> Markdown version of [/jobs/ext/1809846-senior-cloud-security-engineer](https://www.wearedevelopers.com/jobs/ext/1809846-senior-cloud-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Cloud Security Engineer - **Company:** Humana Inc. - **Location:** Miami, FL, United States (Remote available) - **Experience:** Expert - **Salary:** $106,900.0 - $147,000.0 - **Contract:** Permanent contract - **Skills:** Agile Methodology, Systems Engineering, Microsoft Azure, Bash Shell, Cable Modem, Software as a Service, Cloud Computing Security, Cyber Security, Continuous Integration, DevOps, Github, Internet Services, Python (Programming Language), CURL, Linux System Administration, Windows PowerShell, Tcpdump, YAML, Policy as Code, Scripting, Network Access Control, Cloud Platform System, Software Security, Multi-Cloud, Firewalls (Computer Science), Infrastructure as Code (IaC), Information Technology, Deployment Automation, Palo Alto Networks, Hashicorp, Firewall Services Module, Terraform, Cyber Warfare, Prisma Cloud Platform, Devsecops - **Published:** July 7, 2026 - **Apply:** https://dejobs.org/x/x/2C24D21EF70743FC91D11B7A617A0A0B/job/ ## About the Role We are looking for an experienced professional with expertise in managing GCP Next-Generation Firewalls (NGFW) , Azure Network Security Groups (NSGs) , and the Prisma Cloud security suite . This role focuses on securing multi-cloud environments by automating security policies using Infrastructure as Code (IaC) with Terraform , while leveraging Prisma Cloud tools to ensure comprehensive workload protection and compliance., * Bachelor's Degree in Computer Science, Information Technology, Cybersecurity or related field. * 7+ years of experience supporting and implementing multi-cloud security solutions with a focus on GCP and Azure , including configuration, deployment, troubleshooting, and ongoing maintenance. * 3+ years of direct, hands-on experience with GCP network access control and Azure NSGs , leveraging IaC automation (Terraform) for efficient and secure cloud operations. * Proficiency in deploying and managing NGFW policies using security tags and hierarchical firewall rules within GCP . * Strong ability to manage and troubleshoot Azure NSGs , leveraging Terraform for automation and scaling. * Experience implementing security policies via IaC using Terraform and managing deployments through Azure DevOps (ADO) and GitHub Actions . * Expertise in DevSecOps and shift-left principles, actively ensuring security risks and misconfigurations are addressed early in the development process. * Ability to work in a 24x7 on-call rotation , triage incidents, and participate in incident bridges with senior leadership teams (SLT). * Proven experience in incident response and security operations, including assisting the SOC during critical events. * Capable of providing training and guidance to team members on cloud security best practices., * Certification in Prisma Certified Cloud Security Engineer (PCCSE) and/or Palo Alto Networks Systems Engineer - Prisma Cloud Associate desired. * Additional certifications such as CISSP , CCSP , Security+ , or relevant tracks for Azure and GCP . * Advanced experience with Terraform and managing large-scale IaC automation through CI/CD pipelines . * Experience implementing and managing Policy as Code (PaC) in cloud environments, including Azure Policy , GCP Organizational Policy , or HashiCorp Sentinel . * Familiarity with Agile methodology , including Scrum and Kanban frameworks. * Proficiency with scripting languages such as PowerShell , Python , YAML , and Bash . * Experience troubleshooting Linux environments using tools like cURL , tcpdump , netstat , etc. ## Description The Senior Cloud Security Engineer ensures that cybersecurity policies are engineered and deployed in cloud environments to meet compliance requirements. They automate cloud security controls to minimize and reduce threats, vulnerabilities, and risks. They ensure that cross-functional business processes are in place for cloud security control engineering and implementation, with proper visibility and approvals. The engineer begins to influence departmental strategy, makes decisions on moderately complex to highly complex issues regarding technical approaches for project components, and performs work without direction. They exercise considerable latitude in determining objectives and approaches to assignments., * Deploy and provide operational support for hierarchical NGFW policies in GCP using security tags, and automate configurations using Terraform and DevOps principles . * Manage and troubleshoot Azure Network Security Groups (NSGs) at scale, using Terraform to automate deployment, updates, and scaling of security rules across multiple environments, ensuring continuous network protection and performance. * Ensure all infrastructure changes are deployed through CI/CD pipelines using Terraform modules , following best practices for DevSecOps . * Develop and implement security policies, standards, and procedures for cloud-based applications and infrastructure employing Prisma Cloud's comprehensive security solutions, including Workload Protection (Compute) , Cloud Security Posture Management (CSPM) , and Code Security modules. * Integrate robust code security measures and scanning capabilities into CI/CD pipelines and other cloud workflows using IaC . * Implement and manage enterprise security policies using Prisma CSPM's advanced capabilities, including preventive guardrails and automated remediations, to ensure proactive measures are in place. * Leverage IaC and CI/CD to seamlessly deploy, patch, and upgrade Prisma Cloud and cloud-based security systems. * Configure vulnerability items, misconfigurations, and other alerts in Prisma Cloud , actively assisting stakeholders with timely remediation efforts. * Assist the SOC and Cyber Defense & Response Team during security incidents, involving timely configuration changes to Prisma and frequent participation on major incident bridges. * Manage user access in Prisma portal based on least privilege roles, and provide operations training and support, as needed. * Participate in a 24/7 on-call rotation to ensure rapid incident response, maintaining operational integrity and minimizing downtime across enterprise systems., * WAH requirements: Must have the ability to provide a high speed DSL or cable modem for a home office. Associates or contractors who live and work from home in the state of California will be provided payment for their internet expense. * A minimum standard speed for optimal performance of 25x10 (25mpbs download x 10mpbs upload) is required. * Satellite and Wireless Internet service is NOT allowed for this role. * A dedicated space lacking ongoing interruptions to protect member PHI / HIPAA information Work at Home Requirements To ensure Home or Hybrid Home/Office employees' ability to work effectively, the self-provided internet service of Home or Hybrid Home/Office employees must meet the following criteria: At minimum, a download speed of 25 Mbps and an upload speed of 10 Mbps is required; wireless, wired cable or DSL connection is suggested. In certain roles, the minimum recommended internet speed required by Humana may not be sufficient for business needs. Humana reserves the right to require associates to upgrade their internet service if necessary. Work from a dedicated space lacking ongoing interruptions to protect member PHI / HIPAA information. Travel: While this is a remote position, occasional travel to Humana's offices for training or meetings may be required. Scheduled Weekly Hours 40 ## Related Videos - [CI/CD with Github Actions](https://www.wearedevelopers.com/videos/856-ci-cd-with-github-actions) - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [Don’t Insert Crazy! On cURL and AI Slop - Daniel Stenberg](https://www.wearedevelopers.com/videos/1796-don-t-insert-crazy-on-curl-and-ai-slop-daniel-stenberg) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Bringing AI Model Testing and Prompt Management to Your Codebase with GitHub Models](https://www.wearedevelopers.com/videos/1536-bringing-ai-model-testing-and-prompt-management-to-your-codebase-with-github-models) - [Capture the Flag 101](https://www.wearedevelopers.com/videos/416-capture-the-flag-101) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [7 Cloud Computing Trends Coming in 2025 for Developers](https://www.wearedevelopers.com/magazine/412-7-cloud-computing-trends-coming-in-2025-for-developers) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Best Coding Boot Camps in Germany](https://www.wearedevelopers.com/magazine/237-best-coding-boot-camps-in-germany) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Top 6 Hackathons for Developers in 2023](https://www.wearedevelopers.com/magazine/263-top-6-hackathons-for-developers-in-2023)