> Markdown version of [/jobs/ext/1964114-security-engineer-cloud-security-aws](https://www.wearedevelopers.com/jobs/ext/1964114-security-engineer-cloud-security-aws). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer - Cloud Security (AWS) - **Company:** Xcel Energy Inc. - **Location:** Minneapolis, MN, United States - **Experience:** Expert - **Salary:** $97,600.0 - $138,600.0 - **Contract:** Permanent contract - **Skills:** SAP Cloud, Application Programming Interfaces (APIs), Amazon Web Services, Microsoft Azure, Cloud Computing Security, Cyber Security, Continuous Integration, Data Integration, DevOps, Identity and Access Management, Network Configuration and Change Management, SAP (Applications), Software Vulnerability Management, Data Logging, Scripting, Cloud Platform System, Software Security, SAPBasis, Devsecops - **Published:** August 7, 2026 - **Apply:** https://www.juju.com/job/00000000glv0m5 ## About the Role Are you looking for an exciting job where you can put your skills and talents to work at a company you can feel proud to be a part of? Do you want a workplace that will challenge you and offer you opportunities to learn and grow? A position at Xcel Energy could be just what you're looking for., + Minimum 5 years of experience in information security. + Strong hands-on experience with AWS cloud environments and security concepts. + Strong understanding of AWS IAM, networking, logging, monitoring, and workload security. + Experience using AWS native security tools such as Inspector, Security Hub, or equivalent. + Strong understanding of DevSecOps principles, CI/CD pipelines, and application security fundamentals. + Basic understanding of SAP environments in cloud-hosted architectures. + Experience identifying and communicating risk related to cloud configurations and architecture. + Strong analytical and complex technical problem-solving skills. + Ability to communicate technical risk clearly to non-technical stakeholders. + Experience with APIs, scripting, or automation for data integration and workflow execution. + Ability to operate independently and build a program with limited oversight. Preferred Qualifications + Experience across multiple cloud environments, including AWS multi-account and GovCloud architectures. + Experience supporting Azure cloud environments. + Experience implementing preventative security controls such as guardrails, policy enforcement, or pipeline gating. + Experience improving data quality and visibility across multiple cloud and security data sources. + Experience working with enterprise cloud platform, networking, or architecture teams. Certifications + AWS Certified Security - Specialty required. + AWS Certified Solutions Architect - Professional or AWS Certified DevOps Engineer - Professional preferred. Work Location Hybrid role requiring three days per week in the office. Must be located within Xcel Energy territory and reasonably close to an Xcel Energy facility. Denver, Colorado and Minnesota areas preferred. ## Description The Security Engineer - Cloud Security (AWS) is responsible for building and running the AWS cloud security program with a focus on reducing risk through visibility, guardrails, and automation. This role identifies and analyzes cloud security risk, drives remediation through stakeholders, and implements preventative controls to reduce exposure over time. The role operates in an advisory capacity and does not perform direct operational changes. Initial focus is AWS across commercial and GovCloud environments, with planned expansion to Azure once the AWS program is mature. This position reports to the Manager, Vulnerability Management. Primary Objectives + Build and mature the AWS cloud security program with clear ownership, processes, and workflows. + Identify, prioritize, and communicate cloud security risk across environments and stakeholders. + Implement preventative controls and guardrails to reduce risk before deployment. + Leverage automation and integration to reduce manual effort and improve consistency. + Support remediation by driving findings to the appropriate owners and tracking outcomes. Responsibilities + Serve as the primary cloud security engineer for AWS environments, including commercial, GovCloud, dev, and test accounts. + Use AWS native security capabilities such as Inspector, Security Hub, and related services to identify and analyze risk. + Maintain visibility across IAM, network configuration, logging, monitoring, and workload security posture. + Identify issues such as overly permissive access, unused accounts, misconfigurations, and exposure risks. + Develop and implement guardrails, policies, and controls to prevent insecure configurations and reduce attack surface. + Promote the use of hardened images, containers, and standardized builds to reduce risk at deployment. + Integrate cloud security findings into existing workflows and coordinate remediation with responsible teams. + Work closely with Cloud Platform, SAP, Enterprise Architecture, and other teams to implement meaningful security improvements. + Partner with Application Security teams to support DevSecOps practices, including CI/CD pipeline integration, gates, and automation. + Support SAP cloud security needs and maintain awareness of SAP-specific risks within AWS environments. + Use APIs, scripting, and integration to automate data collection, analysis, and workflow execution. + Analyze cloud risk in context and communicate clear, actionable recommendations to stakeholders. + Support logging and monitoring capabilities setup and integration while deferring operational ownership to SOC/IR teams. ## Related Videos - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [Flex your Energy: Building a Cloud-Native Platform for Renewable Energy Communities](https://www.wearedevelopers.com/videos/1990-flex-your-energy-building-a-cloud-native-platform-for-renewable-energy-communities) ## Related Articles - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [A Guide to Green Tech and Green IT Careers](https://www.wearedevelopers.com/magazine/374-a-guide-to-green-tech-and-green-it-careers) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries)