We use essential cookies

Please Accept our Privacy Policy

Cloud Infrastructure & Security Engineer

Phoenix Energy One, LLC

Denver, CO • $125,000 to $145,000 / yr • 9/28/2026

Job Description

Job Description:\n\nJob Summary: Phoenix Energy is seeking a Cloud Infrastructure & Security Engineer to design, secure, operate, and continuously improve the company's enterprise technology environment. This role serves as a hands-on technical owner across Microsoft Azure infrastructure, cloud and network security, identity and access management, endpoint security, platform reliability, automation, and disaster recovery. The ideal candidate enjoys building scalable enterprise platforms, improving security and operational maturity, automating manual processes, and partnering across Infrastructure, Software Development, Data Engineering, Enterprise Systems, and Business Operations. This is not a traditional SOC-only role; it combines cloud infrastructure engineering with practical enterprise security engineering and governance. This position reports to the Director of Enterprise Technology and plays a foundational role in building a secure, resilient, scalable, and well-governed technology environment for Phoenix Energy. Responsibilities: • Cloud Infrastructure & Azure • Design, deploy, administer, and maintain Microsoft Azure infrastructure, including subscriptions, resource groups, virtual networks, storage, compute, and related platform services. • Administer Azure Virtual Machines and Azure Virtual Desktop (AVD) environments, including operating system deployment, upgrades, maintenance, performance, and standardized build configurations. • Develop and maintain Azure architecture, governance, resource lifecycle, and configuration standards. • Monitor platform health, utilization, capacity, performance, and cloud cost; recommend and implement improvements. • Support reliable development, testing, production, analytics, and enterprise application environments. • Network & Cloud Security • Design and maintain secure virtual networking, DNS, routing, VPN connectivity, firewalls, Network Security Groups, private endpoints, and hybrid connectivity. • Administer and continuously improve the company's Zero Trust platform, including Cloudflare WARP and related access controls. • Establish and maintain security standards for Azure resources, endpoints, network infrastructure, and cloud connectivity. • Improve network visibility, monitoring, segmentation, and secure communications across enterprise environments. • Maintain accurate infrastructure and network architecture documentation. • Identity, Endpoint & Access Security • Administer Microsoft Entra identity and security capabilities, including security groups, Single Sign-On integrations, and identity-related cloud controls. • Support Joiner, Mover, and Leaver processes and enterprise access lifecycle management. • Assist with privileged access management, credential governance, and enterprise password management initiatives. • Administer and improve endpoint security and management platforms, including Hexnode MDM, SentinelOne, and future enterprise endpoint technologies. • Administer enterprise AI platform access, including ChatGPT, Claude, and future approved AI solutions. • Security Operations & Vulnerability Management • Monitor security alerts and coordinate incident response, investigation, containment, remediation, and root cause analysis activities. • Investigate phishing campaigns and security events while partnering with business teams to improve awareness and response. • Manage vulnerability findings across cloud infrastructure, endpoints, and applications and coordinate remediation with infrastructure and development teams. • Support application security processes, security assessments, vulnerability management platforms, and secure software development practices. • Integrate security scanning and controls into CI/CD and software delivery workflows where appropriate. • Monitoring, Reliability, Backup & Disaster Recovery • Implement centralized infrastructure and security monitoring, alerting, logging, and operational visibility. • Perform proactive maintenance and capacity planning to improve availability, stability, and performance. • Develop and maintain backup and recovery strategies for critical enterprise workloads. • Perform backup validation and disaster recovery testing and help establish Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO). • Participate in Business Continuity and Disaster Recovery planning and maintain supporting technical documentation. • Automation & Engineering • Automate infrastructure provisioning, security administration, reporting, and operational workflows using PowerShell, Python, APIs, Azure Automation, Infrastructure-as-Code, or similar technologies. • Standardize deployment and configuration processes to improve consistency and reduce manual effort. • Integrate infrastructure, endpoint, identity, and security platforms into centralized monitoring and workflow solutions. • Develop scripts and automation that improve operational efficiency, compliance validation, and technology reliability. • Evaluate emerging cloud and security technologies that can improve scalability, security, and operational effectiveness. • Governance, Risk & Compliance • Help develop and maintain enterprise technology and security policies, standards, procedures, architecture documentation, and operational runbooks. • Support SOX compliance initiatives and future governance, audit, and security programs. • Participate in access reviews, change management, vulnerability remediation, disaster recovery, and other technology control activities. • Support third-party security reviews, vendor risk assessments, and audit evidence requests. • Ensure infrastructure and security practices align with enterprise policies, regulatory requirements, \t • Cross-Functional Collaboration • Partner with Data Engineering to support SQL Server, PostgreSQL, analytics platforms, integrations, \tand supporting infrastructure. • Partner with Software Development to maintain reliable environments and improve DevSecOps and CI/CD security practices. • Work closely with Enterprise Systems Administration to improve endpoint management, identity integration, and user experience. • Participate in enterprise architecture planning, technology roadmap development, and continuous improvement initiatives. Skills: • Microsoft Azure Administrator Associate (AZ-104) and/or Azure Solutions Architect Expert (AZ-305). • Experience with Azure Monitor, Log Analytics, Microsoft Defender, or SIEM/SOAR platforms. • Experience with Cloudflare security solutions, SentinelOne, Hexnode, or comparable enterprise platforms. • Experience with Infrastructure-as-Code technologies such as Terraform, Bicep, or ARM Templates. • Familiarity with GitHub Actions, CI/CD pipelines, application security tooling, and DevSecOps practices. • Experience supporting SQL Server and PostgreSQL infrastructure. • Experience with governance, compliance, and audit programs such as SOX, SOC 2, ISO 27001, NIST, or CIS. • Experience supporting regulated or publicly traded organizations. • Azure Cloud Architecture & Administration • Enterprise Security Engineering • Identity & Access Management • Enterprise Networking & Zero Trust • Endpoint Security & Management • Infrastructure & Security Automation • Platform Reliability & Monitoring • Vulnerability Management & Incident Response • Backup, Disaster Recovery & Business Continuity • Governance, Documentation & Compliance • Cross-Functional Technical Leadership • Continuous Improvement Requirements: • 5+ years of experience in cloud infrastructure, enterprise infrastructure, cybersecurity, security engineering, or a closely related technical discipline. • 3+ years of hands-on Microsoft Azure administration or engineering experience. • Strong experience with Windows Server, virtual machines, enterprise storage, and cloud infrastructure. • Strong understanding of networking fundamentals including TCP/IP, DNS, VPNs, routing, firewalls, and secure network architecture. • Experience with Microsoft Entra ID, identity management, SSO, and access lifecycle concepts. • Experience with endpoint management and EDR/XDR technologies. • Understanding of Zero Trust architecture and modern enterprise security practices. • Experience with PowerShell, Python, APIs, or similar scripting and automation technologies. • Experience implementing backup, recovery, monitoring, and platform reliability solutions. • Strong troubleshooting, incident response, documentation, and root cause analysis skills. Education: • Bachelor's degree in Information Technology, Computer Science, Cybersecurity, Engineering, or equivalent professional experience. Why This Role Exists: As Phoenix Energy continues to grow, cloud infrastructure and enterprise security have become inseparable foundations of business operations. This role ensures the company's technology platform remains secure, scalable, reliable, resilient, and capable of supporting enterprise applications, analytics, AI initiatives, software development, and future business growth. The Cloud Infrastructure & Security Engineer will help mature Phoenix Energy's Enterprise Technology organization by combining hands-on infrastructure ownership with security engineering, automation, governance, and operational excellence.\n\nCompany Description:\n\nPhoenix Energy One, LLC, is a privately owned oil and gas investment firm specializing in mineral rights and leasehold acquisitions. The company is headquartered in the Denver Tech Center with satellite offices in Casper, WY, Irvine, CA, Ft Lauderdale, FL, Williston and Dickinson, ND, Chicago, IL, and Dallas, TX. Phoenix Energy One, LLC is pursuing an aggressive growth strategy and is pioneering a one-of-a-kind business model within the energy sector. The founding members of Phoenix Energy One, LLC have decades of industry experience.

Company Description

Phoenix Energy One, LLC, is a privately owned oil and gas investment firm specializing in mineral rights and leasehold acquisitions. The company is headquartered in the Denver Tech Center with satellite offices in Casper, WY, Irvine, CA, Ft Lauderdale, FL, Williston and Dickinson, ND, Chicago, IL, and Dallas, TX. Phoenix Energy One, LLC is pursuing an aggressive growth strategy and is pioneering a one-of-a-kind business model within the energy sector. The founding members of Phoenix Energy One, LLC have decades of industry experience.