> Markdown version of [/jobs/ext/2211133-security-engineer](https://www.wearedevelopers.com/jobs/ext/2211133-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer - **Company:** BINGHAMTOM UNIVERSITY - **Location:** United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Automation of Tests, Microsoft Azure, Cyber Security, Continuous Integration, Groovy, Information Security Management, Python (Programming Language), PCI Data Security Standards, Windows PowerShell, Ruby, Software Engineering, Spinnaker, Systems Integration, Software Vulnerability Management, Policy as Code, Scripting, Google Cloud, Git, Information Technology, CIS Benchmarks, Terraform, Prisma Cloud Platform, Autodesk Autocad, Jenkins, Artifactory - **Published:** August 24, 2026 - **Apply:** https://www.themuse.com/jobs/autodesk/principal-security-engineer-secure-posture-management?utm_source=uconnect ## About the Role * Bachelor's degree in computer science, information security, or a related field. * 8+ years of experience in information security or development, with a focus on secure configuration, enterprise security, cloud security, posture management, and vulnerability management. * Deep understanding of secure configuration and hardening frameworks, such as CIS Benchmarks, DISA STIG, NIST 800-53/190. * Strong proficiency in development, building automation and security tooling, such as Git, Artifactory, Jenkins, Spinnaker, scripting languages such as Python, PowerShell, Groovy or Ruby. * Extensive experience with CSPM tools and secure configuration tools and platforms such as Tenable, Prisma Cloud, Orca, or Wiz. * Experience in developing/managing golden image pipelines, CI/CD and IaC templates (Terraform). * Hands-on experience with cloud providers, AWS, Azure or GCP, and strong knowledge of native security services. Preferred Qualifications * Master's degree in computer science, information security, or a related field. * Certifications such as CISSP, CCSP, OSCP, AWS Security Specialty, or similar. * Hands-on experience across multiple cloud platforms: AWS, Azure, and GCP. * Expertise in secure software development, API automation, and integrating security checks into CI/CD pipelines. * Ability to design and deliver complex security automation at scale (IaC modules, policy-as-code, cloud guardrails). * Strong understanding of compliance frameworks (SOC2, ISO 27001, FedRAMP, PCI-DSS) as they relate to configuration and vulnerability management. * Proven ability to identify potential threats and vulnerabilities. * Ability to lead complex security projects, with hands-on experience to create and develop systems and services. * Lifelong learner with a commitment to continuous improvement. * Excellent written/verbal communication skills and ability to present complex security topics to non-technical stakeholders. ## Description We are seeking experienced and motivated Security Engineer who will develop and lead secure configuration and hardening efforts within our Secure Posture Management team. In this role, you will design, implement and advance Autodesk's Secure Posture Management strategy for secure configuration baselines, cloud hardening, IaC security, vulnerability visibility, and golden image pipelines. This role requires deep technical expertise, strong hands-on and automation skills, and the ability to influence engineering teams across the organization. You will collaborate and partner with diverse engineering teams across Autodesk. Your expertise in secure configuration, system hardening, and cloud security will ensure that Autodesk's systems, services, and platforms meet the highest security standards and align with industry best practices and regulatory requirements. Job Responsibilities * Define and execute a unified security posture management strategy including CSPM, secure configuration, golden image pipelines, IaC templates, and vulnerability management. * Develop and refine standards for secure cloud configurations in alignment with industry frameworks, such as CIS or NIST benchmarks. * Develop and maintain hardened baselines (CIS, NIST) across cloud environments, Windows, Linux, and container platforms. * Develop security artifacts, tooling and automations using tools such as Python, PowerShell, Groovy or Ruby. * Use Cloud Security Posture Management (CSPM) tooling to continuously monitor multiple cloud environments (AWS, Azure, GCP) for misconfigurations, security gaps and compliance issues. * Operate and optimize CSPM tooling and drive remediation of cloud misconfigurations. * Regularly reporting on security posture and mitigation progress to executive stakeholders. * Work with development teams to enhance features and ease of use for our golden image, Infrastructure as Code (IaC) pipelines, and embed secure configurations from design to runtime. * Monitor and remediate drift from security standards to ensure security across all environments. * Oversee the secure posture management program and lead remediation efforts across all cloud and data center assets. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Give your build some love, it will give it back!](https://www.wearedevelopers.com/videos/514-give-your-build-some-love-it-will-give-it-back) - [Coffee with Developers: David Heinemeier Hansson](https://www.wearedevelopers.com/videos/875-coffee-with-developers-david-heinemeier-hansson) - [How a Small Team Shrank a Microsoft Monorepo by 94%](https://www.wearedevelopers.com/videos/1236-how-a-small-team-shrank-a-microsoft-monorepo-by-94) - [AI-Native Enterprise Platforms: Interpreting Logic, Not Compiling Code](https://www.wearedevelopers.com/videos/1975-ai-native-enterprise-platforms-interpreting-logic-not-compiling-code) - [Coroutine explained yet again 60 years later](https://www.wearedevelopers.com/videos/690-coroutine-explained-yet-again-60-years-later) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [7 Important Tips That Every Software Developer Should Know](https://www.wearedevelopers.com/magazine/101-7-important-tips-that-every-software-developer-should-know) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)