Senior Cloud Security Engineer
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+33 more
Job description
We are seeking an experienced Senior Cloud Security Engineer to design, harden, and defend our multi-cloud environments. In this role, you will lead the architecture and implementation of cloud security controls across network boundaries, IAM policies, workload protection, and CI/CD pipelines. You will collaborate directly with DevOps, Infrastructure, and Software Engineering teams to integrate security into the development lifecycle (DevSecOps), ensure compliance with industry frameworks, and proactively identify and mitigate cloud vulnerabilities., * Cloud Security Architecture: Design and implement security controls, landing zones, and hardening frameworks across [AWS / Azure / GCP] aligned with CIS benchmarks and NIST guidelines.
- Identity & Access Management (IAM): Architect fine-grained IAM policies, enforce the principle of least privilege, manage SSO/MFA integrations, and audit privileged access across all cloud infrastructure.
- DevSecOps & Pipeline Security: Embed static and dynamic security analysis (SAST/DAST), dependency scanning, and container security into automated CI/CD deployment pipelines.
- Posture Management & Threat Detection: Configure and manage Cloud Security Posture Management (CSPM), Cloud Workload Protection (CWPP), and SIEM/SOAR integration for automated threat detection and alerting.
- Infrastructure as Code (IaC) Security: Scan and validate Terraform, CloudFormation, or Kubernetes manifests using security tools (e.g., Checkov, tfsec, Trivy) prior to production deployment.
- Incident Response & Threat Hunting: Serve as a technical lead for cloud security incidents, conduct root-cause analyses, perform threat hunting, and implement remediation measures.
- Compliance & Auditing: Drive technical readiness for SOC 2 Type II, ISO 27001, HIPAA, or PCI-DSS audits, ensuring continuous compliance across all cloud environments.
Requirements
- Experience: 5+ years of dedicated hands-on experience in cloud security engineering, DevSecOps, or infrastructure security.
- Multi-Cloud Security: Deep expertise securing core native cloud services, networks, and storage within [AWS / Azure / GCP].
- Container & Orchestration Security: Strong practical knowledge of securing Docker containers and Kubernetes clusters (EKS/AKS/GKE), including network policies, runtime security (e.g., Falco), and image signing.
- Automation & Scripting: Proficiency in scripting/programming with Python, Bash, or Go to automate security controls, compliance checks, and incident response tasks.
- IaC Security: Hands-on experience enforcing security standards in Terraform, CloudFormation, or Ansible.
- Security Tooling: Experience with cloud security platforms (e.g., Wiz, Orca Security, Palo Alto Prisma Cloud, Datadog Security, AWS GuardDuty).
- Networking & Encryption: Solid understanding of cloud networking security (VPC peering, Transit Gateways, WAF, DDoS protection) and cryptographic protocols (TLS, KMS, key management)., * Industry-recognized certifications such as CCSP, AWS Certified Security - Specialty, Certified Kubernetes Security Specialist (CKS), CISSP, or Azure Security Engineer Associate.
- Proven track record of automating security remediation actions using serverless logic (e.g., AWS Lambda, Azure Functions).
- Bachelor’s degree in Computer Science, Information Security, or a related technical discipline.
Benefits & conditions
Pulled from the full job description 401(k) Health insurance 401(k) matching Paid time off Vision insurance Dental insurance Life insurance, * Salary: $[Base Salary Range] per year (commensurate with experience)
- Health & Wellness: Comprehensive medical, dental, and vision insurance
- Retirement: 401(k) matching plan
- PTO: Generous Paid Time Off, sick leave, and paid company holidays
- Professional Growth: Dedicated annual budget for security certifications, labs, and industry conferences (e.g., AWS re:Inforce, DEF CON)
Pay: $77,000.00 - $80,000.00 per year, * 401(k)
- Dental insurance
- Health insurance
- Life insurance
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
7 Cloud Computing Trends Coming in 2025 for Developers
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
Why Upskilling And Reskilling is Important For Developers
How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again