POSITION TITLE: Cloud Security Specialist
STATUS: Exempt
COMPENSATION RANGE: $148,000-$164,000 Annually
LOCATION: Based out of our beautiful West Creek Office, located at 12580 West Creek Pkwy, Richmond, VA 23238. Hybrid schedule is offered, in office 2 days a week, work from home 3 days a week, after training and probationary period is completed. No relocation offered.
REPORTS TO: Chief Risk Officer
POSITION SUMMARY
The Cloud Security Specialist supports day-to-day execution of the organization’s cloud security program across Microsoft Azure and Amazon Web Services. The role monitors cloud security controls, secures identity and access, reviews cloud and network architecture, integrates security into deployment pipelines, protects cloud-hosted data, and coordinates remediation with Information Security, Infrastructure, and Application Development. This is a growth-oriented role for a candidate with foundational to intermediate cybersecurity, cloud, or DevOps experience.
PRIMARY DUTIES
Cloud Security Operations and Posture Management
-
Monitor Azure and AWS environments for misconfigurations, vulnerabilities, policy violations, suspicious activity, and drift from CIS Benchmarks and approved baselines.
-
Administer and tune cloud security posture management and cloud-native security services, including Microsoft Defender for Cloud, AWS Security Hub, and AWS GuardDuty.
-
Investigate cloud security alerts, document findings, coordinate remediation with system and application owners, and escalate high-risk findings to senior staff.
-
Maintain cloud security dashboards, asset inventories, and landing zone usage and reporting.
Identity and Access Management
-
Support Azure and AWS identity controls, including Microsoft Entra ID, AWS IAM, role-based access control (RBAC), least privilege, multifactor authentication, conditional access, and privileged access management.
-
Review roles, service principals, managed identities, access keys, and excessive or inactive access; support identity federation and SSO using OAuth 2.0, OpenID Connect, and SAML.
Cloud Architecture and Network Security
-
Support secure landing zone design, hub-and-spoke topology, environment separation, and network zoning using NSGs, AWS security groups, network ACLs, and private endpoints.
-
Support secure configuration of load balancers and gateways (Azure Application Gateway, Azure Load Balancer, AWS ALB/NLB, API gateways), cloud WAF, CASB, and API security controls.
-
Review proposed cloud architectures for sound security design and escalate design concerns to senior staff.
Secure Cloud Engineering and DevSecOps
-
Integrate security requirements into deployments; review infrastructure-as-code (Bicep, ARM, Terraform, CloudFormation) and configurations for security risks.
-
Support security scanning, secrets detection, and policy checks in Azure DevOps (ADO) pipelines.
-
Implement and maintain security policy as code using Azure Policy, AWS Service Control Policies, and AWS Config rules.
Data Security in the Cloud
-
Support secure configuration of storage, databases, encryption, secrets, and key management (Azure Key Vault, AWS KMS).
-
Support data classification, labeling, and DLP with Microsoft Purview, and governance controls for Microsoft Fabric and Copilot, including oversharing risk.
Monitoring and Incident Response
-
Ensure cloud audit, security, and data access logs reach security monitoring platforms; support investigations, triage, and documentation for cloud-related incidents.
Cloud Risk, Compliance, and Reporting
-
Support risk assessments, audit evidence collection, and assessment of cloud controls against NIST, CIS Benchmarks, NYDFS, Virginia BOI, PCI-DSS, and other requirements.
-
Prepare cloud security metrics and reports for leadership; document standards, procedures, diagrams, and exceptions.
ADDITIONAL DUTIES
-
Participate in security awareness, tabletop exercises, and training; perform other duties as assigned.
MINIMUM EDUCATIONAL / EXPERIENCE QUALIFICATIONS
-
Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or related field. Equivalent work experience in lieu of degree is considered.
-
Two or more years of experience in cybersecurity, network security, DevSecOps, or related work.
-
Three to five years of hands-on experience administering Microsoft Azure and/or Amazon Web Services.
MINIMUM SKILL QUALIFICATIONS
-
Working knowledge of cloud security, identity and access management, RBAC, cloud networking, encryption, logging, and secure configuration.
-
Experience reviewing infrastructure as code, deployment pipelines, containers, or cloud-hosted applications.
-
Strong analytical, troubleshooting, documentation, communication, and teamwork skills.
PREFERRED QUALIFICATIONS
-
Experience with Microsoft Entra ID, Microsoft Defender for Cloud, AWS Security Hub, AWS GuardDuty, SIEM, or comparable cloud security tools.
-
Experience with Azure DevOps pipelines, Git, and policy as code (Azure Policy, AWS SCPs, AWS Config).
-
Experience with landing zones, hub-and-spoke design, cloud WAF, CASB, API security, and Azure CAF or AWS Well-Architected Framework.
-
Experience with Microsoft Purview, Fabric, and Copilot governance; identity protocols (OAuth 2.0, OIDC, SAML, PKI).
-
Container security (Docker, Kubernetes) and scripting in Python or PowerShell.
-
Security+, Microsoft Azure Security Engineer Associate (AZ-500), AWS Certified Security – Specialty, or equivalent certification.
-
Familiarity with NIST CSF, CIS Controls, ISO 27001/2, PCI-DSS, SOX, HIPAA, GDPR, GLBA, CNAPP/CWPP concepts, EDR/MDR, and Linux and Windows administration.
REPORTING RELATIONSHIP
Reports To: Manager, Active Defense & Security Operations
OTHER DUTIES
This job description describes the general nature and level of work assigned and is not an exhaustive list of responsibilities, duties, or skills. Other job-related duties may be assigned.
At VA Farm Bureau, we provide an exceptional benefits package, including ongoing job development and support in all roles, paid training and continuing education reimbursement, medical and dental insurance available on your first day, generous employee 401K contribution, excellent Paid Time off (PTO) plan and more!
Virginia Farm Bureau Companies provide equal employment opportunity in all aspects of employment without regard to race, color, national origin, religion, gender, pregnancy, age, disability, orientation or veteran status.
Skills Required
- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field; equivalent work experience may substitute.
- Two or more years of experience in cybersecurity, network security, DevSecOps, or related work.
- Three to five years of hands-on experience administering Microsoft Azure and/or Amazon Web Services.
- Working knowledge of cloud security, identity and access management, RBAC, cloud networking, encryption, logging, and secure configuration.
- Experience reviewing infrastructure as code, deployment pipelines, containers, or cloud-hosted applications.
- Strong analytical, troubleshooting, documentation, communication, and teamwork skills.
- Experience with Microsoft Entra ID, Microsoft Defender for Cloud, AWS Security Hub, AWS GuardDuty, SIEM, or comparable cloud security tools.
- Experience with Azure DevOps pipelines, Git, and policy as code.
- Experience with landing zones, hub-and-spoke design, cloud WAF, CASB, API security, Azure CAF, or AWS Well-Architected Framework.
- Experience with Microsoft Purview, Fabric, Copilot governance, OAuth 2.0, OIDC, SAML, or PKI.
- Experience with container security using Docker or Kubernetes and scripting in Python or PowerShell.
- Security+, AZ-500, AWS Certified Security - Specialty, or equivalent certification.
- Familiarity with NIST CSF, CIS Controls, ISO 27001/2, PCI-DSS, SOX, HIPAA, GDPR, GLBA, CNAPP/CWPP, EDR/MDR, and Linux or Windows administration.
What We Do
Nearly a century ago, Virginia Farm Bureau made the state’s farmers a promise – to protect and preserve what they’d labored so hard to create. A promise to do our part to ensure a bright future for our children, and our children’s children. Today that promise extends beyond farmers. And when you’re with Virginia Farm Bureau, you have an important role in upholding it. The Virginia Farm Bureau family of companies includes: • Virginia Farm Bureau Federation • Virginia Farm Bureau Mutual Insurance Co. • Benefit Design Group Inc. • Employee Benefits Corporation of America • Countryway Insurance Co. Virginia Farm Bureau Federation is a membership organization focused on supporting and growing Virginia agriculture. Membership includes access to exclusive leadership programs, commodity representation, agricultural marketing and business development assistance, products, insurance and other services. Since 1950, Virginia Farm Bureau Mutual Insurance Co. has been protecting our members’ interests. We offer auto, home, farm and life insurance and more. We strive to be a leading insurer for all Virginians while remaining the foremost provider to Virginia's farmers. Employee Benefits Corporation of America is among the largest marketers of group insurance plans in the mid-Atlantic region and provides a variety of health care products and carriers. Benefit Design Group Inc. is a licensed and bonded third-party administrator providing sales, service, billing and administrative support for more than 400 brokers and 2000 employer groups in the Mid-Atlantic region. Countryway Insurance Co. sells products through a network of independent agents in eight northeastern states, Virginia and Kentucky. We focus on the needs of farms and rural communities. Virginia Farm Bureau is based in Richmond, Va., with over 1,000 employees throughout the state and on the Eastern Seaboard. We’re a community-oriented company deeply rooted in every county across the state, and we're expanding!








