> Markdown version of [/jobs/ext/2722700-cloud-security-engineer](https://www.wearedevelopers.com/jobs/ext/2722700-cloud-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cloud Security Engineer - **Company:** Hex - **Location:** United States - **Experience:** Experienced - **Salary:** $200,000.0 - $265,000.0 - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Amazon Web Services, Cloud Computing, Cloud Computing Security, Computer Networks, Databases, Continuous Integration, Identity and Access Management, Python (Programming Language), PostgreSQL, PCI Data Security Standards, Role-Based Access Control, Redis, Security Information and Event Management, Software Engineering, TypeScript, Software Vulnerability Management, Spring Cloud, Backend, Kubernetes, Graphql, Terraform, Devsecops - **Published:** September 4, 2026 - **Apply:** https://startup.jobs/cloud-security-engineer-hex-technologies-7725410 ## About the Role * 5+ years of experience in cloud security engineering, with extensive expertise in AWS. * Demonstrated proficiency with Kubernetes security including cluster hardening, role-based access control (RBAC), network policies, and container vulnerability management. * Expert-level knowledge and hands-on experience with Terraform. * Familiarity with AWS security services (e.g., IAM, GuardDuty, Security Hub, CloudTrail, WAF). * Familiarity with CNAPP solutions such as Wiz * Familiarity with SIEM solutions such as Panther * Solid understanding of secure software development lifecycle practices, CI/CD security, and DevSecOps methodologies. * Relevant certifications such as AWS Certified Security - Specialty, Certified Kubernetes Security Specialist (CKS), and Terraform Associate certification are highly desirable. * Bonus points for security certifications from SANS or OffSec. * Excellent problem-solving, communication, and leadership skills. ## Description * Design, implement, and manage security solutions and controls for AWS environments and Kubernetes clusters, including appropriate isolation/sandboxing methods for Hex's RCE-as-a-Service platform * Build, deploy, and maintain infrastructure-as-code using Terraform, ensuring robust security standards are enforced. * Conduct security assessments, threat modeling, and audits on AWS cloud infrastructure and Kubernetes deployments. * Collaborate with development and operations teams to embed security best practices into CI/CD pipelines. * Monitor and respond to cloud security incidents, identifying root causes and recommending remediation actions. * Provide expertise in compliance requirements related to cloud security (e.g., SOC 2, ISO 27001, GDPR, HIPAA, PCI DSS). * Mentor engineers and advocate for cloud security across the organization., Our product is a web-based notebook and app authoring platform. Our frontend is built with Typescript and React, using a combination of Apollo GraphQL and Redux for managing application state and data. On the backend, we also use Typescript to power an Express/Apollo GraphQL server that interacts with Postgres, Redis, and Kubernetes to manage our database and Python kernels. Our backend is tightly integrated with our infrastructure and CI/CD, where we use a combination of Terraform, Helm, and AWS to deploy and maintain our stack. ## Related Videos - [Reducing LLM Calls with Vector Search Patterns - Raphael De Lio (Redis)](https://www.wearedevelopers.com/videos/1714-reducing-llm-calls-with-vector-search-patterns-raphael-de-lio-redis) - [Putting the Graph In GraphQL With The Neo4j GraphQL Library](https://www.wearedevelopers.com/videos/257-putting-the-graph-in-graphql-with-the-neo4j-graphql-library) - [Developing the Backend with Stefan Lingler, CTO at Shpock](https://www.wearedevelopers.com/videos/100360-developing-the-backend-with-stefan-lingler-cto-at-shpock) - [Kubernetes Security Best Practices](https://www.wearedevelopers.com/videos/1411-kubernetes-security-best-practices) - [Event based cache invalidation in GraphQL](https://www.wearedevelopers.com/videos/433-event-based-cache-invalidation-in-graphql) - [Meet Your New BFF: Backend to Frontend without the Duct Tape](https://www.wearedevelopers.com/videos/682-meet-your-new-bff-backend-to-frontend-without-the-duct-tape) ## Related Articles - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Learning Kubernetes made easy with KubeCampus](https://www.wearedevelopers.com/magazine/348-learning-kubernetes-made-easy-with-kubecampus) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [7 Cloud Computing Trends Coming in 2025 for Developers](https://www.wearedevelopers.com/magazine/412-7-cloud-computing-trends-coming-in-2025-for-developers)