Cloud Security Engineer (IaC)

Orangepeople LLC
Plano, TX, United States
21 days ago
Apply on www.careerjet.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Working hours
Regular working hours

Tech stack

Artificial Intelligence Amazon Web Services Cloud Computing Security Continuous Integration Identity and Access Management Key Management Network Segmentation Role-Based Access Control Software Vulnerability Management Delivery Pipeline Kubernetes Helm Charts Infrastructure as Code (IaC)
+9 more
Containerization Kubernetes Infrastructure Automation Frameworks Wikis CIS Benchmarks Terraform Devsecops Serverless Computing Docker

Job description

We are seeking an Infrastructure as Code (IaC) Security Engineer to design, build, and maintain secure, scalable, and automated infrastructure solutions that underpin our AI security development platform. This role is responsible for owning the IaC layer across our container and orchestration stack, including EKS, Docker, and Helm, ensuring that all infrastructure is provisioned securely, repeatably, and in compliance with security best practices. The ideal candidate will bring security into every phase of infrastructure automation, from Terraform modules to CI/CD pipelines, enabling the AI security team to deliver rapidly without compromising the integrity of our environments., * Design, implement, and maintain secure Infrastructure as Code solutions for cloud and containerized environments supporting AI security workloads.

  • Own and manage EKS clusters, including node group configurations, networking policies, RBAC, and pod security standards to support secure AI model development and deployment.
  • Develop and maintain hardened Terraform modules, configurations, and reusable infrastructure patterns with built-in security controls (e.g., least-privilege IAM, encryption-at-rest, network segmentation).
  • Build and manage Docker images and Helm charts with security-first principles image scanning, minimal base images, secrets management, and signed artifacts.
  • Integrate security guardrails into CI/CD pipelines, including automated policy checks (e.g., OPA/Gatekeeper, Checkov, tfsec) for infrastructure deployments.
  • Automate environment provisioning, scaling, configuration, and release processes with a focus on immutable infrastructure and drift detection.
  • Collaborate with AI security engineers, platform teams, and DevSecOps to ensure infrastructure supports threat modeling, vulnerability management, and incident response requirements.
  • Troubleshoot and remediate infrastructure security issues across Kubernetes, Terraform, CI/CD, and container platforms.
  • Enforce infrastructure compliance with organizational security policies, regulatory frameworks (e.g., NIST, CIS Benchmarks), and operational best practices.
  • Document secure infrastructure patterns, deployment runbooks, and automation workflows for the AI security development team., * Participate in OP monthly team meetings and participate in team-building efforts.
  • Contribute to OP technical discussions, peer reviews, etc.
  • Contribute content and collaborate via the OP-Wiki/Knowledge Base.
  • Provide status reports to OP Account Management as requested.

Requirements

  • Bachelor s degree preferred and/or equivalent relevant experience considered.
  • Strong hands-on experience designing and implementing secure Infrastructure as Code solutions in cloud and containerized environments.
  • Deep production experience managing Kubernetes, including EKS cluster administration, networking, RBAC, and workload security.
  • Strong experience with Terraform, including development of reusable modules and secure infrastructure provisioning patterns.
  • Hands-on experience building and managing Docker images and Helm charts for containerized deployments.
  • Experience integrating infrastructure automation into CI/CD pipelines with automated validation and deployment workflows.
  • Strong understanding of infrastructure security best practices, including IAM, encryption, secrets management, and network segmentation.
  • Experience troubleshooting and remediating issues across Kubernetes, Terraform, containers, and deployment pipelines.
  • Ability to collaborate effectively with engineering, platform, and DevSecOps teams in a fast-paced environment., * Experience supporting AI, ML, or security-focused platform workloads in Kubernetes-based environments.
  • Experience with AWS and cloud-native services related to container orchestration, networking, and infrastructure automation.
  • Familiarity with infrastructure security and policy enforcement tools such as OPA/Gatekeeper, Checkov, tfsec, or similar solutions.
  • Knowledge of compliance and security frameworks such as NIST, CIS Benchmarks, or related infrastructure governance standards.

Benefits & conditions

  • 401(k).
  • Dental Insurance.
  • Health insurance.
  • Vision insurance.
  • We are an equal-opportunity employer and value diversity, equality, inclusion, and respect for people.
  • The salary will be determined based on several factors, including, but not limited to, location, relevant education, qualifications, experience, technical skills, and business needs.

About the company

At OP, we help you harness the power of technology for maximum impact. A technology consulting and solutions company, we offer advisory and managed services, innovative platforms, and staffing solutions across a wide range of fields including AI, cyber security, enterprise architecture, and beyond. For nearly two decades, we ve been challenging the status quo of the consulting industry, serving up fresh, ingenious thinking through a radically lean structure. Together, this strategy delivers unprecedented performance at an unparalleled pace for faster results that propel your business forward.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.careerjet.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:34 min

Pivoting careers into specialized platform engineering roles

Xavier Portilla Edo · LIVE

4:44 min

Evaluating documentation folders versus Git submodules and wikis

Roman Liukevich Roman Liukevich · Europe 2026 Virtual

2:07 min

Inspecting default bridge architectures and custom Docker networks

Oliver Seitz Oliver Seitz · World Congress 2025

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

2:17 min

Finding educational resources for blockchain programming

Liu Xiaohui · LIVE

2:34 min

Docker sandbox architecture and microVM environment integration

Manuel de la Peña Manuel de la Peña · World Congress 2026 Europe

Videos

See all

Related articles

See all