Cyber Cloud Operations Engineering Specialist (Azure IAM Security)
TruistAbout the role
The position is described below. If you want to apply, click the Apply Now button at the top or bottom of this page. After you click Apply Now and complete your application, you'll be invited to create a profile, which will let you see your application status and any communications. If you already have a profile with us, you can log in to check status.
If you have a disability and need assistance with the application, you can request a reasonable accommodation. Send an email to Accessibility (accommodation requests only; other inquiries won't receive a response).
Regular or Temporary:
RegularLanguage Fluency: English (Required)
Work Shift:
1st shift (United States of America)Please review the following job description:
******For this opportunity, Truist will not sponsor an applicant for work visa status or employment authorization, nor will we offer any immigration-related support for this position (including, but not limited to H-1B, F-1 OPT, F-1 STEM OPT, F-1 CPT, J-1, TN-1 or TN-2, E-3, O-1, or future sponsorship for U.S. lawful permanent residence status.)***
This role is 5 days a week in the Atlanta, Charlotte, Raleigh or Richmond VA office***
The Cyber Operations Engineering Specialist is an advanced, identity-focused role within the Cloud Security team.
This position is responsible for hunting, monitoring, triaging, and mitigating identity-based threats across Microsoft Entra ID (Azure AD), hybrid environments, and cloud infrastructure.
This role evaluates data from specialized security tools (e.g., Microsoft Sentinel, Microsoft Entra ID Protection, Defender for Identity,
Privileged Identity Management (PIM), and SOAR solutions) to analyze unauthorized access attempts, anomalous authentication behavior, and permission misuse in complex, often unstructured environments.
Essential Duties and Responsibilities
Following is a summary of the essential functions for this job. Other duties may be performed, both major and minor, which are not mentioned below. Specific activities may change from time to time.
Identify & Analyze Identity Threats: Characterize and analyze security alerts within Microsoft Entra ID (Azure AD), Identity Protection, and Privileged Identity Management (PIM) to understand and mitigate potential identity-based attacks.
Event Correlation & Context: Perform correlation of sign-in logs, audit logs, and risk events using Azure Sentinel (SIEM) and Microsoft Defender for Cloud to understand the full scope of a compromised identity.
Incident Response & Remediation: Act as an escalation point for high-severity identity incidents; take immediate action to revoke sessions, reset credentials, and block malicious IPs/users to contain threats.
Azure AD Governance & Policy: Configure, manage, and audit Conditional Access Policies (CAPs), MFA, and Azure RBAC to ensure compliance with Zero Trust principles.
Trend Analysis & Reporting: Perform quarterly reviews of user privileges, identity risk trends, and audit logs; provide reporting on the overall health of the identity security posture.
Identity Automation: Develop and improve automation workflows using Azure Logic Apps, PowerShell, and Azure CLI to automate user provisioning, deprovisioning, and incident remediation.
Runbook Improvement: Constantly improve SOC/IAM runbooks, focusing on reducing false positives in identity alerts and enhancing response playbooks for PIM escalations.
Recommendations & Governance: Provide strategic recommendations to management on enhancing IAM security, implementing Privileged Access Management (PAM), and closing identity security gaps
Required Qualifications:
The requirements listed below are representative of the knowledge, skill and/or ability required. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
Bachelor’s degree in Computer Science, Computer Engineering, Cybersecurity, or related field of relevant education, certification, or related training.
Three years of experience
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s