Staff Security Engineer
17 hours ago
Scottsdale
Position Summary The Staff Infrastructure & Security Engineer is the sole technical owner of all cloud infrastructure, cybersecurity, identity, endpoint operations, and DevOps platform engineering for a 240-person consultancy operating a large-scale Azure and Microsoft Fabric environment. Reports to the IT Director. Accountable for the end-to-end buildout, hardening, and operational excellence of every infrastructure and security workstream on the 2026 roadmap. Scope includes SIEM deployment, zero-trust identity, disaster recovery, cloud cost optimization, and the CI/CD and hosting infrastructure powering our proprietary AI platform, the Hub: a multi-tenant "Super App" serving internal teams and external clients, with a suite of AI-driven applications (Trainer, SalesIQ, Jarvis, Knowledge, Momentum, Dashboards, Blueprints, Capture) shipping at high velocity across web and mobile. This is not a maintenance role. It is a greenfield buildout across 80+ SharePoint sites, multiple Fabric Lakehouses, a growing multi-tenant client ecosystem, and a product engineering organization that needs world-class deployment and observability tooling. ABOUT CARDONE VENTURES Our mission is to help business owners achieve their personal, professional, and financial goals through the growth of their businesses. Our core values guide our hiring process: we are inspirational, accountable, transparent, disciplined, aligned, and results oriented. This role requires an AI-native engineer LLM fluency is a hard requirement, not a preference. The throughput expected assumes active, daily use of AI tooling to achieve what typically requires a multi-person team. Claude AI (Anthropic) is provided and expected to be used for IaC authoring, detection rule development, runbook creation, policy generation, log analysis, and automation scripting. Engineers who embrace AI as a force multiplier will thrive here. Those who don't will struggle to keep pace with the scope. What Success Looks Like • SIEM Operational, within 6 months: Tuned alerting, active connectors, and initial SOAR playbooks live. Mean-time-to-detect under 30 minutes for critical events., • Hub CI/CD: 50%+ cycle time reduction. Zero-downtime deployments and sub-5-minute rollback fully operational within the first 6 months, • Hub Platform Uptime: 99.9% SLA with proactive alerting that surfaces degradation before end users or clients report it., • Endpoint Compliance: 100% fleet by end of Q3. Full Intune compliance across 240+ Windows and Mac endpoints with hardened baselines, automated patching, and DLP enforced., • Disaster Recovery, validated by end of Q3: Immutable backups, documented runbooks, and a successful DR drill with measured RTO. Quarterly tests sustained thereafter., • Identity & Access, within 6 months: MFA hardened, PIM enforced for all privileged roles, CA policies cleaned up and documented, first company-wide access review complete., • Azure Cost Reduction: 15%+ savings via right-sizing, tagging enforcement, and cost optimization, while simultaneously improving reliability metrics., • Penetration Test, H2: Pass external pen test with no critical or high-severity findings unresolved beyond agreed SLAs. Objectives • Hub Platform & DevOps: Own CI/CD pipelines, Azure hosting, container orchestration, environment management, full-stack observability, and the multi-tenant infrastructure powering the Hub and its application suite across web and mobile, including new launches like voice mode, telephony, and AI agents (Dawson AI, Jarvis)., • Cloud Infrastructure & IaC: Architect and enforce Terraform/Bicep IaC across all Azure environments and own cloud operations, cost optimization, SRE metrics, capacity planning, and incident response across the Microsoft Fabric, OneLake, and SharePoint Online estate., • Security Operations & SIEM: Design, deploy, and operationalize the SIEM platform (connectors, detection rules, alert tuning, SOAR pilot), stand up the vulnerability management program, and manage ongoing posture (firewall hygiene, segmentation, patch/firmware lifecycle, hardening)., • Identity & Access Management: Execute the full IAM lifecycle in Entra ID (auth policies, MFA, PIM, CA cleanup, SSO audit, passkeys, guest controls, quarterly access reviews) and administer identity integrations across Okta, Entra ID, and key SaaS apps., • Endpoint Management: Deploy and harden Intune across 240+ Windows and Mac endpoints (baselines, app control, patch automation, compliance, DLP), maintain endpoint security posture, and standardize device provisioning and lifecycle., • Disaster Recovery & Business Continuity: Design and implement backup and DR architecture (immutable storage, SaaS backup coverage, restore testing, RTO tuning, runbooks) and execute quarterly DR drills., • Automation, AI & Reporting: Operate as an AI-native practitioner using Claude and LLM tooling daily, automate repeatable tasks via PowerShell/Python/Bash, and deliver concise infrastructure and security reporting to the IT Director, CTO, and executive stakeholders. Required Competencies • Deep, hands-on expertise across Azure cloud infrastructure (compute, networking, storage, Entra ID, Intune, Defender, and Sentinel or equivalent SIEM) with the ability to architect and implement at enterprise scale without a team., • Hands-on experience with container orchestration (Kubernetes/AKS or Azure Container Apps), CI/CD platforms (GitHub Actions, Azure DevOps), and IaC (Terraform strongly preferred; Bicep/ARM acceptable) for both corporate and application hosting environments., • Strong application-level observability skills (Datadog, Application Insights, Grafana) with the ability to instrument, monitor, and troubleshoot distributed systems serving web and mobile clients., • AI fluency is a hard requirement: demonstrated proficiency using LLMs and AI-assisted tooling (Claude, Copilot, or equivalent) to accelerate IaC authoring, security policy generation, detection rule development, runbook creation, and automation scripting., • Command-level knowledge of modern security frameworks (NIST, CIS, zero-trust principles) and practical experience implementing identity governance, endpoint hardening, DLP, SIEM/SOAR, and vulnerability management programs., • Proven ability to own and execute 4–6 concurrent technical workstreams independently, prioritizing ruthlessly and delivering production-grade results without dedicated project management support., • Strong understanding of Microsoft Fabric, OneLake, and SharePoint Online administration, including data governance, access controls, and integration with the broader M365 ecosystem., • Exceptional written and verbal communication skills, with the ability to translate complex infrastructure and security decisions into clear business-risk language for non-technical executives., • Track record of building from zero, standing up programs, processes, and tooling in environments where none existed. Preferred Qualifications • SIEM/SOAR platforms (Microsoft Sentinel preferred; Splunk or equivalent acceptable) and detection engineering., • Microsoft Fabric and OneLake in production data environments., • Compliance/security frameworks (SOC 2–style controls) and evidence-driven operations., • Multi-tenant SaaS platforms, especially data isolation, per-tenant observability, and secure deployment patterns., • Mobile delivery (iOS/Android via CI/CD pipelines, app store deployments, MDM integration)., • Certifications (nice to have): AZ-104, AZ-500, SC-200, Terraform Associate, CKA/CKAD, CISSP/CISM, Security+. About the Hub Platform The Hub is the company's proprietary AI-powered Super App, a multi-tenant platform serving internal teams and external clients across multiple industry verticals. It is the primary product of the engineering organization and the infrastructure this role is responsible for hosting, deploying, and keeping operational. Hub application suite: • Trainer: AI-powered training and enablement, • SalesIQ: sales intelligence and performance analytics, • Jarvis: internal AI assistant and agent capabilities, • Knowledge: organizational knowledge base and retrieval, • Momentum: performance and goal tracking, • Dashboards: executive and operational reporting, • Blueprints: process documentation and workflow tooling, • Capture: data capture and intake workflows The Hub ships at high velocity across web and mobile, with active development of voice mode, telephony integrations, and AI agent capabilities. The infrastructure owner is expected to be a close partner of the engineering team, not a gatekeeper. A Note on Claude AI This role is expected to actively use Claude (Anthropic's AI) as a core part of the day-to-day workflow. We provide access and encourage its use for: • Writing and iterating on runbooks, SOPs, and technical documentation, • Drafting and reviewing IaC templates, scripts, and configuration snippets, • Log and alert analysis to accelerate incident triage, • Detection rule authoring and SIEM query development, • Summarizing CVEs, vendor docs, and change management notes, • Building knowledge base content and training materials Additional Requirements • Onsite role at the primary office; travel to Scottsdale and other locations as needed., • Participation in an on-call rotation., • Ability to lift and handle IT equipment (APs, switches, firewalls, laptops) for deployments and desk setups. COMMITMENT TO DIVERSITY Cardone Ventures is an equal opportunity employer. We hire local talent at all levels regardless of race, color, religion, age, national origin, gender, gender identity, sexual orientation, or disability, and actively foster inclusion across all interactions with clients, candidates, and partners. Interested? Send your resume to with the job title and source in the subject line. Existing candidates: connect directly with your recruiter.