Cloud Security Engineer

Dexperts Inc
Bellevue, WA, United States
1 day ago
Apply on www.dice.com
Prepare application

Role details

Contract type
Temporary contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Job source

Tech stack

Kubernetes Security Amazon Web Services ARM Architecture Microsoft Azure Cloud Computing Cloud Computing Security Cloud Engineering Continuous Integration Software Design Patterns Network Security Routing PCI Data Security Standards
+12 more
Ansible Zero Trust Network Access Tripwire Scripting Google Cloud Modern Ui Delivery Pipeline Multi-Cloud HybridCloud Containerization Terraform Prisma Cloud Platform

Job description

We’re seeking a Cloud Security Engineer to join an Advanced Fusion Center (AFC) Subject Matter Expert (SME) team supporting the ongoing, day-to-day operation and monitoring of a client’s cloud security stack. This is a steady-state operations role - SME Services focus on the ongoing day-to-day management, operation, and/or monitoring of technology platforms

Working within client-owned infrastructure under client direction. It is not a net-new build/architecture role.

Key Responsibilities:

Directly from the engagement scope, the Cloud Security Engineer will:

¡ Design and implement hybrid enterprise network architectures with segmentation, zero trust principles, and layered defenses2

¡ Maintain operational cloud security and compliance continuity around hybrid cloud systems, primarily in AWS2

¡ Support Prisma Cloud, Cortex Cloud, and CI/CD pipelines using Terraform2

¡ Apply a deep understanding of cloud native controls (Azure NSGs, AWS SGs, routing, private endpoints, ingress/egress controls)2

¡ Perform scripting, Infrastructure as Code (Ansible), and IT orchestration2 across managed platforms

¡ Implement future-proof configurations with considerations for long-term maintainability and risk reduction2

¡ Partner with business stakeholders to design secure implementation patterns and orchestration2

¡ Assess the posture of current network security assets and remediate2

Requirements

¡ AWS-primary cloud security experience - hands-on operational security and compliance in production AWS (hybrid a plus)

¡ Prisma Cloud and/or Cortex Cloud (Palo Alto CNAPP) hands-on experience - CSPM/CWPP posture management

¡ CI/CD security with Terraform - authoring and maintaining IaC in automated pipelines

¡ Cloud-native network controls - AWS Security Groups, Azure NSGs, routing, private endpoints, ingress/egress design

¡ Infrastructure as Code (Ansible) and IT orchestration platforms

¡ Zero Trust & segmentation design and operational experience

¡ Strong security posture assessment and remediation skills

Plus the SOW’s baseline SME skillsets:

· Proactively and reactively troubleshooting common issues within their field of expertise; Base experience in cloud, containerization, and other modern design patterns; Modern problem solving and design patterns: basic scripting, cloud, and automation; Critical thinking skills “beyond runbooks” and problem solving; Written and verbal communication and language skills3

Preferred Qualifications

¡ Multi-cloud exposure (Azure/Google Cloud Platform alongside AWS)

¡ Compliance framework experience (CIS, NIST, SOC 2, PCI-DSS)

¡ Container/Kubernetes security (EKS/AKS)

¡ Relevant certifications (e.g., AWS Security Specialty, Palo Alto PCCSE, Terraform Associate)

· CI/CD security tooling (Checkov, tfsec, Snyk, Aqua/Trivy) - note: Prisma Cloud’s IaC scanning is built on Checkov, so this experience transfers well

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:34 min

Pivoting careers into specialized platform engineering roles

Xavier Portilla Edo ¡ LIVE

1:42 min

Automating Skupper deployments using Ansible

Alex Soto Alex Soto ¡ World Congress 2024

2:04 min

Enhancing network privacy with routing fees and onion routing

Andreas M Antonopoulos ¡ LIVE

1:53 min

Transitioning toward DevSecOps with dynamic scanning and secrets management

Christoph Ruggenthaler ¡ LIVE

6:13 min

Defining cloud proficiency by technical role

Piet Van Dongen ¡ LIVE

3:19 min

Executing complex workflows using Ansible Automation Platform

Goetz Rieger Goetz Rieger ¡ World Congress 2025

Videos

See all

Related articles

See all