Cloud Security Engineer

National Association of Insurance Commissioners
Kansas City, MO, United States
2 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$107,000.0 - $142,000.0
Working hours
Regular working hours
Job source

Tech stack

Kubernetes Security Microsoft Windows Artificial Intelligence Amazon Web Services Apple Mac Systems Microsoft Azure Software as a Service Cloud Computing Cloud Computing Security Cloud Engineering Cyber Security Computer Networks
+20 more
Continuous Integration Linux DevOps Infrastructure as a Service (IaaS) Identity and Access Management Key Management Network Security Platform as a Service (PAAS) Zero Trust Network Access Azure Machine Learning Cloud Platform System Firewalls (Computer Science) Gitlab Cloudformation Containerization Kubernetes Infrastructure Automation Frameworks CIS Benchmarks Terraform Oracle Cloud Infrastructure

Job description

The Security, Risk, and Compliance division of the National Association of Insurance Commissioners (NAIC) has an exciting opportunity for a Cloud Security Engineer. This position is responsible for defining, implementing, and maintaining the security architecture of the organization’s cloud and cloud-native environments. This role partners closely with Cloud Engineering, DevOps, Compliance, and Risk teams to ensure cloud platforms-including Kubernetes and emerging AI-enabled technologies-are designed and operated securely, in alignment with regulatory requirements, security best practices, and organizational risk tolerance. This is a full-time hybrid position, in a positive and flexible environment. Residency within 100 miles of the Kansas City office is required., * Design, implement, and maintain secure cloud architectures across IaaS, PaaS, and SaaS platforms (e.g., AWS, Azure, OCI), including security guardrails and standards.

  • Develop and maintain cloud security standards and documentation and ensure cloud architecture designs align with said standards and risk management requirements.
  • Lead security architecture and controls for containerized and Kubernetes-based workloads, including cluster hardening and secure configuration, workload isolation and network policies, secrets management and key rotation, and container image security and supply chain integrity.
  • Collaborate with DevOps teams on container security tooling, runtime protection, and secure CI/CD pipelines.
  • Contribute to the development and architecture of an organizational AI security strategy, including governance, acceptable use, and risk controls.
  • Translate regulatory and compliance requirements (e.g., SOC 2, NIST, ISO 27001, GovRAMP) into actionable cloud security controls.
  • Evaluate and implement cloud security posture management (CSPM), container security, CI/CD security, and cloud-native security tools.

Management Responsibilities:

This position does not have direct reports., This position does not require overnight business travel. Employees are responsible for their personal transportation to/from the home and office, including events, meetings, and training required by the NAIC.

Requirements

  • Bachelor’s degree (B.A. or B.S.) from four-year College or university in a computer related field and 5+ years of experience in information security, with significant focus on cloud environments, and/or equivalent combination of education and technical experience.
  • Hands-on experience securing AWS (Azure and OCI experience are a plus).
  • Practical experience securing Kubernetes and containerized workloads.
  • Familiarity with infrastructure-as-code and CI/CD security concepts.
  • Strong working knowledge of:
  • Cloud IAM and identity federation
  • Network security (VPCs/VNETs, firewalls, security groups)
  • Encryption, key management, and secrets handling
  • Ability to communicate complex security concepts clearly to technical and non-technical audiences., * Experience working in regulated or compliance-driven environments (e.g., SOC 2, GovRAMP, PCI, HIPAA).
  • Familiarity with frameworks such as NIST 800-53, CIS Benchmarks, or Zero Trust architectures.
  • Experience evaluating or securing AI/ML platforms or SaaS tools.
  • Experience with CSPM, container security, or cloud-native security tools (vendor-agnostic).
  • Relevant certifications (e.g., AWS Security Specialty, CCSK, CKS, CISSP) are a plus.

Systems & Technology Requirements:

  • AWS
  • Kubernetes & Container Technologies
  • Infrastructure-as-code tools (e.g., Terraform, CloudFormation, ARM, Gitlab)
  • Windows, Linux, and MacOS Endpoints
  • Identity & Access Management (IAM / IdP), Applicants must be authorized to work for any employer in the U.S. We are unable to sponsor or take over sponsorship of an employment Visa at this time.

Benefits & conditions

$107,000 - $142,000 commensurate with education and experience.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.jofdav.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:39 min

Understanding the four Cs of cloud native security

Rico Komenda Rico Komenda · World Congress 2025

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · World Congress 2025

6:14 min

Structuring CI/CD pipelines with integrated security and quality checks

Christoph Ruggenthaler · LIVE

2:17 min

Mapping the maturity roadmap for scaled devops adoption

Dominik Krichbaum Dominik Krichbaum · World Congress 2026 Europe

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

3:55 min

Demonstrating .NET installation on Debian and Azure Linux

Silvano Coriani Silvano Coriani · Europe 2026 Virtual

Videos

See all

Related articles

See all