> Markdown version of [/jobs/ext/2271342-cloud-security-specialist-platform-engineering](https://www.wearedevelopers.com/jobs/ext/2271342-cloud-security-specialist-platform-engineering). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cloud Security Specialist - Platform Engineering - **Company:** Xona Space Systems - **Location:** United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Amazon Web Services, Microsoft Azure, Cloud Computing Security, Cyber Security, Computer Networks, Continuous Integration, DevOps, Identity and Access Management, Python (Programming Language), Key Management, Network Segmentation, Role-Based Access Control, Cloud Services, Zero Trust Network Access, Security Information and Event Management, Policy as Code, Google Cloud, Cloud Platform System, Delivery Pipeline, SC Clearance, Containerization, Kubernetes - **Published:** August 27, 2026 - **Apply:** https://www.dice.com/job-detail/6393f7f3-413b-4517-baf9-0e3cd65f3f5e ## About the Role * Experience: 4+ years of experience in cloud security, DevOps, or platform engineering, with a strong emphasis on security operations and architecture. * Cloud Expertise: Deep hands-on experience securing cloud environments (AWS, Google Cloud Platform, or Azure). Certifications such as AWS Certified Security, CISSP, or CCSK are a plus. * Container & Kubernetes Security: Strong understanding of containerization security best practices, and Kubernetes security controls (RBAC, network policies, runtime security). * Scripting & Automation: Proficiency in languages such as Python, Go, etc. and experience with automation tools. * Security Tooling: Familiarity with CI/CD security integrations, Software Bill of Materials (SBOM), Security Information and Event Management (SIEM), and cloud security posture management (CSPM) tools. Preferred Qualifications * Experience implementing Zero Trust architectures within a modern enterprise. * Familiarity with Policy-as-Code frameworks (e.g., Open Policy Agent). * Demonstrated passion for developer enablement and building "security as a product" rather than a roadblock. * Hands-on experience running offensive security scenarios or red-team exercises for distributed, highly available cloud environments. For U.K. Roles: To comply with U.K. regulations, this role requires Baseline Personnel Security Standard (BPSS) checks, and successful candidates must be eligible to obtain UK Security Clearance (SC). ## Description We are looking for a Cloud Security Engineer to embed security into the core of our Platform Engineering team. In this role, you will design, implement, and automate security guardrails across our AWS infrastructure and deployment pipelines. Rather than acting as a traditional compliance gatekeeper, you will focus on building secure defaults, automated policy enforcement, and self-service security tools that empower engineering teams to move fast without compromising safety. Working closely with architecture, DevOps, and enterprise security, you will deliver secure foundational services, automate compliance, and help maintain high security standards across the entire engineering organization. Key Responsibilities * Cloud Security Architecture & Hardening: Design and enforce secure cloud patterns, zero-trust network segmentation, and hardening standards across our AWS multi-account architecture and container platforms (e.g., Kubernetes). * Identity and Access Management (IAM): Architect secure authentication, authorization, secrets management, and zero-trust networking principles across all platform services. * Automation & Guardrails: Build automated security guardrails that empower developers to move fast safely, minimizing friction while maintaining strict compliance standards (e.g., CMMC, NIST 800-171). * Threat Management & Incident Response: Conduct regular security assessments and threat modeling. Partner with SRE and operations teams to monitor security telemetry, triage cloud threats, and participate in incident response and root-cause analysis. ## Related Videos - [Kubernetes Security Best Practices](https://www.wearedevelopers.com/videos/1411-kubernetes-security-best-practices) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [Understanding Kubernetes in a visual way](https://www.wearedevelopers.com/videos/100085-understanding-kubernetes-in-a-visual-way) - [Kubernetes Security - Challenge and Opportunity](https://www.wearedevelopers.com/videos/412-kubernetes-security-challenge-and-opportunity) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [DevOps Maturity Check – a way to balance autonomy and alignment](https://www.wearedevelopers.com/videos/58-devops-maturity-check-a-way-to-balance-autonomy-and-alignment) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [7 Cloud Computing Trends Coming in 2025 for Developers](https://www.wearedevelopers.com/magazine/412-7-cloud-computing-trends-coming-in-2025-for-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)