> Markdown version of [/jobs/ext/2818989-cloud-security-engineer](https://www.wearedevelopers.com/jobs/ext/2818989-cloud-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cloud Security Engineer - **Company:** SHEIN --- - **Location:** Los Angeles, United States - **Experience:** Expert - **Salary:** $130,000.0 - $169,000.0 - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Artificial Intelligence, Amazon Web Services, ARM Architecture, Build Automation, Microsoft Azure, Cloud Computing Security, Cyber Security, Computer Networks, Continuous Integration, Data Centers, Networking Hardware, Intrusion Detection and Prevention, Intrusion Detection Systems, Key Management, Open Source Technology, Role-Based Access Control, Tripwire, Google Cloud, Multi-Cloud, Containerization, Kubernetes, Prisma Cloud Platform - **Published:** September 10, 2026 - **Apply:** https://startup.jobs/senior-cloud-security-engineer-shein-8122626 ## About the Role * 5+ years of security engineering experience, with 3+ years of meaningful hands-on work in cloud security, container/Kubernetes security or closely related cloud-native security domains. * Strong practical experience securing production K8s clusters (EKS, AKS, GKE, or self-managed), including: pod security standards, network policy design, RBAC architecture, admission control, and secrets management. * Endpoint XDR or equivalent Host-based Intrusion Detection System (HIDS) experience. * Built or operated container runtime security tooling (Falco, Sysdig, Aqua, Prisma Cloud Compute, or equivalent) in production environments. * Experience writing admission controllers, OPA/Gatekeeper policies, Kyverno policies, or equivalent policy-as-code for container environments. * Familiarity with open-source cloud-native security projects (Falco, OPA, Trivy, kube-bench, Cilium, or similar) - we value engineers who understand how tools work under the hood, not just how to configure them. * AWS/Azure cloud security experience and comfort working across multi-cloud environments. * Demonstrated ability to coordinate technical decisions across international, cross-time-zone teams, including teams where Mandarin is the primary working language - via direct bilingual fluency or a track record of effective cross-border technical partnership. * Self-directed execution - you identify gaps, propose solutions, and work collaboratively across departments to ship them. * Strong communication skills and the ability to collaborate effectively across teams, functions, and time zones. Nice to Have * Experience designing Cloud Security Posture Management, K8s security architecture from scratch for multi-region deployments. * Open-source maintainer, committer, or significant contributor to cloud-native security projects (CNCF ecosystem preferred). * Experience with CI/CD pipeline security integration: container image scanning, image signing, SBOM generation, and supply chain verification. * Palo Alto Cortex XDR or equivalent experience. * Experience deploying containerized security sensors, NTA, or NDR in production K8s - running security tooling IN containers, not just securing containers. * Experience with CNAPP platforms (Wiz, Lacework, Orca) - understanding cloud posture tooling in practice. * AI/ML workload security considerations (model serving infrastructure, GPU cluster hardening). * CKS (Certified Kubernetes Security Specialist) or equivalent certification. ## Description We're hiring a Senior Cloud Security Engineer to own and mature Cloud Security runtime protection across our container and Kubernetes environments across our global, multi-cloud footprint. This is an engineering role for someone with deep, practical experience in cloud-native security infrastructure, plus hands-on familiarity with deploying and operating security tooling in containerized environments. You'll work closely with infrastructure, platform, and security teams across regions to design and implement controls that are effective, durable, and usable in production. We're looking for someone who can go beyond configuration and checklists: a hands-on engineer who can architect systems, automate processes, troubleshoot failures, and make strong design decisions in complex multi-cloud environments. We operate at meaningful scale: customers in 150+ countries, footprint across multi-cloud providers, and engineering teams shipping continuously. We've already made significant investments in our security foundations and are now focused on the next stage of maturity for Cloud container and workload security. In this role, your primary focus will be cloud security posture, container and Kubernetes security: runtime threat detection, admission control, image integrity, secrets management, and the policy-as-code frameworks needed to run these systems well at scale. You'll also drive cross-border cloud security alignment, partnering with global-based infrastructure teams on shared architecture decisions across the multi-cloud tenants. This is a greenfield engineering role - you'll be the cloud security engineer on the global team. This is a strong fit for someone who wants to combine hands-on engineering, practical architecture judgment, and cross-functional influence in a role with real scope and ownership., * Own and mature cloud security posture, container and Kubernetes security across our global cloud environments. * Define and improve standards, guardrails, and reference patterns for CSPM, container image security, runtime integrity enforcement, and admission control. * Tune and operate policy-as-code frameworks (Kyverno, OPA/Rego) to enforce security baselines across K8s clusters at scale. * Deploy and manage containerized security tooling - NTA sensors, NDR, and runtime threat detection - across global data centers. * Design and implement Kubernetes hardening: RBAC, network policies, pod security standards, and secrets management. * Partner with engineering and infrastructure teams early in the design process to help implement secure, practical container platform architectures. * Drive cross-border cloud security alignment with global-based teams on shared architecture decisions spanning Azure, AWS, GCP, etc. * Integrate security telemetry from OT network devices and containerized workloads into centralized SOC platforms. * Utilize AI to build automation and operational tooling to improve reliability, visibility, and container lifecycle security. * Contribute to security architecture reviews and design decisions for cloud security infrastructure, container platforms, and CI/CD pipelines. * Troubleshoot runtime security, container and K8s security production issues, perform root cause analysis, and drive durable remediation. * Develop incident response runbooks for container/K8s-specific attack patterns. ## Related Videos - [Hacking Kubernetes: Live Demo Marathon](https://www.wearedevelopers.com/videos/488-hacking-kubernetes-live-demo-marathon) - [Kubernetes Security Best Practices](https://www.wearedevelopers.com/videos/1411-kubernetes-security-best-practices) - [The Open-source Java SDK for Multi-Cloud Development - Sandeep Pal](https://www.wearedevelopers.com/videos/2113-the-open-source-java-sdk-for-multi-cloud-development-sandeep-pal) - [Understanding Kubernetes in a visual way](https://www.wearedevelopers.com/videos/100085-understanding-kubernetes-in-a-visual-way) - [Kubernetes Security - Challenge and Opportunity](https://www.wearedevelopers.com/videos/412-kubernetes-security-challenge-and-opportunity) - [Winning the Hybrid Cloud](https://www.wearedevelopers.com/videos/432-winning-the-hybrid-cloud) ## Related Articles - [Learning Kubernetes made easy with KubeCampus](https://www.wearedevelopers.com/magazine/348-learning-kubernetes-made-easy-with-kubecampus) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers)