Used Tools & Technologies
Machine LearningRequired Skills & Competences
Tag name is followed by "@" symbol and proficiency level value.
About proficiency levels:
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
Security @ 3
Docker @ 3
Kubernetes @ 3
Vault @ 3
DevOps @ 3
IaC @ 3
Terraform @ 5
CI/CD @ 3
AWS @ 3
Azure @ 3
Communication @ 3
PowerShell @ 5
Compliance @ 3
AI @ 3
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
Details
xAI is seeking an Azure Security Engineer to design, implement, and maintain security controls across Azure Government (including hybrid and multi-cloud scenarios). This is a hands-on role to build and maintain cloud security posture, protect workloads, and collaborate with engineering, DevOps, and compliance teams to embed security throughout the development lifecycle. The role requires leveraging Microsoft native security tools, detecting threats, responding to incidents, and achieving/maintaining compliance with government regulations such as FedRAMP and CMMC.
Responsibilities
- Implement, design, and manage security architecture for Azure Government and Commercial deployments (with considerations for DoD IL5/IL6 and FedRAMP High controls)
- Configure and optimize Microsoft Defender for Cloud, Microsoft Sentinel, Microsoft Defender for Endpoint, and related services for threat detection, vulnerability management, and automated response
- Design and enforce identity & access management using Microsoft Entra ID, Privileged Identity Management (PIM), Conditional Access policies, RBAC, and just-in-time access
- Secure network architectures with Azure Firewall, Network Security Groups (NSGs), DDoS Protection, Web Application Firewall (WAF), Network Watcher, and private endpoints
- Protect data at rest and in transit via Azure Key Vault, encryption strategies, data classification, and information protection controls
- Develop and maintain security policies, initiatives, and blueprints using Azure Policy and Microsoft Purview for compliance (NIST, FedRAMP, CMMC, STIGs, etc.)
- Perform threat hunting, incident response, and forensics using Sentinel playbooks, Log Analytics, and KQL queries
- Conduct security reviews of Infrastructure as Code (IaC), containers, Kubernetes (AKS), and serverless workloads
- Collaborate with developers and architects to implement DevSecOps practices, including secure CI/CD pipelines, code scanning, and secure defaults
- Monitor and remediate security findings, reduce attack surface, and improve overall security posture per the Microsoft Cloud Security Benchmark (MCSB)
- Deploy configurations and compliance policies to Azure AVD endpoints using Intune and other Azure native services
Requirements
- Active U.S. security clearance (e.g., Secret, Top Secret) or eligibility to obtain one
- 3+ years of experience in cloud security, cybersecurity engineering, or related roles with a strong Azure focus
- Deep hands-on expertise with core Azure security services: Microsoft Defender suite, Sentinel, Intune, Entra ID, Key Vault, Azure Policy, Firewall, Network Watcher, and Purview
- Strong understanding of DLP implementation both in cloud and on endpoints utilizing Purview and other Microsoft native controls
- Experience implementing security in hybrid/multi-cloud environments
- Proficiency in scripting/automation: PowerShell, Azure CLI, Bicep/ARM templates, Terraform
- Strong understanding of identity federation, zero-trust principles, encryption, network security, and vulnerability management
- Familiarity with compliance frameworks (NIST, FedRAMP, CMMC, STIGs, etc.) and regulatory requirements
- Excellent problem-solving, analytical, and communication skills; ability to stay composed under pressure
Preferred Skills and Experience
- Microsoft Certified: Azure Security Engineer Associate (AZ-500), Microsoft Cybersecurity Architect (SC-100)
- Additional relevant certifications (e.g., CISSP, CCSP, Microsoft Certified: Azure Administrator, AWS Security Specialty, SANS GCPS, SANS GCAD)
- Deep experience with detection and response engineering and SOC operations
- Knowledge of container security (Docker, AKS), secure DevOps, or AI/ML workload protection
- Prior experience in government regulations frameworks such as FedRAMP and CMMC
ITAR Requirements
To conform to U.S. Government export regulations, applicant must be a (i) U.S. citizen or national, (ii) U.S. lawful, permanent resident (aka green card holder), (iii) Refugee under 8 U.S.C. § 1157, or (iv) Asylee under 8 U.S.C. § 1158, or be eligible to obtain the required authorizations from the U.S. Department of State.
Compensation and Benefits
$180,000 - $440,000 USD
Base salary is one part of the total rewards package, which also includes equity, medical/vision/dental coverage, access to a 401(k), short & long-term disability insurance, life insurance, and other perks.