Cloud Security Engineer T&M
Mexico City - Mexico
Job Summary
At Sequoia Connect we are a Talent-First Technology Ecosystem that redefines how elite professionals interact with the global digital landscape. We move beyond traditional models to act as a catalyst for the top 1% of global talent connecting human potential with complex industrial execution. By joining our inner circle you are not simply taking a position; you are aligning with a strategic partner dedicated to updating your Human OS and accelerating your growth through world-class high-impact projects.
We are currently partnering with a global IT powerhouse that represents the connected world through innovative customer-centric experiences. As a USD 6 billion organization and one of the top 7 IT service providers globally our client empowers over 1200 global customersincluding several Fortune 500 companiesto Rise. With a massive network of 163000 professionals across 90 countries they are at the absolute forefront of digital transformation leveraging next-generation technologies such as 5G AI Blockchain and Quantum Computing.
This is your chance to thrive in a workplace recognized as one of the most sustainable corporations in the world. You will join an environment that values innovation and societal impact working on end-to-end digital transformation projects for global leaders. If you are a driven professional looking for global career opportunities and exposure to high-impact projects within an international network of expertise this is where you belong.
We are currently searching for a Cloud Security Engineer T&M:
The Challenge (Responsibilities)
- Own the full lifecycle of security findings and recommendationsfrom Our Clients security team Microsoft Defender for Cloud or other toolingthrough triage remediation verification and closure.
- Root-cause recurring issues and implement systemic fixes (policy-as-code automated guardrails secure baselines) to prevent findings from reappearing.
- Track remediation SLAs and report on risk reduction and posture trends over time.
- Secure and govern modern authentication flows across the estate: OIDC OAuth 2.0 with PKCE JWT validation and handling and mTLS.
- Administer and harden Microsoft Entra ID: app registrations and Enterprise Application permissions consent governance service principals and managed identities credential and secret hygiene and least-privilege scoping.
- Design implement and continuously tune Conditional Access policies.
- Build and enforce guardrails using Azure Policy and Terraform; maintain secure-by-default infrastructure-as-code baselines and detect/remediate configuration drift.
- Operate Microsoft Defender for Cloud to drive secure-score improvement remediate recommendations and manage cloud security posture (CSPM).
- Contribute to security governance: standards control definitions exception handling and audit evidence.
- Secure all cloud and SaaS administrative portals including Azure Microsoft 365 admin and identity providers.
- Strengthen privileged access through MFA enforcement Privileged Identity Management (PIM) / just-in-time elevation role minimization and break-glass procedures.
- Apply security controls to AI workloads services and AI agents including agent/workload identities tool and permission scoping and mitigating data-exposure and prompt-injection risks.
Your Profile (Requirements)
- 5 years in cloud security or security engineering with deep hands-on Azure experience.
- Strong hands-on Microsoft Entra ID expertise: app registrations Enterprise Apps permissions and consent and Conditional Access.
- Solid working knowledge of modern authentication: OIDC OAuth 2.0 / PKCE JWT and mTLS.
- Proficiency with Terraform and Azure Policy for policy-as-code and automated guardrails.
- Experience with Microsoft Defender for Cloud and cloud security posture management.
- A demonstrable track record of root-causing and permanently closing security findingsnot just patching them.
- Working understanding of AI AI agents and AI security considerations.
- High-Performance Mindset: Resilience emotional intelligence and a focus on agile delivery.
- Technologist DNA: A deep understanding of the difference between coding and engineering.
Desired
- Multi-cloud exposure (AWS GCP).
- Relevant certifications (e.g. Microsoft SC-100 AZ-500 SC-300; CISSP).
- Experience with CI/CD pipeline security secrets management and SIEM/SOAR.
- Scripting/automation proficiency with PowerShell or Python.
- Hands-on experience securing LLM-based or agentic systems in production.
- Familiarity with cloud-native foundations or AI coding assistants.
Languages
- Advanced Oral English: For seamless collaboration with global teams.
- Advanced Spanish.
Special Notes
- This is a hands-on engineering and remediation role not an advisory position. Success is measured by a measurably more secure environment and a shrinking backlog of recurring findings enforced by design.
Work Arrangement
We value flexibility to support your lifestyle. This position is available as:
- Remote
If you meet these qualifications and are pursuing new challenges start your application on our website to join an award-winning employer. Explore all our job openings Sequoia Careers Page: Requirements:
Azure Microsoft Entra ID Terraform OIDC Microsoft Defender