Cloud Security Engineer

LHH
San Francisco, CA, United States
10 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
8 years minimum
Compensation
$180,000.0 - $250,000.0
Working hours
Regular working hours
Job source

Tech stack

Kubernetes Security Artificial Intelligence Amazon Web Services Microsoft Azure Software as a Service Cloud Computing Cloud Computing Security Computer Networks Continuous Integration Octopus Deploy Open Web Application Security Role-Based Access Control
+13 more
Reliability Engineering Azure Machine Learning Software Vulnerability Management Policy as Code Large Language Models Kubernetes Infrastructure Automation Frameworks Microsoft Sentinel Terraform Devsecops Key Vault Static Application Security Testing Dynamic Application Security Testing

Job description

About the role: Our client is building a cloud-native, agentic AI SaaS platform on an Azure-native stack and are looking for a hands-on Sr. Cloud Security Engineer to own the intersection of platform engineering, cloud security, and DevSecOps automation. This person will turn security controls into code, strengthen the platform before go-to-market, and help protect developer velocity while raising the company’s security and compliance posture., * Build, author, and operate secure infrastructure as code using Terraform, including reusable modules and plans created from scratch rather than only maintaining existing templates.

  • Own Kubernetes platform security for AKS, including hardened baselines, network policy, admission control, runtime protection, and practical hands-on implementation of security controls.
  • Drive GitOps delivery with Argo CD, including AKS manifest drift management, release automation, controlled deployment workflows, and rollback or failback patterns where needed.
  • Build and operate secure CI/CD pipelines with SAST, DAST, dependency, container, and infrastructure scanning as automated quality gates without unnecessarily slowing engineering teams.
  • Implement policy-as-code and Azure-native controls across the cloud landing zone, including Azure Policy and secure patterns for identity, access, and privileged operations.
  • Operate and tune Azure security tooling, including Microsoft Defender for Cloud, Microsoft Sentinel, Key Vault, Entra ID, RBAC, managed identities, and PIM.
  • Partner with engineering and SRE to define monitoring policies, alert triggers, and incident response workflows for the platform.
  • Help operationalize the vulnerability management program, including remediation workflows, prioritization, ownership, and reduce false positives across scanning and WAF-related processes.
  • Support secure software supply chain practices, including signed images, SBOMs, provenance, hardened base images, and policy-enforced registries.
  • Contribute technical evidence and automation to support ISO 27001 / 42001 and SOC 2 certification efforts, in partnership with GRC and infrastructure stakeholders.

Requirements

  1. Required: 8+ years of experience across DevOps, SRE, cloud security, security engineering, or platform engineering, with senior-level depth and a track record of building in fast-moving environments.
  2. Required: Deep hands-on experience with Terraform, including writing modules or plans from scratch and applying infrastructure-as-code practices across environments.
  3. Required: Strong Kubernetes and container security experience, preferably with AKS in production or near-production environments.
  4. Required: GitOps experience with Argo CD strongly preferred; Flux experience is also relevant if you can quickly adapt to Argo CD.
  5. Required: Enterprise-grade DevSecOps capability across CI/CD security, scanning automation, policy-as-code, vulnerability management, incident response, and secure release practices.
  6. Required: Azure security depth is preferred, including Defender for Cloud, Sentinel, Entra ID, managed identities, RBAC, PIM, Key Vault, ACR, and Azure networking. Strong AWS or GCP cloud security experience may be considered if paired with the ability to ramp quickly in Azure.
  7. Required: Experience contributing to compliance or certification efforts such as ISO, SOC 2, NIST, or similar frameworks, especially through evidence automation or control implementation.
  8. Required: Ability to work independently, identify where you can add value, and execute with limited technical oversight in a startup-style build environment.
  9. Required: Clear communication, sound judgment, low ego, professionalism, and a collaborative approach to working with engineering, infrastructure, security, and GRC partners.
  10. Nice to have: AI/ML platform security exposure, including Azure AI Foundry, OWASP LLM Top 10, MITRE ATLAS, or NIST AI RMF.
  11. Nice to have: Azure security certifications such as AZ-500 or SC-100, Kubernetes security certifications such as CKS, or other relevant cloud/security credentials.
  12. Nice to have: Experience in high-growth SaaS, startup, platform engineering, or product-led environments where security must be embedded into how software is built and shipped.

Benefits & conditions

  • $180k to $250k + equity (DOE)
  • Medical, dental, and vision insurance
  • 401(k) plan w/match
  • 19 days of PTO + 11 paid holidays

About the company

LHH is seeking a Sr. Cloud Security Engineer to join our client’s team in a full-time + hybrid-role, based in San Francisco, CA. This is an emerging enterprise intelligence startup focused on enabling organizations to effectively manage and optimize a blended workforce of human employees and autonomous AI systems.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.lhh.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

1:34 min

Essential commands for running and testing Terraform configurations

Hennie Francis · LIVE

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

4:55 min

Centralizing credentials management using Azure Key Vault resource integration

Marcel Lupo · LIVE

2:09 min

Shifting security left using the DevSecOps approach

Aarno Aukia · LIVE

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · WWC 2022

Videos

See all

Related articles

See all