Cloud Security Analyst
Role details
Job location
Tech stack
Job description
As a Cloud Security Analyst on our Security team, you will help deliver an exceptional and secure product experience to our customers all around the world. You will play a crucial role in ensuring the security and compliance of our systems, customers and data. Working on security at Cloudbeds requires an adaptable cross-functional mindset. You should be comfortable talking to individuals at every level and space across the organization, from Engineering to Sales, and even Executives.
Our Security strategy is to enable the delivery of trusted, scalable, and reliable products leveraging the best of modern technologies, tools, and standards. For the Cloud Security Analyst role, we are looking for someone who can communicate best practices across both a technology and organizational process space. Our best fit team members will have worked with a broad range of compliance regulation standards, application development best practices, and Security frameworks. You will participate in implementation and ongoing monitoring of security tooling at all edges of the security landscape. You will assist with Requests for Proposals from prospective customers, daily monitoring of endpoint detection platforms, conducting Pen-tests, application vulnerability discovery and remediation, compliance requests, company-wide security training programs, and more security owned initiatives!
Our Security Team:
You will work with the Security team, and help us play our part in reinventing the world of hospitality tech and travel.
What You Bring to the Team:
- Secure application stacks running in the cloud across their full lifecycle - from the codebase through the underlying infrastructure.
- Embed security into CI/CD pipelines, partnering with DevOps and Engineering to shift security left (SAST, DAST, dependency/SCA, secrets, and IaC scanning).
- Architect, implement, and maintain cloud-native security controls, configurations, and policies (network, encryption, logging).
- Manage Identity and Access Management (IAM) policies, enforcing least privilege across cloud accounts.
- Implement and manage container and Kubernetes security tooling (image scanning, runtime policies, admission controls).
- Monitor cloud infrastructure for threats and anomalies (e.g., AWS GuardDuty) and triage alerts across platforms.
- Conduct cloud vulnerability assessments and drive remediation alongside engineering teams.
- Oversee application security operations, including code analysis tooling and remediation workflows.
- Support incident response and forensics in cloud environments, including scenario testing and runbook updates.
- Author and maintain clear, thorough security documentation, standards, and runbooks.
- Collaborate with cross-functional teams and multi-level stakeholders to drive security initiatives company wide.
- Collaborate on audits, compliance initiatives (PCI Level 1), and third-party security questionnaires., * Overall 10 Best Places to Work | HotelTechAwards (2025)
- Most Loved Workplace® Certified (2024)
- Top 10 People's Choice(2024)
- Deloitte Technology Fast 500 (2024)
Discover our Benefits:
- Remote First, Remote Always
- PTO in accordance with local labor requirements
- Monthly Wellness Fridays - enjoy an extra long weekend every month
- Full Paid Parental Leave
- Home office stipend based on country of residency
- Professional development courses in Cloudbeds University
- Access to professional development, including manager training, upskilling and knowledge transfer, To all Staffing and Recruiting Agencies: Our Careers Site is only for individuals seeking a job at Cloudbeds. Staffing, recruiting agencies, and individuals being represented by an agency are not authorized to use this site or to submit applications, and any such submissions will be considered unsolicited. Cloudbeds does not accept unsolicited resumes or applications from agencies. Please do not forward resumes to our jobs alias, Cloudbeds employees, or any other company location. Cloudbeds is not responsible for any fees related to unsolicited resumes/applications.
Requirements
- 5 years of practical experience in cloud or application security.
- Hands-on experience securing application stacks deployed in the cloud - both the code and the infrastructure behind it.
- Strong experience with AWS security services and the ability to design and implement cloud-native controls.
- Solid software development fundamentals: comfortable reading code, working in a repository, and reasoning about application vulnerabilities (e.g., OWASP Top 10).
- Practical experience integrating security into CI/CD pipelines and DevOps workflows (SAST, DAST, SCA, secrets, and IaC scanning).
- Experience with container and Kubernetes security (image scanning, runtime protection, policy enforcement).
- Working knowledge of IAM concepts and least-privilege design across cloud environments.
- Strong technical documentation skills - able to write clear standards, runbooks, and policies that engineers will actually use.
- Strong communication, problem-solving and diplomacy skills. Our teams communicate in English, but few speak it as a first language.
- Familiarity with compliance standards relevant to the cloud (PCI DSS, GDPR, SOC 2, etc.).
- Understanding and evaluating short and long term risk vs implementation speed when selecting tooling.
- Ability to wield security knowledge to resolve disputes rationally without hierarchical authority
- A Bachelor's Degree in a relevant field
Bonus Skills to Stand Out:
- Certifications such as AWS Certified Security - Specialty, AWS Solutions Architect,
- CCSP, or CompTIA Cloud+/Security+.
- Scripting/automation experience (e.g., Python, Terraform) for security orchestration and infrastructure-as-code.
- Direct experience with tools like GitHub Advanced Security, AWS Security Hub,
- Crowdstrike, ArgoCD, Github Actions, Kubernetes, and GRPC.
- Experience with cloud security automation and orchestration (SOAR, policy-as-code).
- Experience with incident response planning and execution in cloud environments.
- Experience working with a remote-first and globally distributed team.
- Experience with Atlassian products [Jira/Confluence].
- Travel industry experience is a plus but definitely not required.