Southern Bancorp is more than a bank. As a Community Development Financial Institution (CDFI), a special certificate on designated for institutions that serve predominantly underserved communities, Southern Bancorp combines traditional banking and lending services with financial development tools and public policy advocacy to help families and communities grow stronger. Inspired by the principle that building net worth drives economic opportunity, our mission is to be wealth builders for everyone in the communities we serve, with a focus on low-wealth and un(der)banked populations, as well as an emphasis on Black and Brown individuals.
The Cloud Security Engineer will be responsible for protecting Microsoft 365 and Azure environments through secure architecture, identity controls, information protection, governance, automation, and operational excellence. While approximately two-thirds of the role focuses on Microsoft Purview and enterprise data protection, the engineer will also play an active role in Azure security, identity management, cloud workload protection, and security automation.
Primary Responsibilities
Data Security & Information Protection (60–65%)
- Design and maintain the organization's enterprise data classification strategy.
- Administer and optimize Microsoft Purview.
- Implement and maintain:
- Sensitivity Labels
- Auto-labeling Policies
- Data Loss Prevention (DLP)
- Retention Policies
- Records Management
- Insider Risk Management
- Communication Compliance
- Intune Policy Protection measures
- Develop Sensitive Information Types (SITs), Exact Data Match (EDM), and Trainable Classifiers.
- Identify sensitive information across Exchange Online, SharePoint, Teams, OneDrive, and supported cloud repositories.
- Continuously improve data governance through policy tuning, reporting, and operational reviews.
- Prepare the organization for AI technologies such as Microsoft 365 Copilot through effective classification and information protection.
Cloud Security Engineering (20–25%)
- Secure Microsoft Azure workloads and cloud-native services.
- Implement security best practices across networking, storage, compute, and platform services.
- Configure and maintain Microsoft Defender for Cloud recommendations.
- Develop and maintain Azure Policy initiatives.
- Review cloud configurations against CIS Benchmarks and Microsoft Security Baselines.
- Participate in cloud architecture reviews and security design discussions.
- Support vulnerability management and remediation efforts across cloud environments.
Identity & Access Security (10–15%)
- Administer Microsoft Entra ID security controls.
- Develop and maintain Conditional Access policies.
- Support Privileged Identity Management (PIM).
- Secure enterprise application registrations and service principals.
- Review permissions, delegated access, and application consent.
- Assist with identity governance initiatives and Zero Trust adoption.
Security Engineering & Automation (5–10%)
- Develop PowerShell and Microsoft Graph automation.
- Build KQL queries for operational reporting and investigations.
- Integrate Purview and Azure telemetry into SIEM platforms.
- Improve security operations through automation and orchestration.
- Document repeatable operational procedures and engineering standards.
Required Qualifications
- 3+ years of experience securing Microsoft cloud environments.
- Hands-on administration of Microsoft Purview.
- Experience with Microsoft Entra ID.
- Experience securing Azure resources and cloud-native services.
- Strong understanding of:
- Microsoft 365 Security
- Information Protection
- Identity & Access Management
- Zero Trust Architecture
- Data Governance
- Experience with Microsoft Defender technologies.
- Familiarity with scripting using PowerShell.
Preferred Qualifications
Experience with:
- Microsoft Defender for Cloud
- Azure Policy
- Azure App Registrations
- Microsoft Graph API
- KQL
- Wazuh or OpenSearch
- Logic Apps and Power Automate
Professional certifications such as:
- Microsoft Certified: Information Protection Administrator Associate
- Microsoft Certified: Identity and Access Administrator Associate
- Microsoft Certified: Azure Security Engineer Associate
What we offer our employees:
A positive impact on Your Future:
- 401(k)/Roth plan with immediate eligibility and employer match up to 6%
- Employee stock ownership plan
- Discounted rate on primary home mortgage
- Credit and housing counseling as well as free financial education tools available to customers and employees
Benefits to improve your health:
- Two medical plans available – low-deductible PPO plan or HDHP with Health Savings Account
- Dental and vision insurance
- Employer paid life insurance, and short- and long-term disability coverage
- Retirement plan with generous company match and employee stock purchase option
- Voluntary life insurance options for employee, spouse, and children
The opportunity to nurture your well-being:
- Paid holidays and paid time off
- Bonus plan
- Opportunity for merit raises
- Employee reward and recognition programs
- Community service opportunities
Southern Bancorp is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, religion, color, national origin, sex, age, sexual orientation, gender identity, gender expression, status as a protected veteran, among other things, or status as a qualified individual with disability. Reasonable accommodation may be made to enable individuals with disabilities to perform the essential functions.
As a Community Development Financial Institution, Southern Bancorp desires its workforce to reflect the diversity of the customers and communities that we serve. Racial and ethnic minorities, people from working class backgrounds, women and LGBTQ people are often underrepresented in many financial service industry professions.