
Cloud Security Engineer (Azure)
Primary stack
Job description
About the Position
We are seeking an Azure Security Engineer. You will implement and improve cloud, identity, and endpoint controls in a regulated hedge fund environment. Based in Malaysia, you will support Singapore and regional offices by turning security designs into production-ready configurations across Entra ID, Microsoft Defender, Intune, and Azure Firewall, with a focus on hardening, testing, and documentation.
Responsibilities
- Configure and maintain Microsoft Entra ID controls including Conditional Access, multi-factor authentication (MFA), and Privileged Identity Management (PIM) workflows
- Build and improve Azure security controls including Microsoft Defender for Cloud, Azure Firewall, and network segmentation in a hub-and-spoke design
- Manage endpoint security baselines in Microsoft Intune and Microsoft Defender for Endpoint, resolving configuration drift
- Implement security designs from the Security Architect through secure, reliable production configurations
- Perform configuration reviews and hardening aligned to CIS Controls v8 and internal standards
- Remediate findings from vulnerability scans, security assessments, and technical reviews within agreed service levels
- Partner with Engineering, Security Operations, and Governance teams on changes, control tuning, escalations, and audit needs
- Maintain documentation and standard operating procedures (SOPs), test control effectiveness, and recommend improvements
Requirements
- Hands-on experience implementing cloud, identity, and endpoint security controls in production
- Practical knowledge of Microsoft Azure security services including Microsoft Entra ID, Conditional Access, Privileged Identity Management (PIM), Microsoft Defender for Cloud, Microsoft Defender for Endpoint, and Azure Firewall
- Experience configuring device and endpoint controls through Microsoft Intune
- Understanding of vulnerability management tools and remediation workflows such as Nessus, Microsoft Defender, or equivalent
- Familiarity with hardening frameworks such as CIS Controls v8 or equivalent standards
- Ability to translate security designs into secure, maintainable configurations and operating procedures
- Strong skills in troubleshooting, testing, and documentation with accurate configuration records
- Clear collaboration across Security Architecture, Security Operations, Governance, and Engineering teams
Nice to Have
- Experience in financial services, investment management, or another regulated environment
- Exposure to Microsoft Sentinel, Microsoft Defender XDR, Microsoft Purview Data Loss Prevention (DLP), MAS Technology Risk Management (TRM), or MAS Notice 658
- Microsoft certifications such as SC-100, SC-300, or AZ-500, or cloud security certifications such as CCSP or CISSP
We Offer
- Opportunity to work in a regulated hedge fund environment
- Collaborate with a diverse team of Security Architecture, Security Operations, Governance, and Engineering professionals
- Professional growth and development opportunities
About the Company
[Company description if present]
© EPAM. This job description was sourced from the employer's public career page. TheJob is not the employer — we index the posting and route candidates to the source. All content rights and hiring decisions belong to the employer.
EPAM helps organizations innovate their business processes and rethink the way they manage their businesses so they can remain competitive in this new digital age.
More at EPAM
All 2384 roles
Lead Full-Stack Developer
EPAM · Argentina +1

Python Engineering Manager
EPAM · Mexico

Product Manager
EPAM · Argentina +2

Automation Tester (JavaScript)
EPAM · Brazil
