Senior Cloud Security Engineer

PRYZM CONSULTING LLC
Charlotte, NC, United States
about 1 month ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$77,000.0 - $80,000.0
Working hours
Regular working hours
Job source

Tech stack

Kubernetes Security Amazon Web Services Microsoft Azure Bash Shell Cloud Computing Cloud Computing Security Cyber Security Computer Programming Computer Networks Continuous Integration DDoS Mitigation DevOps
+33 more
Cryptographic Protocols Identity and Access Management Information Security Management Intrusion Detection and Prevention Python (Programming Language) Key Management PCI Data Security Standards Peering Ansible Security Information and Event Management Software Deployment Software Engineering Tripwire Datadog Scripting Delivery Pipeline Multi-Cloud AWS Lambda Infrastructure as Code (IaC) Amazon Virtual Private Cloud (VPC) Cloudformation Containerization Kubernetes Information Technology Cybercrime CIS Benchmarks Terraform Prisma Cloud Platform Devsecops Serverless Computing Docker Static Application Security Testing Dynamic Application Security Testing

Job description

We are seeking an experienced Senior Cloud Security Engineer to design, harden, and defend our multi-cloud environments. In this role, you will lead the architecture and implementation of cloud security controls across network boundaries, IAM policies, workload protection, and CI/CD pipelines. You will collaborate directly with DevOps, Infrastructure, and Software Engineering teams to integrate security into the development lifecycle (DevSecOps), ensure compliance with industry frameworks, and proactively identify and mitigate cloud vulnerabilities., * Cloud Security Architecture: Design and implement security controls, landing zones, and hardening frameworks across [AWS / Azure / GCP] aligned with CIS benchmarks and NIST guidelines.

  • Identity & Access Management (IAM): Architect fine-grained IAM policies, enforce the principle of least privilege, manage SSO/MFA integrations, and audit privileged access across all cloud infrastructure.
  • DevSecOps & Pipeline Security: Embed static and dynamic security analysis (SAST/DAST), dependency scanning, and container security into automated CI/CD deployment pipelines.
  • Posture Management & Threat Detection: Configure and manage Cloud Security Posture Management (CSPM), Cloud Workload Protection (CWPP), and SIEM/SOAR integration for automated threat detection and alerting.
  • Infrastructure as Code (IaC) Security: Scan and validate Terraform, CloudFormation, or Kubernetes manifests using security tools (e.g., Checkov, tfsec, Trivy) prior to production deployment.
  • Incident Response & Threat Hunting: Serve as a technical lead for cloud security incidents, conduct root-cause analyses, perform threat hunting, and implement remediation measures.
  • Compliance & Auditing: Drive technical readiness for SOC 2 Type II, ISO 27001, HIPAA, or PCI-DSS audits, ensuring continuous compliance across all cloud environments.

Requirements

  • Experience: 5+ years of dedicated hands-on experience in cloud security engineering, DevSecOps, or infrastructure security.
  • Multi-Cloud Security: Deep expertise securing core native cloud services, networks, and storage within [AWS / Azure / GCP].
  • Container & Orchestration Security: Strong practical knowledge of securing Docker containers and Kubernetes clusters (EKS/AKS/GKE), including network policies, runtime security (e.g., Falco), and image signing.
  • Automation & Scripting: Proficiency in scripting/programming with Python, Bash, or Go to automate security controls, compliance checks, and incident response tasks.
  • IaC Security: Hands-on experience enforcing security standards in Terraform, CloudFormation, or Ansible.
  • Security Tooling: Experience with cloud security platforms (e.g., Wiz, Orca Security, Palo Alto Prisma Cloud, Datadog Security, AWS GuardDuty).
  • Networking & Encryption: Solid understanding of cloud networking security (VPC peering, Transit Gateways, WAF, DDoS protection) and cryptographic protocols (TLS, KMS, key management)., * Industry-recognized certifications such as CCSP, AWS Certified Security - Specialty, Certified Kubernetes Security Specialist (CKS), CISSP, or Azure Security Engineer Associate.
  • Proven track record of automating security remediation actions using serverless logic (e.g., AWS Lambda, Azure Functions).
  • Bachelor’s degree in Computer Science, Information Security, or a related technical discipline.

Benefits & conditions

Pulled from the full job description 401(k) Health insurance 401(k) matching Paid time off Vision insurance Dental insurance Life insurance, * Salary: $[Base Salary Range] per year (commensurate with experience)

  • Health & Wellness: Comprehensive medical, dental, and vision insurance
  • Retirement: 401(k) matching plan
  • PTO: Generous Paid Time Off, sick leave, and paid company holidays
  • Professional Growth: Dedicated annual budget for security certifications, labs, and industry conferences (e.g., AWS re:Inforce, DEF CON)

Pay: $77,000.00 - $80,000.00 per year, * 401(k)

  • Dental insurance
  • Health insurance
  • Life insurance

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:07 min

Inspecting default bridge architectures and custom Docker networks

Oliver Seitz Oliver Seitz · World Congress 2025

2:17 min

Mapping the maturity roadmap for scaled devops adoption

Dominik Krichbaum Dominik Krichbaum · World Congress 2026 Europe

1:36 min

Visualizing memory limits and isolating suspicious endpoints

Dina Matveev Dina Matveev · Europe 2026 Virtual

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

2:34 min

Docker sandbox architecture and microVM environment integration

Manuel de la Peña Manuel de la Peña · World Congress 2026 Europe

1:34 min

Pivoting careers into specialized platform engineering roles

Xavier Portilla Edo · LIVE

Videos

See all

Related articles

See all