Senior Cloud Security Engineer

JMJ Phillip Group
Houston, TX, United States
2 days ago
Apply on jmjphillip.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$150,000.0 - $200,000.0
Working hours
Regular working hours
Job source

Tech stack

Amazon Web Services Audit Trail Microsoft Azure Cloud Computing Security CompTIA Security+ Cyber Security Identity and Access Management Intrusion Detection and Prevention Information Systems Security Architecture Professional Network Security Microsoft Security Essentials Network Planning and Design
+9 more
Cloud Services Security Information and Event Management Software Vulnerability Management Data Logging Firewalls (Computer Science) Cybercrime Microsoft Sentinel ArcSight Event Correlation Cloudwatch

Job description

We are seeking a hands-on Senior Cloud Security Engineer to establish and strengthen continuous security monitoring, detection engineering, incident response, and security operations across cloud, endpoint, network, and on-premises environments. This individual will play a critical role in identifying, investigating, and resolving security events while working closely with engineering, infrastructure, networking, compliance, and leadership teams., Security Monitoring and Detection Engineering

  • Own continuous security monitoring across cloud, endpoint, network, and on-premises environments.
  • Administer and optimize Microsoft Sentinel or comparable SIEM platforms, including data connectors, analytics rules, alerting, dashboards, workbooks, and automation.
  • Monitor and manage AWS security services, including GuardDuty, Security Hub, CloudTrail, CloudWatch, and IAM.
  • Develop and maintain security detections, correlation rules, use cases, and alert thresholds.
  • Improve threat visibility while reducing false positives and alert fatigue.
  • Identify gaps in logging, monitoring, and detection coverage and implement corrective actions.
  • Support threat hunting, security analytics, and proactive identification of emerging risks.

Incident Response and Security Operations

  • Investigate security alerts, anomalous activity, potential compromises, and policy violations.
  • Lead incident triage, containment, eradication, recovery, and post-incident review activities.
  • Develop, maintain, and exercise incident response plans, playbooks, escalation procedures, and communication processes.
  • Ensure security incidents and events are properly documented with sufficient evidence for internal and external assessments.
  • Monitor endpoint security and EDR platforms and investigate suspicious endpoint activity.
  • Establish and maintain centralized security logging, retention, review, and audit capabilities., * Coordinate vulnerability findings with infrastructure and application teams to prioritize remediation.
  • Track remediation activities and verify that identified security issues have been resolved.
  • Support risk assessments and identify gaps in security controls.
  • Provide technical recommendations to strengthen security posture and reduce operational risk.

Compliance and Assessment Support

  • Work with compliance and technical teams to align operational security activities with applicable cybersecurity requirements.
  • Support the operational execution and evidence collection associated with NIST SP 800-171 and related security frameworks.
  • Maintain documentation and evidence demonstrating that required security processes are actively operating.
  • Support government assessments, audits, customer security reviews, and other compliance activities.
  • Assist with the development and maintenance of security policies, procedures, standards, and operating documentation.

Security Architecture and Continuous Improvement

  • Provide technical input into security architecture, cloud deployments, network design, and new technology implementations.
  • Develop meaningful security operations metrics, including alert volumes, response times, incident trends, remediation status, and detection coverage.
  • Partner with engineering teams to improve security controls, processes, and operational capabilities.
  • Identify opportunities for automation, workflow improvements, and more efficient incident response processes.
  • Provide leadership with clear visibility into security posture, operational risk, and emerging threats., * A highly visible, hands-on senior engineering role with significant ownership of security operations.
  • The opportunity to build and improve security monitoring, detection, incident response, and operational processes.
  • Exposure to cloud, endpoint, network, and hybrid infrastructure security environments.
  • The ability to work closely with engineering, infrastructure, compliance, and executive leadership.
  • Opportunities to contribute to security architecture, automation, threat detection, and continuous improvement initiatives.
  • Professional growth within a technically challenging environment supporting complex cybersecurity and compliance requirements.

Requirements

The ideal candidate combines strong technical security engineering experience with expertise in cloud security operations, SIEM platforms, threat detection, incident response, and federal cybersecurity requirements., * 5+ years of experience in cybersecurity, security operations, cloud security, or related engineering roles.

  • Demonstrated experience with SIEM administration, detection engineering, alert investigation, and incident response.
  • Hands-on experience with Microsoft Sentinel or a comparable enterprise SIEM platform.
  • Experience with AWS security services, including GuardDuty, Security Hub, CloudTrail, IAM, and CloudWatch.
  • Experience with endpoint detection and response technologies.
  • Strong understanding of security logging, event correlation, threat detection, and incident investigation.
  • Experience operating in Microsoft Azure and AWS environments.
  • Working knowledge of network security, firewalls, identity systems, endpoints, and hybrid infrastructure.
  • Understanding of vulnerability management processes and common cybersecurity frameworks.
  • Strong technical documentation and communication skills.
  • Ability to work independently and take ownership of security operations from identification through resolution.
  • Experience working in fast-paced environments with multiple technical stakeholders and priorities.

Certifications (Preferred, but not Required)

  • Certified Information Systems Security Professional (CISSP).
  • Certified Cloud Security Professional (CCSP).
  • CompTIA Security+.
  • GIAC certifications.
  • AWS Certified Security - Specialty.
  • Microsoft security certifications.
  • Other relevant certifications in cloud security, incident response, threat detection, or security operations.

Benefits & conditions

  • Competitive salary range of $150,000 to $200,000, based on experience, qualifications, and technical expertise.

About the company

Houston offers a strong and diverse technology and business environment, with opportunities across energy, aerospace, manufacturing, engineering, healthcare, and government-related industries. The area is home to a large and growing technology workforce, providing access to experienced professionals and a broad range of industries facing increasingly complex cybersecurity challenges. Houston also offers a vibrant metropolitan lifestyle with diverse cultural, dining, entertainment, and recreational opportunities.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on jmjphillip.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

6:13 min

Defining cloud proficiency by technical role

Piet Van Dongen · LIVE

3:56 min

Leveraging GitOps for AI auditing and instant rollbacks

Jaroslaw Gajewski Jaroslaw Gajewski · World Congress 2026 Europe

4:34 min

Motivational categories behind modern cybercriminal activities

Mauro Verderosa · LIVE

3:13 min

Navigating the GenAI observability dashboard in Amazon CloudWatch

Yasemin Aktürk Yasemin Aktürk · Europe 2026 Virtual

1:09 min

Managing enterprise execution with the Operate runtime

Marcin Makowski Marcin Makowski · World Congress 2026 Europe

2:11 min

Securing heterogeneous legacy payment infrastructure against AI

Michele Zuccala Michele Zuccala +4 · World Congress 2026 Europe

Videos

See all

Related articles

See all