Cloud Security Engineer

Hex
United States
3 days ago
Apply on startup.jobs
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
5 years minimum
Compensation
$200,000.0 - $265,000.0
Working hours
Regular working hours
Job source

Tech stack

Kubernetes Security Amazon Web Services Cloud Computing Cloud Computing Security Computer Networks Databases Continuous Integration Identity and Access Management Python (Programming Language) PostgreSQL PCI Data Security Standards Role-Based Access Control
+11 more
Redis Security Information and Event Management Software Engineering TypeScript Software Vulnerability Management Spring Cloud Backend Kubernetes Graphql Terraform Devsecops

Job description

  • Design, implement, and manage security solutions and controls for AWS environments and Kubernetes clusters, including appropriate isolation/sandboxing methods for Hex’s RCE-as-a-Service platform
  • Build, deploy, and maintain infrastructure-as-code using Terraform, ensuring robust security standards are enforced.
  • Conduct security assessments, threat modeling, and audits on AWS cloud infrastructure and Kubernetes deployments.
  • Collaborate with development and operations teams to embed security best practices into CI/CD pipelines.
  • Monitor and respond to cloud security incidents, identifying root causes and recommending remediation actions.
  • Provide expertise in compliance requirements related to cloud security (e.g., SOC 2, ISO 27001, GDPR, HIPAA, PCI DSS).
  • Mentor engineers and advocate for cloud security across the organization., Our product is a web-based notebook and app authoring platform. Our frontend is built with Typescript and React, using a combination of Apollo GraphQL and Redux for managing application state and data. On the backend, we also use Typescript to power an Express/Apollo GraphQL server that interacts with Postgres, Redis, and Kubernetes to manage our database and Python kernels. Our backend is tightly integrated with our infrastructure and CI/CD, where we use a combination of Terraform, Helm, and AWS to deploy and maintain our stack.

Requirements

  • 5+ years of experience in cloud security engineering, with extensive expertise in AWS.
  • Demonstrated proficiency with Kubernetes security including cluster hardening, role-based access control (RBAC), network policies, and container vulnerability management.
  • Expert-level knowledge and hands-on experience with Terraform.
  • Familiarity with AWS security services (e.g., IAM, GuardDuty, Security Hub, CloudTrail, WAF).
  • Familiarity with CNAPP solutions such as Wiz
  • Familiarity with SIEM solutions such as Panther
  • Solid understanding of secure software development lifecycle practices, CI/CD security, and DevSecOps methodologies.
  • Relevant certifications such as AWS Certified Security - Specialty, Certified Kubernetes Security Specialist (CKS), and Terraform Associate certification are highly desirable.
  • Bonus points for security certifications from SANS or OffSec.
  • Excellent problem-solving, communication, and leadership skills.

Benefits & conditions

In addition to our unique culture, Hex proudly offers a competitive total rewards package, including but not limited to, market-benched salary & equity, comprehensive health benefits, and flexible paid time off.

The salary range for this role is: $200,000 - $265,000

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on startup.jobs
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

3:55 min

Demonstrating semantic routing thresholds with the Redis vector library

2:52 min

Generating APIs with the Neo4j GraphQL library

William Lyon · LIVE

1:52 min

Structuring and scaling the backend engineering team

Stefan Lingler Stefan Lingler +1 · Coffee With Developers

1:39 min

Understanding the four Cs of cloud native security

Rico Komenda Rico Komenda · World Congress 2025

3:42 min

Comparing in-memory and Redis storage for cache scalability

Simone Sanfratello · World Congress 2022

Videos

See all

Related articles

See all