About the job
Mission
At Neko Health, our goal is to transform healthcare from a focus on treatment to a focus on prevention. We utilize cutting-edge, non-invasive technology combined with clinical expertise to provide early, actionable health insights.
Role Purpose
As a Cloud Security Engineer at Neko Health, you will significantly contribute to safeguarding our Azure environment in a regulated healthcare framework. Your responsibilities include designing and implementing robust security measures, monitoring for potential threats, ensuring compliance, and empowering teams to securely develop and manage cloud infrastructure at scale.
What You’ll Achieve in the First 6–12 Months
• Define and enforce secure baselines across Azure infrastructure, enhancing our cloud security posture and risk visibility.
• Deploy and optimize Microsoft Defender for Cloud and Sentinel for improved threat detection and response.
• Introduce and refine policy-as-code methodologies for infrastructure deployments, ensuring consistent and auditable security enforcement.
• Collaborate with engineering and DevOps teams to integrate security into infrastructure-as-code and architectural designs.
• Assist in cloud-related incident responses and prepare audit-ready documentation that meets regulatory requirements.
Key Responsibilities
• Secure Azure resources, including virtual machines, storage, and databases.
• Configure and oversee Microsoft Defender for Cloud and Microsoft Sentinel.
• Create and enforce policy-as-code utilizing Terraform and ARM templates.
• Conduct architecture assessments and threat modeling for cloud services.
• Work closely with DevOps and engineering teams to embed security into infrastructure-as-code.
• Support incident responses and maintain security documentation that is audit-ready.
Minimum Qualifications
• Proven experience with Azure security services, including Defender for Cloud and Sentinel.
• Solid understanding of identity and access management principles, least privilege access, and identity protection strategies.
• Familiarity with compliance standards such as ISO 27001, NIST CSF, and HIPAA is advantageous.
• Proficient in Infrastructure-as-Code tools like Terraform and ARM templates.
• Experience with integrating SIEM/SOAR platforms and cloud monitoring solutions.

