Description
Job Overview
Wind Creek Hospitality is seeking a high-energy, technically accomplished Cloud Security Engineer to advance the security of growing cloud, SaaS, data, and application environments. This role partners with infrastructure, identity, data, analytics, development, architecture, product, privacy, compliance, and security operations teams to design and implement security at enterprise scale.
The engineer serves as a hands-on technical authority for multi-cloud security, with primary depth in Microsoft Azure and working competency in AWS. The position owns security engineering outcomes through deployment, monitoring, incident support, optimization, and operations. Success requires curiosity, sound judgment, disciplined documentation, effective communication, and the ability to translate risk into practical controls.
Role Mission
Engineer, automate, and continuously improve security across Azure, AWS, SaaS, data, identity, applications, and cloud-native platforms using a risk-based, zero-trust, and DevSecOps approach.
Purpose
Our genuine engagement and positive energy provide guests an escape from their routine into our exciting fantasy world of fun, chance, and possibility, where everyone feels a sense of belonging and importance.
Value System
Our enthusiastic commitment to our purpose inspires and empowers us to do everything right, have fun, and be the best. We will be recognized fairly, elevating our levels of personal accountability, and focus on our customer. The resulting creation of wealth will grow opportunities for all.
Duties And Responsibilities
- Engineer and operate security controls for Azure, AWS, SaaS, hybrid, and cloud-native environments, including identity, networking, compute, storage, databases, containers, serverless services, applications, APIs, and data platforms.
- Implement and continuously improve cloud security posture management, workload protection, attack-path analysis, regulatory compliance monitoring, and security recommendations using Microsoft Defender for Cloud, AWS-native security services, and approved CNAPP/CSPM tooling.
- Design and enforce identity-first and zero-trust controls using Microsoft Entra ID and cloud IAM, including least privilege, role-based access control, privileged access, workload identities, managed identities, service principals, access reviews, conditional access, and secrets reduction.
- Build security guardrails and policy-as-code for subscriptions, accounts, management groups, landing zones, and resource configurations. Automate preventive and detective controls through Azure Policy, AWS Organizations and Service Control Policies, and approved infrastructure-as-code pipelines.
- Embed security into CI/CD and platform engineering workflows. Implement source, dependency, secret, container, infrastructure-as-code, API, and dynamic application security testing with enforceable quality gates and risk-based exception handling.
- Secure Kubernetes, container registries, serverless workloads, virtual machines, platform services, and cloud databases using hardened configurations, image assurance, runtime controls, network segmentation, encryption, key management, and vulnerability remediation.
- Engineer centralized logging, telemetry, detections, alerting, and automated response using Microsoft Sentinel, Microsoft Defender XDR, Azure Monitor, AWS CloudTrail, Amazon GuardDuty, AWS Security Hub, and related enterprise security platforms.
- Create and tune analytics, detections, hunting queries, dashboards, workbooks, and response automations using KQL and other supported query or scripting languages. Reduce false positives while preserving detection coverage and evidence quality.
- Lead or support cloud incident response, containment, forensic acquisition, root-cause analysis, recovery, lessons learned, and corrective action tracking. Preserve evidence and maintain clear incident records in accordance with legal, regulatory, and internal requirements.
- Other duties and responsibilities as assigned.
J
Ob Requirements (Please Ensure You Meet The Listed Requirements Prior To Applying)
- High School diploma or GED required or currently enrolled and successfully complete a GED program within 6 months from start date as a condition of continued employment
- Bachelor’s Degree in Computer Science or related field, or four (4) years’ experience working in an IT related field - required
- Seven (7) years’ experience in information technology, with a minimum of three (3) years’ hands-on experience securing or administering production cloud environments with a security focus - required
- Three (3) years’ experience in Multi-Cloud, hands-on experience with Microsoft Azure security and Microsoft Entra ID, and with AWS security services and multi-account or multi-subscription governance - required
- Three (3) years’ experience in current, role-relevant cloud administration, engineering, architecture, or security certification from Microsoft, AWS, or an industry-recognized provider - required
- Current security certification appropriate to the role, such as Microsoft Cybersecurity Architect Expert, Microsoft Identity and Access Administrator Associate, AWS Certified Security - Specialty, ISC2 CCSP or CISSP, GIAC cloud security certification, or an equivalent credential - required
- Experience in cloud identity and access management, privileged access, federation, conditional access, workload identity, secrets management, and least-privilege design.
- Experience in cloud network security, including segmentation, private connectivity, firewalls, web application firewalls, DDoS protection, DNS security, secure remote access, and zero-trust network access concepts.
- Experience in cloud security management, cloud workload protection, vulnerability management, security configuration assessment, and risk-based remediation.
- Experience with SIEM/SOAR, security telemetry, threat detection, incident response, and log analysis. Microsoft Sentinel, Defender XDR, Defender for Cloud, KQL, AWS CloudTrail, GuardDuty, and Security Hub.
- Experience with infrastructure as code and policy as code using technologies such as Terraform, Bicep/ARM, CloudFormation, Azure Policy, and AWS Organizations or Service Control Policies.
- Experience in DevSecOps and software supply-chain security, including CI/CD controls, SAST, DAST, SCA, secrets scanning, container scanning, artifact integrity, SBOM concepts, and secure release gates.
- Experience in securing containers, Kubernetes, server-less workloads, APIs, cloud databases, storage services, and platform-as-a-service environments.
- Experience in scripting and automation using PowerShell and Python; familiarity with Azure CLI, AWS CLI, REST APIs, JSON, YAML, and Git-based workflows.
- Experience in cloud key management, public key infrastructure, certificate lifecycle management, hardware security modules, encryption design, and secrets vaults.
- Experience implementing secure data and AI practices, including data classification, data loss prevention, privacy, AI workload access controls, content safety, logging, and responsible-use guardrails.
- Experience applying recognized frameworks and benchmarks such as NIST CSF, NIST SSDF, CIS Controls and Benchmarks, Microsoft Cloud Security Benchmark, and PCI DSS.
- Experience conducting or supporting cloud incident response, forensic investigations, evidence preservation, root-cause analysis, corrective action, record keeping, and reporting.
- Experience developing, documenting, and maintaining, procedures, diagrams, playbooks, and operational metrics.
- Experience supporting applications in a service-focused industry; food and beverage, gaming, hotel, payment, or other regulated environments.
- Strong troubleshooting, written communication, verbal communication, stakeholder management, and technical presentation skills in a fast-paced, multi-vendor environment.
- Understanding of the organization’s goals and objectives, with the ability to communicate technical risk in user-friendly and executive-ready language.
- Self-motivated and directed, with strong attention to detail and a commitment to continuous learning.
Core Technical Competencies
Domain |
Expected Capability |
Identity & Zero Trust |
Entra ID; AWS IAM; RBAC; PIM/PAM; Conditional Access; workload identities; federation; access reviews; least privilege |
Cloud Security Platforms |
Defender for Cloud; Defender XDR; Microsoft Sentinel; Azure Policy; AWS CloudTrail; GuardDuty; Security Hub; AWS Config; approved CNAPP/CSPM tools |
Engineering & Automation |
PowerShell; Python; KQL; Terraform; Bicep/ARM; CloudFormation; CLI/API automation; Git; JSON/YAML; policy as code |
DevSecOps & Cloud Native |
CI/CD security; SAST/DAST/SCA; secrets and container scanning; SBOM concepts; Kubernetes; registries; serverless; API security |
Data, Cryptography & Resilience |
Classification; DLP; encryption; KMS/Key Vault; PKI/certificates; secrets vaults; immutable backup; recovery controls |
Governance & Assurance |
NIST CSF; NIST SSDF; CIS; MCSB; PCI DSS; threat modeling; risk exceptions; audit evidence; metrics and reporting |
AI Security |
AI workload identity and data protection; model/plugin risk; prompt/content protections; logging; privacy; responsible-use controls |
- Able and willing to travel inside and outside of the Continental United States.
- Willing to work odd and irregular hours including nights, weekends, and holidays.
- Must have a valid and current State Driver’s License and an insurable driving record for purposes of driving company vehicles as required.
- Must have a Tribal Gaming License (or the ability to obtain and maintain a license) as a requirement for this position.
- Must have willingness and ability to work in a smoke/secondary smoke environment.
NATIVE AMERICAN INDIAN PREFERENCE IN HIRING POLICY SHALL BE ADHERED TO AT ALL TIMES
Complaints about the recruitment or selection process for employment should be directed in writing to office of the President and CEO of Wind Creek Hospitality.
Posted August 17, 2026