About the role
What will you do at OneStream Software?
Cloud Security Engineer
Location: Remote, USA
Employment Type: Full-Time
Benefits
Offered: Vision, Medical, Life, Dental, 401K
Gross annual base salary: USD 86,000 – 112,000
Additional variable compensation and benefits may apply. Total compensation is
based on experience, skills, and location using objective, job-related criteria.
Summary
We are seeking a Cloud Security Engineer to join our Information Security team
and play a key role in protecting and continuously improving the security
posture of OneStream’s cloud environment, including Microsoft Azure and
Microsoft 365. This position is responsible for helping safeguard OneStream’s
cloud services, corporate information, and customer data by identifying and
mitigating risk through proactive security monitoring, threat detection,
vulnerability management, secure configuration, and cloud security governance.
This role works closely with cross-functional teams to help ensure cloud
technologies and services are deployed and operated securely in alignment with
business and security objectives.
Primary Duties and Responsibilities
* Design, implement, and continuously improve security controls and
configuration baselines across Microsoft Azure and Microsoft 365, aligned
with industry standards and frameworks.
* Configure, administer, and optimize cloud security solutions, including
Microsoft Defender for Cloud, Microsoft Defender for Endpoint, Microsoft
Defender for Cloud Apps (CASB), and related technologies.
* Conduct security assessments of cloud resources, applications, Azure
Kubernetes Service (AKS), and containerized workloads to identify
vulnerabilities, misconfigurations, excessive permissions, and other security
risks.
* Perform vulnerability management activities, including prioritizing findings,
coordinating remediation efforts, and validating corrective actions.
* Configure and enhance cloud security monitoring, threat detection,
investigation, response, and automation capabilities using Microsoft Sentinel
(SIEM), Kusto Query Language (KQL), and related technologies.
* Collaborate with Cloud, Compliance, and other internal teams to ensure cloud
services are designed, deployed, and maintained in accordance with security
best practices, organizational standards, and industry hardening standards
such as CIS Benchmarks and DISA STIGs.
* Respond to customer security inquiries, assessments, and questionnaires by
gathering, validating, and communicating information regarding security
controls, cloud technologies, and security practices.
* Develop and maintain technical documentation, procedures, dashboards, alerts,
and reporting to improve security visibility and operational effectiveness.
* Support internal and external audits by gathering evidence, validating
control adherence, and demonstrating compliance with organizational,
customer, and regulatory requirements.
* Support incident response activities by investigating suspicious, anomalous,
or unauthorized activity within cloud environments and participating in
security investigations.
Required Education and Experience
* BS/BA in Cybersecurity, Computer Science, Engineering, or technology-related
field (or equivalent work experience).
* 3+ years of experience securing cloud-based infrastructure, services and
technologies.
* Experience identifying, analyzing, and mitigating security risks within cloud
environments.
* Experience applying cloud security principles to secure cloud platforms,
including Microsoft Azure, through secure configuration, least-privilege
access, data protection, threat detection and response, and security
hardening aligned with industry standards.
* Experience deploying, administering, and using security technologies such as
Microsoft Defender, SIEM, CASB, vulnerability management, and related
security functions
* Working knowledge of Azure Log Analytics, Kusto Query Language (KQL),
PowerShell, Bash, and REST APIs.
* Working knowledge of identity and access management concepts, including
Microsoft Entra ID, role-based access control (RBAC), authentication,
authorization, and least-privilege access.
* Working knowledge of Windows and Linux operating systems.
* Familiarity with incident response, incident management, and change
management processes.
Preferred Education and Experience
* Experience working for a Cloud Service Provider (CSP), Managed Service
Provider (MSP), Software-as-a-Service (SaaS) provider, or similarly regulated
cloud environment.
* 5+ years of experience with Microsoft Azure, including securing cloud-native
technologies, Azure Kubernetes Service (AKS), and containerized workloads.
* Understanding of security controls and compliance frameworks such as NIST
800-53, FedRAMP, SOC 1, SOC 2, ISO 27001, or similar standards.
* Understanding of identity and access management (IAM) concepts, technologies,
and protocols including Microsoft Entra ID, Okta, SAML, OAuth, and OpenID
Connect (OIDC).
* Experience with Infrastructure as Code (IaC) technologies and deployment
practices, such as ARM, Bicep, Terraform, and Azure DevOps pipelines.
* Working knowledge of network security principles, networking protocols (e.g.,
TCP/IP, DNS, TLS), and firewall technologies.
* Familiarity with Agile, Scrum, and DevSecOps methodologies.
* Relevant cybersecurity certifications (e.g., AZ-500, AZ-104, SC-200, SC-300,
SC-100, Security+, Cloud+, or equivalent).
Knowledge, Skills, and Abilities
* Strong analytical and problem-solving skills.
* Excellent written, verbal, and presentation communication skills.
* Ability to effectively communicate technical information to diverse
audiences, including technical and non-technical stakeholders.
* Demonstrated initiative, accountability, and attention to detail.
* Effective prioritization and organizational skills in a fast-paced
environment.
* Adaptability to changing technologies, priorities, and business needs.
* Commitment to continuous learning and professional development.
Who We Are
OneStream is how today’s Finance teams can go beyond just reporting on the past
and Take Finance Further™ by steering the business to the future. It’s the only
enterprise finance platform that unifies financial and operational data, embeds
AI for better decisions and productivity, and empowers the CFO to become a
critical driver of business strategy and execution. Our vision is to be the
operating system for modern finance, digitizing core financial functions and
empowering the CFO to become a critical driver of business strategy. To learn
more visit www.onestream.com
[https://nam11.safelinks.protection.outlook.com/? url=http%3A%2F%2Fwww.onestream.com%2F&data=05%7C01%7Ccbaetens%40onestreamsoftware.com%7Cefb0e697518e4c23f0fc08dbc514fcc3%7Cf9796dfaf91c40958663e77a96f2d645%7C0%7C0%7C638320466155766102%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=Nl1Wyl3SIFPonX%2BgKBN8QCK7IJ4IPiyyTFmec43bn7k%3D&reserved=0].
Why Join The OneStream Team
* Transparency around corporate structure, salary, and benefits
* Core value of customer success
* Variety of project work (not industry-specific)
* Strong culture and camaraderie
* Multiple training opportunities
Benefits
at OneStream
OneStream employees are passionate, hardworking individuals who go above and
beyond to keep our customers happy and follow through on our mission statement.
They consistently deliver the best and in turn, we make every effort to keep
them cared for and happy. A sample of the benefits we provide are:
* Excellent Medical Plan
* Dental & Vision Insurance
* Life Insurance
* Short & Long Term Disability
* Vacation Time
* Paid Holidays
* Professional Development
* Retirement Plan
All candidates must be legally authorized to work for any company in the country
where this position is located without sponsorship.
OneStream is an Equal Opportunity Employer.
#LI-CB1
#LI-Remote
Which skills does this role require?
Make your next move
Build a shortlist and prepare
Identify the requirements you can demonstrate, then choose examples from your work to discuss with the hiring team.
- Build a focused shortlist before you applyCompare role requirements with your experience and give each application a clear reason.
- Practice explaining your experience in an interviewRehearse your answers before meeting the hiring team.
Other roles to compare
Review the responsibilities and requirements before adding an opening to your shortlist.
Security Engineer, Web Application Security
Pizza Hut · United States
Senior Network Security Engineer
GovCIO · United States
Network Security Engineer Master
GovCIO · United States
Cloud Security Engineer
Morgan & Morgan, P.A. · Tampa, Florida, United States
Cybersecurity Assessment Data Analyst
CACI International Inc · United States
ML Security Engineer
Bright Vision Technologies · Kirkland, Washington, United States
Role information can change. Confirm current details on the original application page.
