Network Cloud Security Engineer

EOS Inc.
Austin, TX, United States
25 days ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours
Job source

Tech stack

Kubernetes Security Artificial Intelligence Amazon Web Services Audit Trail Microsoft Azure Cloud Computing Cloud Computing Security Cloud Database Cloud Engineering Cyber Security Computer Programming Continuous Integration
+29 more
DDoS Mitigation DevOps Federated Identity Management Github Identity and Access Management Intrusion Detection and Prevention Python (Programming Language) Key Management Network Security OpenID Role-Based Access Control Azure Active Directory Security Software Security Information and Event Management Data Logging Cloud-native Network Functions (CNF) Scripting Google Cloud Software Security Multi-Cloud Amazon Virtual Private Cloud (VPC) Kubernetes Infrastructure Automation Frameworks Cloudflare Terraform Ddos Devsecops Security Orchestration, Automation & Response Golang

Job description

We are seeking experienced Cloud Security Engineers to help secure and harden a complex, multi-cloud AI environment.

Engineers will work across one or more of four primary security workstreams:

  • Identity & Credential Security

  • Cloud Data-Plane & Network Security

  • Cloud Logging, Detection & Response

  • External Attack Surface & Kubernetes Security

The ideal candidate will have deep expertise in at least one or two of these areas and sufficient breadth to collaborate across the broader cloud-security program.

We are particularly interested in engineers who can take a security requirement and turn it into a working production control - including code, Terraform/IaC, automation, testing, documentation and operational handoff., Cloud Security Engineering

  • Design, implement and validate security controls across AWS, Azure and/or GCP.
  • Translate security requirements into production-ready technical solutions.
  • Develop and maintain infrastructure-as-code using Terraform or similar technologies.
  • Automate repetitive security and infrastructure processes using Python, Go, scripting or other appropriate tools.
  • Work directly with cloud infrastructure, platform, DevOps and security teams.
  • Troubleshoot complex cloud-security issues and develop practical remediation plans.
  • Test security controls and provide evidence of implementation and effectiveness.
  • Document technical designs, configurations, procedures and operational requirements.
  • Support rapid remediation of identified security gaps.

WORKSTREAM 1 - IDENTITY & CREDENTIAL SECURITY

Help eliminate long-lived and static credentials while improving identity attribution and least-privilege access.

Responsibilities may include:

  • Implementing workload identity and federation.
  • OIDC-based authentication.
  • IAM/RBAC design and implementation.
  • Short-lived credentials and token-based authentication.
  • Service-account and machine identity remediation.
  • AWS, Azure, GCP and GitHub identity integrations.
  • Credential discovery and remediation automation.
  • Preventive guardrails to prevent creation of new static credentials.
  • Least-privilege access controls.
  • Identity federation and access governance.

Ideal background: Cloud IAM, identity engineering, workload identity, OIDC, RBAC, federation and cloud security automation.

WORKSTREAM 2 - CLOUD DATA-PLANE & NETWORK SECURITY

Reduce the potential blast radius of compromised credentials, workloads and cloud resources.

Responsibilities may include:

  • GCP VPC Service Controls / service perimeters.
  • AWS security and organizational guardrails.
  • Azure identity federation and token exchange.
  • Cross-account and cross-tenant restrictions.
  • Data-access controls.
  • Egress allowlists and restrictions.
  • Cloud network security.
  • Segmentation and isolation.
  • Secure cloud landing zones.
  • Infrastructure-as-code implementation of security controls.

Ideal background: Cloud security architecture/engineering, cloud networking, AWS/GCP/Azure security controls and infrastructure automation.

WORKSTREAM 3 - CLOUD LOGGING, DETECTION & RESPONSE

Close visibility gaps and improve the ability to detect and respond to security events.

Responsibilities may include:

  • AWS CloudTrail and cloud audit logging.
  • Azure Activity Logs.
  • GCP logging and audit telemetry.
  • Kubernetes/AKS logging.
  • GitHub and application security telemetry.
  • SIEM integration.
  • Security detection engineering.
  • Behavioral analytics.
  • Alerting and monitoring.
  • Automated security response and credential containment.
  • Security-event investigation and remediation.
  • Building automation around security operations.

Ideal background: Cloud detection engineering, SIEM, security automation, cloud logging, SOC engineering and incident response.

WORKSTREAM 4 - EXTERNAL ATTACK SURFACE & KUBERNETES SECURITY

Reduce internet-facing exposure and harden cloud-native workloads.

Responsibilities may include:

  • Kubernetes/EKS/AKS/GKE security.
  • Container security.
  • Cloudflare WAF and DDoS controls.
  • Public-facing application protection.
  • Public storage exposure remediation.
  • Internet-facing resource inventory.
  • Cloud security posture management.
  • Vulnerability identification and remediation.
  • Wiz or comparable cloud-security platforms.
  • Kubernetes configuration and security hardening.
  • Helm/IaC-based security implementation.
  • Attack-surface validation and testing.

Ideal background: Kubernetes security, DevSecOps, cloud infrastructure security, WAF/DDoS, CSPM and attack-surface management.

Requirements

  • 5+ years of experience in cloud infrastructure, cloud security, DevSecOps, security engineering or a closely related discipline.
  • Strong hands-on experience with AWS, Azure and/or GCP.
  • Demonstrated experience implementing cloud security controls in production environments.
  • Strong understanding of cloud identity, access management and security architecture.
  • Experience with Terraform, infrastructure-as-code or comparable automation technologies.
  • Experience with scripting or programming, preferably Python, Go or similar.
  • Experience working with production infrastructure and troubleshooting complex technical issues.
  • Ability to collaborate directly with cloud infrastructure, platform, DevOps and security teams.
  • Strong technical documentation and communication skills.
  • Ability to work independently in a fast-moving, highly technical environment., * Experience across multiple cloud platforms, particularly AWS, Azure and GCP.
  • Kubernetes / EKS / AKS / GKE security experience.
  • OIDC, workload identity and federation.
  • GCP VPC Service Controls.
  • AWS organizational/security guardrails.
  • Azure Entra ID and cloud federation.
  • CloudTrail, Azure Activity Logs and GCP audit logging.
  • SIEM and security detection engineering.
  • Cloudflare, WAF and DDoS protection.
  • Wiz or comparable CSPM/CNAPP platforms.
  • DevSecOps and CI/CD security.
  • Secrets management.
  • Cloud incident response.
  • FedRAMP, NIST, IL4/IL5 or other high-compliance environments.
  • Experience supporting AI/ML or GPU-intensive infrastructure.
  • Experience in large-scale enterprise or hyperscale cloud environments., A candidate with deep expertise in one area and strong working knowledge across the others can be an excellent fit.

Benefits & conditions

The EOS pay range for this job is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, experience, education, knowledge, skills, and abilities, as well as internal equity, market data, or other laws.

About the company

EOS IT Solutions is a global technology and logistics company delivering complex technology infrastructure, deployment and managed services to some of the world’s largest organizations.

For this engagement, EOS is seeking highly technical Cloud Security Engineers to support a large-scale enterprise AI environment. This is a hands-on engineering engagement focused on implementing, automating, testing and operationalizing cloud security controls across AWS, Azure and Google Cloud.

This is not a strategy-only, assessment-only or GRC role. Successful engineers will be expected to work directly in cloud environments, infrastructure-as-code, security tooling and automation to deliver measurable security improvements.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:51 min

Rising DDoS attacks and evaluating CDN mitigation strategies

Chris Heilmann +2 · LIVE

1:08 min

Building solutions with open source GoLang infrastructure tools

Jad Wahab · LIVE

4:35 min

Setting up passwordless federated identity configuring OpenID Connect patterns

Marcel Lupo · LIVE

1:34 min

Pivoting careers into specialized platform engineering roles

Xavier Portilla Edo · LIVE

3:11 min

Surviving sudden scale events and malicious traffic

Justin Kitagawa · Coffee With Developers

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

Videos

See all

Related articles

See all