Sr. Cloud Security Engineer

Akaasa Technologies
Hollywood, FL, United States
24 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$62,400.0 - $83,200.0
Working hours
Regular working hours

Tech stack

Microsoft Windows Application Programming Interfaces (APIs) Artificial Intelligence Amazon Web Services Microsoft Azure Software as a Service Cloud Computing Cloud Computing Security Cloud Database Cloud Engineering Cyber Security Data Security
+40 more
DDoS Mitigation Domain Name System (DNS) Identity and Access Management Intrusion Detection and Prevention Virtual Private Networks (VPN) Python (Programming Language) Key Management Network Security Routing OAuth PCI Data Security Standards Windows PowerShell Azure Active Directory Cloud Services Zero Trust Network Access Salesforce.Com Systems Integration Software Vulnerability Management Policy as Code Network Switches Cloud-native Network Functions (CNF) Scripting Google Cloud Cloud Platform System Large Language Models Software Security Multi-Cloud Firewalls (Computer Science) Cloudformation Palo Alto Networks Bicep Hashicorp Cloudflare CIS Benchmarks SailPoint Terraform Oracle Cloud Infrastructure Serverless Computing Workday Servicenow

Job description

Multi-Cloud Security Architecture & Engineering

  • Design, implement, and continuously harden secure landing zones, tenant baselines, and guardrails across Azure, AWS, Google Cloud, and Oracle Cloud Infrastructure - including hybrid and multi-cloud connectivity patterns
  • Develop and maintain cloud security standards, reference patterns, and secure-by-default blueprints that apply consistently across providers, not just one vendor’s stack
  • Lead security reviews and risk assessments for new cloud workloads, migrations, and modernization initiatives, providing actionable remediation guidance to engineering teams
  • Operate cloud-native application protection across the estate; posture management, workload protection, attack-path analysis, and drive findings to closure (Wiz, Microsoft Defender for Cloud)
  • Secure container and serverless platforms (AKS, EKS, GKE, Functions, Lambda, Cloud Run) including image supply chain, runtime policy, and registry hygiene

Cloud Identity, Entitlements & Non-Human Access

  • Engineer and secure identity and access across every provider’s native model - Microsoft Entra ID, AWS IAM and Identity Center, Google Cloud IAM, and OCI IAM - including federation, MFA, conditional access, and privileged access patterns
  • Implement least-privilege and cloud infrastructure entitlement management (CIEM), continuously right-sizing roles, permissions, and cross-account trust relationships
  • Govern non-human identities: service principals, workload identities, service accounts, API keys, and OAuth grants, across cloud and SaaS platforms (Astrix, HashiCorp Vault, Azure Key Vault)
  • Partner with the IAM team to integrate cloud and SaaS applications into enterprise identity governance and lifecycle processes (SailPoint ISC, Delinea)
  • Harden break-glass, root, and subscription-owner access across providers with monitored, auditable emergency-access procedures

Cloud Network Security & Zero Trust

  • Design and secure cloud networking across providers: VNets, VPCs, VCNs, transit and hub-spoke topologies, private connectivity, DNS, and cloud firewalls (Azure Firewall, AWS Network Firewall, Palo Alto Networks)
  • Enforce segmentation and zero-trust access between cloud workloads, on-premises environments, and third parties, in partnership with the network security team (Zscaler, Cloudflare)
  • Eliminate public exposure paths: open storage, permissive security groups, unintended internet-facing services, through preventive guardrails and continuous detection
  • Secure hybrid connectivity (ExpressRoute, Direct Connect, Interconnect, FastConnect, site-to-site VPN) with encryption, routing, and inspection controls
  • Protect internet-facing cloud applications with WAF, DDoS mitigation, and API security controls (Cloudflare, Salt)

Threat Detection, Incident Response & Vulnerability Management

  • Monitor, investigate, and respond to cloud and SaaS security incidents end-to-end, conducting root cause analysis and driving corrective actions
  • Operate and tune cloud-native detection services across providers: Microsoft Defender, AWS Security Hub and GuardDuty, Google Security Command Center, and OCI Cloud Guard, normalizing findings into enterprise workflows
  • Engineer cloud telemetry pipelines, activity logs, control-plane audit logs, flow logs, SaaS audit events, that route, shape, and enrich data for cost-effective analysis (Cribl, Trellix Helix)
  • Manage cloud vulnerability and exposure findings, prioritizing by exploitability and attack path rather than raw severity (Wiz, Rapid7)
  • Develop cloud-focused detections mapped to attacker techniques for control-plane abuse, identity compromise, and data exfiltration scenarios

SaaS & Data Security

  • Assess and continuously harden the security posture of enterprise SaaS applications - collaboration, HR, ITSM, and business platforms such as Microsoft 365, Workday, ServiceNow, and Salesforce-class services
  • Govern third-party app integrations, OAuth consent, and SaaS-to-SaaS connections that create unmonitored data paths (Astrix)
  • Implement data protection controls across cloud and SaaS: classification, DLP, encryption, and key management, in partnership with privacy and compliance teams (Microsoft Purview, Zscaler)
  • Monitor SaaS audit telemetry for account compromise, anomalous access, and risky configuration changes, feeding high-fidelity findings to the SOC
  • Establish security baselines and onboarding requirements for new SaaS platforms before they reach production use

Automation, IaC, Governance & Collaboration

  • Codify cloud security guardrails as policy-as-code and infrastructure-as-code so environments are secure by default (Terraform preferred; Bicep, CloudFormation)
  • Leverage AI/ML and large language models to analyze cloud and SaaS telemetry at scale, accelerate alert triage and enrichment, and automate reporting and documentation
  • Build and maintain security automations, integrations, and response playbooks across the cloud stack using APIs and SOAR (Torq; Python, PowerShell)
  • Support Cybersecurity Strategy & Governance, audit, and privacy programs by automating evidence collection and continuous control monitoring for cloud controls (Onspring, TrustArc)
  • Evaluate emerging cloud and SaaS security technologies, provide technical leadership across IT teams, and participate in an on-call rotation for a 24/7 gaming and hospitality environment

Requirements

  • 5+ years of experience across cloud engineering, cloud security, and cybersecurity engineering in enterprise environments
  • Genuine multi-cloud expertise: expert-level, hands-on experience in at least one major cloud (Azure, AWS, or Google Cloud) and strong working proficiency across the others, including exposure to Oracle Cloud Infrastructure, with the ability to translate security concepts fluently between providers rather than defaulting to a single vendor’s toolset
  • Cloud identity depth across providers: hands-on experience with Microsoft Entra ID, AWS IAM / Identity Center, Google Cloud IAM, and/or OCI IAM federation, MFA, conditional and context-aware access, privileged access, and workload/non-human identity
  • Practical experience applying AI/ML or large language models to cloud data analysis, detection, triage, or automation
  • Experience designing and securing cloud architectures, hybrid environments, and cloud networking, VNets, VPCs, VCNs, VPNs, private connectivity, firewalls, and zero-trust patterns, on more than one platform
  • Hands-on experience with cloud-native security services across providers (Microsoft Defender and Sentinel, AWS Security Hub and GuardDuty, Google Security Command Center, OCI Cloud Guard) plus third-party CNAPP/CSPM platforms
  • Experience securing SaaS applications and their integrations: posture hardening, OAuth and third-party app governance, audit telemetry, and data protection, across platforms such as Microsoft 365, Workday, ServiceNow, and similar enterprise services
  • Strong Infrastructure as Code and automation proficiency: Terraform (preferred), plus scripting in Python and PowerShell; experience embedding security checks into CI/CD pipelines
  • Strong understanding of cloud governance, regulatory compliance (PCI-DSS, SOX, tribal gaming regulations), risk management, and security best practices
  • Relevant certifications preferred: AWS Security Specialty, Google Professional Cloud Security Engineer, Microsoft AZ-500 or SC-100, Oracle Cloud Security Professional, CCSP, CISSP, and/or HashiCorp Terraform Associate, multi-provider credentials valued over depth in a single vendor track

About the company

Field Service Engineer Corporate Technologies is a leading provider of managed IT solutions to businesses and institutions in Minnesota, Michigan, North Dakota, Southern Californ…

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.careerjet.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

6:13 min

Defining cloud proficiency by technical role

Piet Van Dongen · LIVE

6:22 min

Eliminating HR bureaucracy and trusting employees

Rudi Bauer Rudi Bauer +1 · Cappuccino with HR

2:56 min

Provisioning a secure container infrastructure with Bicep

Matthias Falkenberg +1 · WWC 2022

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · WWC Europe 2026

1:34 min

Pivoting careers into specialized platform engineering roles

Xavier Portilla Edo · LIVE

5:06 min

Primary reasons for capability gaps in modern recruitment systems

Rudi Bauer Rudi Bauer +1 · Cappuccino with HR

Videos

See all

Related articles

See all