- Company Name
- CAI
- Job Title
- Systems Engineer
- Job Description
-
**Job Title**
Systems Engineer
**Role Summary**
Responsible for strengthening hybrid cloud security across Active Directory, Microsoft Azure AD, and Google Cloud Platform. Drives IAM program enhancements, performs security assessments, configures controls in on‑prem and cloud environments, and collaborates with security teams to onboard products into Microsoft Sentinel.
**Expectations**
* 3+ years in cloud security engineering or IAM administration/engineering.
* Hands‑on experience with AD, Microsoft Graph, PowerShell, LDAP, Azure Security (Entra ID, Defender for Cloud, conditional access, PIM), and Google Cloud IAM/security tools.
* Proven ability to configure, monitor, and maintain security controls and incident response processes.
* Strong communication and collaboration skills with technicians, analysts, and leadership.
* Knowledge of compliance frameworks (NIST CSF, CIS Controls, ISO 27001) preferred.
* Relevant certifications (Azure Security Engineer Associate, Google Professional Cloud Security Engineer, Security+, MCSA, etc.) are a plus.
**Key Responsibilities**
* Conduct daily account provisioning audits and corrections across tenants using LDAP, PowerShell, and Microsoft Graph.
* Perform regular cloud and IAM security assessments, ensuring compliance with industry standards and internal policies.
* Improve and maintain security configurations, policies, and controls in hybrid Microsoft and Google environments.
* Enhance IAM capabilities: user lifecycle management, RBAC, privileged access management, conditional access policies.
* Collaborate with security staff to onboard and integrate cloud and third‑party security solutions into Microsoft Sentinel.
* Develop and refine analytic rules, playbooks, and dashboards in Microsoft Sentinel for threat detection and response.
* Assist incident investigations by optimizing logging, monitoring, and reporting from cloud services and IAM systems.
* Provide guidance on IAM best practices, security governance, and SIEM operations to technicians.
**Required Skills**
* Active Directory, Microsoft Graph, PowerShell, LDAP operations.
* Azure Security (Entra ID, Defender for Cloud, conditional access, PIM).
* Google Cloud IAM/security tools.
* Microsoft Sentinel: log ingestion, use‑case development, rule creation.
* IAM platform expertise (Azure Entra ID, Google Admin Console).
* SIEM onboarding (connectors, custom log sources).
* Incident response, threat detection, and security monitoring fundamentals.
**Preferred Skills**
* Scripting/automation (PowerShell, Python) for IAM and SIEM tasks.
* Familiarity with NIST CSF, CIS Controls, ISO 27001 compliance frameworks.
* Strong written and verbal communication.
**Required Education & Certifications**
* Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or related field (or equivalent experience).
* Certifications: Azure Security Engineer Associate, Google Professional Cloud Security Engineer, Security+, MCSA, or similar are highly desirable.