Cloud & Application Security Engineer
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+25 more
Job description
The Cloud & Application Security Engineer will design, implement, validate, and operate security controls across our cloud infrastructure, applications, and software delivery pipelines. This role will partner with DevOps, various Engineering, and Security teams to build secure-by-default platforms that enable developers while reducing organizational risk.
This is a hands-on role requiring strong experience in cloud security architecture, application security testing, CI/CD pipeline hardening, and infrastructure-as-code security.
What will you do?
- Design, implement, and mature secure cloud architectures across AWS, Azure, and GCP, with a primary focus on GCP.
- Develop, audit, and harden cloud infrastructure, including IAM, networking, organization policies, logging, and Terraform-based Infrastructure-as-Code.
- Provide security architecture reviews and guidance for cloud applications, APIs, infrastructure, DevOps, and AI-assisted development.
- Perform application security assessments, secure code reviews, and hands-on testing of web applications, APIs, and cloud services using automated and manual techniques to identify vulnerabilities and drive remediation.
- Identify , prioritize, and remediate cloud and application vulnerabilities, including critical and zero-day threats.
- Lead evaluations, proof-of-concepts, and implementation of cloud and application security technologies.
- Secure AI platforms and AI-assisted development by implementing appropriate security controls and reviewing AI-assisted applications for security risks.
- Partner with Security Operations to improve cloud detection, monitoring, incident response, and security visibility.
- Provide exceptional experiences for our guests, partners, and team members, including by adhering to our appearance and presentation guidelines while on-site.
Requirements
- 4-6 years of related experience .
- Bachelor’s degree, or equivalent combination of education and experience .
- Experience securing enterprise cloud environments across AWS, Azure, and/or GCP, including Kubernetes.
- Strong understanding of cloud architecture, IAM, networking, cloud security controls, and Infrastructure-as-Code.
- Experience integrating security into CI/CD pipelines using Terraform and modern DevOps platforms.
- Proficiency in Python, PowerShell, Bash, Go, or a similar language, or demonstrated ability to leverage AI-assisted engineering tools to develop automation and security solutions.
- Hands-on experience with Wiz or a comparable CSPM/CNAPP platform.
- Experience with application security, including secure SDLC, threat modeling, secure code reviews, SAST, DAST, SCA, secret scanning, vulnerability management, remediation, and web application security testing.
- Strong understanding of web application security, REST APIs, authentication (OAuth/OIDC/JWT), and OWASP Top 10.
- Familiarity with AI security concepts and securing enterprise AI platforms or AI-assisted applications.
- Security certifications (e.g., CISSP, CCSP, AWS Security Specialty, Google Professional Cloud Security Engineer, AZ-500, CSSLP, or GWAPT) are a plus.
Benefits & conditions
Pay Range (Burbank): $130,000-$155,000
Pay Range (Las Vegas): $120,000-$140,000
LI-Onsite
Pay Range
$120,000 - $140,000 USD
At MSG, we recognize the importance of upskilling employees’ talents and strengths so they can drive their careers forward. We are proud to offer a robust set of tools and resources to help employees understand their interests and purpose, harness their talents and obtain the skills they need to reach the next step in their careers. Growth and longevity for our employees are top priorities here.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Understanding and Mitigating Common Web Vulnerabilities
Dev Digest 134 - Where pixels sing?
Dev Digest 132 - Binging WADFlix?
Dev Digest 120 - Apple and peers