> Markdown version of [/jobs/ext/1044565-lead-cloud-security-appsec-engineer](https://www.wearedevelopers.com/jobs/ext/1044565-lead-cloud-security-appsec-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Lead Cloud Security/AppSec Engineer - **Company:** Properfood, LLC - **Location:** Cambridge, MA, United States - **Experience:** Expert - **Salary:** $148,000.0 - $203,500.0 - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Artificial Intelligence, Amazon Web Services, Application Layers, Cloud Computing, Cloud Computing Security, Cloud Engineering, Code Review, Cyber Security, Computer Networks, Continuous Integration, Data Auditing, Information Leak Prevention, Identity and Access Management, Intrusion Detection and Prevention, Python (Programming Language), Azure Active Directory, Data Streaming, Software Technical Review, Cloud Platform System, Large Language Models, Prompt Engineering, Software Security, AI Platforms, Kubernetes, Terraform, GPT, Static Application Security Testing, Dynamic Application Security Testing - **Published:** June 9, 2026 - **Apply:** https://www.dice.com/job-detail/23c11778-451f-4fd9-96fb-2f5899741b6d ## About the Role * 5+ years in cloud security, application security, or a closely related security engineering discipline * Deep hands-on experience with AWS security services (Security Hub, GuardDuty, IAM, SCPs, CloudTrail) and cloud posture tooling - Wiz experience strongly preferred * Practical AppSec experience: you've integrated SAST/DAST/SCA tooling into CI/CD pipelines and worked directly with developers to resolve findings, not just filed tickets * Experience with cloud identity platforms - Entra ID / Azure AD, including conditional access policy design and enforcement * Ability to write infrastructure-as-code and scripting to automate security controls (Python, Terraform, or equivalent), including comfort working with LLM APIs, prompt engineering, and agentic orchestration frameworks * Demonstrated experience building AI-augmented security workflows - you've used LLMs, agentic frameworks, or AI-assisted tooling to automate security tasks at scale, not just experimented with ChatGPT. You should be able to articulate which security problems are well-suited to AI automation and which aren't. * Strong enough communication skills to be credible with engineering leadership and portfolio company CTOs - you'll be in technical design reviews, not just security reviews Proven ability to build trusted working relationships with Infrastructure & Operations teams - you approach I&O as a partner, not a gatekeeper, and can influence security outcomes through collaboration rather than mandate * Comfort operating as a self-directed practitioner in a lean team; this role requires you to set your own execution priorities within a defined strategic direction Nice to Have * Experience securing ML/AI platforms - Bedrock, SageMaker, or comparable environments * AWS Security Specialty, GWEB, OSCP, or equivalent certification * Experience in a portfolio company or multi-entity security model * Familiarity with HIPAA technical safeguard requirements and PHI data flows in cloud environments * Experience designing or operating agentic AI workflows for security operations * Container and Kubernetes security experience (EKS, image scanning, network policy) ## Description The Information Security team has strong detection and response capability and a maturing compliance program. This is a greenfield opportunity to build Flagship's cloud security and application security engineering practice in earnest - with the CISO and Director of Security Engineering as your strategic partners and a well-resourced program behind you. You'll define how cloud posture management, SSDLC security, and cloud-side DLP get done at Flagship - in deep partnership with the Infrastructure & Operations team, who are your primary counterparts for cloud architecture, network, and endpoint infrastructure. What makes this role distinctive is the expectation that you'll build AI-augmented workflows from the start - using LLMs and agentic tooling to handle the routine 80% so your expertise stays focused on the 20% that actually requires human judgment. If you want to own a practice area rather than execute someone else's playbook, this is that role. You'll own the technical execution of cloud security and AppSec across Flagship and its portfolio, working directly with engineering teams to embed security into their pipelines, not just review them after the fact. What You'll Own * Cloud security posture management: own remediation execution against Wiz findings in close partnership with Infrastructure & Operations - building shared remediation playbooks, coordinating finding resolution across AWS environments, and ensuring security controls are implemented consistently with I&O's infrastructure standards * CI/CD and SSDLC security: design and implement security guardrails in engineering pipelines - SAST, secrets scanning, IaC security, container scanning - working directly with portfolio engineering teams, and building AI-powered pipeline security automation (e.g., LLM-assisted code review, automated fix suggestions for SAST findings) that reduces developer friction and scales security coverage beyond what manual review allows * Cloud-side DLP enforcement: build and operationalize data loss prevention controls at the cloud and application layer, not just policy definition * Cloud identity and access: own technical execution on Entra/Azure AD conditional access, BYOD policy enforcement, and cloud identity governance in partnership with Infrastructure & Operations, who manage the underlying directory and endpoint infrastructure * Detection engineering (cloud layer): write and tune cloud-side detection rules and contribute to alert fidelity improvements in partnership with the SOC * AI platform security: contribute to security architecture reviews and guardrail design for AI-powered portfolio products, including Bedrock and EKS-based platforms * Serve as the embedded security engineering partner for portfolio company engineering teams - not a reviewer at the end of the process, but a collaborator throughout it * Design and maintain AI-augmented workflows across all functional areas you own - using LLMs, agentic tooling, and automation to multiply your own capacity. You'll be expected to treat AI as a core part of your engineering toolkit, not an experiment: building prompt-driven triage pipelines, automating remediation drafting, and continuously identifying where human judgment is the bottleneck versus where it's being wasted on pattern-matchable work., This is a net-new capability role on a small team - you won't be executing someone else's existing playbook, you'll be building the cloud and AppSec program from a solid foundation. You'll work directly with the CISO and collaborate closely with the Director of Security Engineering. Flagship's portfolio spans some of the most technically ambitious biology and AI work happening anywhere, and the security work reflects that complexity. If you want a role where the scope is real, the autonomy is genuine, and you have the freedom to build an AI-augmented security practice - this is it. ## Related Videos - [ Evaluating AI models for code comprehension](https://www.wearedevelopers.com/videos/1462-evaluating-ai-models-for-code-comprehension) - [Infrastructure as Code: The Developer's Secret Weapon](https://www.wearedevelopers.com/videos/1221-infrastructure-as-code-the-developer-s-secret-weapon) - [Understanding Kubernetes in a visual way](https://www.wearedevelopers.com/videos/100085-understanding-kubernetes-in-a-visual-way) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Streaming AI Responses in Real-Time with SSE in Next.js & NestJS](https://www.wearedevelopers.com/videos/1630-streaming-ai-responses-in-real-time-with-sse-in-next-js-nestjs) - [Real-World Security for Busy Developers](https://www.wearedevelopers.com/videos/1545-real-world-security-for-busy-developers) ## Related Articles - [7 Cloud Computing Trends Coming in 2025 for Developers](https://www.wearedevelopers.com/magazine/412-7-cloud-computing-trends-coming-in-2025-for-developers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Got AI ideas but no money? Here are 10 free ways to level up your AI skills with Google Cloud](https://www.wearedevelopers.com/magazine/600-got-ai-ideas-but-no-money-here-are-10-free-ways-to-level-up-your-ai-skills-with-google-cloud)