCI-DSS, NIST CSF, and CIS Azure Benchmarks
- Proficiency in scripting and automation: PowerShell, Azure CLI, and/or Python for security and network operations tasks
- Expe