Patch My PC

Cloud Security Engineer

Remote, United States · Remote · Posted today

Opens jobs.lever.co

Get a version of your resume written for this job.

Salary
US$110,000–145,000 / year
Job type
Full-time
Work mode
Remote
Source
Lever (employer's hiring system)

Skills mentioned

Cloud Security, Azure, SOC 2, ISO 27001, Incident Response

About the role

About Our Company:

At Patch My PC, we exist to improve lives. What started as a free tool to keep apps updated has grown into a trusted enterprise solution that helps IT and Security teams automate, manage, deploy, and report on third-party updates in Microsoft ConfigMgr, Intune, and WSUS. Our fully remote crew of 150 GIF-loving humans supports over 10,000 customers and more than 32 million devices. We make patching easier, boost security, and give IT teams their time back.

Our core values guide how we work, how we treat each other, and how we grow. They keep us focused on what matters most. We're here to improve the lives of our customers, our team members, and our communities.


About this Role:

We're hiring a Cloud Security Engineer to strengthen and operate our Microsoft cloud security stack. This is a hands-on engineering role: you'll build, tune, and maintain the security and compliance controls that protect organizational and customer data while bringing a red-team mindset to find weaknesses before attackers do. 

You'll own the day-to-day engineering of our Microsoft Purview, Defender for Cloud, Entra, and Azure monitoring capabilities, translate technical risk into clear recommendations for leadership, and act as a trusted security advisor to internal teams and customers. This role sits at the intersection of security engineering, cloud operations, and governance, ideal for someone who likes to build controls, break assumptions, and measurably improve security posture. 

Responsibilities:

    Cloud Security Engineering & Operations 

  • Design, deploy, configure, and maintain Microsoft cloud security and compliance technologies, including Microsoft Purview, Microsoft Defender for Cloud, Azure Log Analytics, Microsoft Entra ID, Privileged Identity Management (PIM), and Identity Governance. 
  • Engineer and continuously improve technical security controls across Microsoft 365 and Azure. 
  • Automate recurring security and compliance tasks to reduce manual effort and drift. 
  • Monitor security and compliance posture, and drive continuous-improvement initiatives with measurable outcomes. 
  • Data Protection & AI Governance 

  • Build, deploy, and maintain Data Loss Prevention (DLP) policies across the organisation. 
  • Monitor AI technology usage and engineer controls to mitigate data exposure, information leakage, and inappropriate use. 
  • Assess emerging AI-related threats and implement appropriate governance and technical guardrails. 
  • Partner with internal teams to ensure sensitive data is adequately protected. 
  • Threat Assessment & Security Reviews 

  • Apply a red-team mindset to proactively identify weaknesses in systems, configurations, processes, and controls. 
  • Conduct security reviews, exposure assessments, and control-effectiveness evaluations. 
  • Produce clear, concise reports for leadership covering findings, risk assessments, control gaps, and prioritized remediation recommendations. 
  • Track remediation and support stakeholders in implementing corrective actions. 
  • Monitoring & Incident Support 

  • Use Azure Log Analytics and security tooling (e.g., KQL queries, alerting) to detect suspicious activity, trends, and compliance issues. 
  • Support security investigations and incident response, including analysis, containment, and remediation recommendations. 
  • Customer & Stakeholder Engagement 
  • Represent security and compliance in customer calls covering governance, data protection, and control topics. 
  • Support the compliance team on customer questionnaires, assessments, and security reviews. 
  • Communicate technical concepts effectively to both technical and non-technical audiences. 

Required Skills:

  • 7+ years of hands-on experience engineering and operating Microsoft cloud security technologies: Purview, Defender for Cloud, Azure Log Analytics, Entra ID, PIM, Identity Governance, and DLP. 
  • Solid understanding of cloud security principles and Microsoft 365 / Azure security controls. 
  • Experience investigating security risks and identifying control weaknesses. 
  • Comfort writing queries (e.g., KQL) and automating tasks (PowerShell, Graph API, or similar) is a strong plus. 
  • Willingness and ability to travel. Tthis role may require travel to customers to discuss our security practices and showcase how our tooling improves their security posture. 
  • Strong analytical and problem-solving skills, with the ability to think from an attacker's perspective. 
  • Excellent written communication, able to produce professional reports and executive summaries. 
  • Strong presentation and customer-facing communication skills. 
  • Able to work independently in a remote setting while collaborating with distributed teams. 

Nice to Have:

  • Microsoft security certifications (SC-200, SC-300, SC-400, AZ-500, or equivalent). 
  • Experience with compliance frameworks such as ISO 27001, SOC 2, GDPR, or similar. 
  • Experience with security governance, risk, and compliance (GRC) programmes. 
  • Exposure to AI governance, security, or responsible-AI initiatives. 
  • Experience as a consultant in Configuration Manager, Intune and other related technologies. 
  • Experience at leading customer focused workshops.  
  • Ideal Candidate 

    A hands-on cloud security engineer who enjoys building and tuning controls, finding weaknesses before attackers do, translating technical risk into business recommendations, and helping organizations, both ours and our customers mature their security posture. Equally comfortable in a config console, a log-analytics query, and a customer call. 

Compensation & Benefits:

    Competitive Base Salary: $110,000 - $145,000 based on experience and location.

    Benefits:

  • 401k Match: Match 200% of contributions up to the first 5% of salary, resulting in a total potential match of 10%.
  • Medical, Dental, and Vision Coverage: Patch My PC covers 99% of premiums for both team members and dependents.
  • Other Benefits:

  • FSA/HSA.
  • Fertility benefits.
  • Parental leave.
  • Paid-time off (PTO).
  • Volunteer leave.
  • Charitable donation matching.
  • Tuition reimbursement.
  • Gym membership reimbursement.
  • Internet stipend.
  • Pet insurance.
  • Learn more about our benefits here: https://patchmypc.com/careers#we-care.

What to Expect in the Interview Process

Curious about what comes next? Learn more about our hiring process here: http://patchmypc.com/careers#hiring-process

Equal Opportunity Employer:

Patch My PC is an Equal Opportunity Employer and is committed to a policy of equal treatment and opportunity in every aspect of its recruitment and hiring process. We encourage women, racial and ethnic minorities, individuals with disabilities, and veterans to apply.

Work Authorization:

To be eligible for consideration, candidates for fully remote positions must reside in one of the following U.S. states at the time of hire:

AL, AK, AR, AZ, CA, CO, CT, DE, FL, GA, HI, IA, ID, IL, IN, KS, KY, LA, ME, MI, MN, MO, MS, MT, NC, ND, NE, NH, NJ, NM, NV, OH, OK, PA, RI, SC, SD, TN, TX, UT, VA, WA, WI, WV, WY.

Job ID lv-patchmypc-c6ae9e75-99a1-47fd-8e1b-6b8477fb1902 · Original posting ↗