> Markdown version of [/jobs/ext/3199962-cloud-security-engineer](https://www.wearedevelopers.com/jobs/ext/3199962-cloud-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cloud Security Engineer - **Company:** MOHR ENTERPRISES LLC - **Location:** Naperville, IL, United States - **Experience:** Experienced - **Salary:** $130,000.0 - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Microsoft Azure, Bash Shell, BigQuery, Cloud Computing, Cloud Computing Security, Cloud Engineering, Cloud Storage, Cyber Security, Continuous Integration, Data as a Services, DevOps, Identity and Access Management, Intrusion Detection and Prevention, Python (Programming Language), Key Management, Network Security, Network Segmentation, PCI Data Security Standards, Windows PowerShell, Cloud Services, Zero Trust Network Access, Secure Coding, Software Deployment, Software Engineering, Software Vulnerability Management, Data Logging, Scripting, Google Cloud, Data Storage Technologies, Cloud Platform System, Software Security, Software Troubleshooting, Amazon Virtual Private Cloud (VPC), Infrastructure Automation Frameworks, Data Management, CIS Benchmarks, Devsecops, Serverless Computing, Security Orchestration, Automation & Response, Static Application Security Testing, Vulnerability Analysis, Dynamic Application Security Testing - **Published:** September 20, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=07d4862a664c7ea1 ## About the Role * 3+ years of experience in cloud security, cybersecurity, cloud engineering, DevSecOps, or a related technical field. * Hands-on experience with Google Cloud Platform security services and concepts. * Experience securing cloud workloads, identities, applications, and data services. * Familiarity with cloud security monitoring, vulnerability management, and incident response. * Strong understanding of: + IAM + Encryption + Logging + Threat detection + Vulnerability management + Secure application deployment * Familiarity with application security concepts such as: + Secrets management + Dependency scanning + Vulnerability remediation + Secure coding principles * Strong analytical, troubleshooting, and communication skills. * Ability to work effectively with both technical and non-technical stakeholders., * Relevant cloud or security certifications such as: + Google Professional Cloud Security Engineer + Azure Security Engineer Associate (AZ-500) + Security+ + Equivalent certifications * Familiarity with CNAPP and CSPM tools. * Experience with container security, Kubernetes security, and secure software supply chain practices. * Exposure to application security tools and processes such as: + SAST + DAST + Dependency scanning + Secrets detection + Software Composition Analysis + Secure code review * Familiarity with security frameworks such as CIS Benchmarks, NIST 800-53, PCI-DSS, or ISO 27001. * Experience with scripting and automation using Python, PowerShell, Bash, or similar languages. * Strong troubleshooting and analytical mindset with excellent attention to detail. * Comfortable working in fast-moving cloud environments with minimal supervision. * Strong communication skills across technical and non-technical teams. * Proactive and accountable, with the ability to identify risks before failures occur ## Description We are seeking a Cloud Security Engineer with hands-on technical experience securing cloud platforms and modern application environments. This role will focus on implementing and improving cloud security controls, monitoring and responding to security findings, supporting compliance initiatives, and partnering with engineering and project teams to integrate security into cloud and application workflows. The environment is primarily based within Google Cloud Platform (GCP), with a smaller Azure footprint supporting a subset of applications. The ideal candidate is a hands-on engineer who can solve technical security challenges across cloud infrastructure, Identity and Access Management (IAM), data and workload protection, and DevOps/CI/CD processes. Success in this role requires strong collaboration and communication skills, as this individual will work closely with infrastructure, platform, application, and security teams to improve security while enabling business objectives., Cloud Security Implementation * Implement and maintain cloud security controls across GCP and Azure environments, including projects, subscriptions, and organizational structures. * Assist with the design, deployment, and continuous improvement of cloud security guardrails, baseline configurations, and policy enforcement mechanisms. * Support Identity and Access Management initiatives, including: + Least-privilege access + Privileged account and identity management + Service account governance + Identity federation + Zero-trust principles * Secure cloud services, workloads, and data platforms through configuration reviews, hardening activities, and security best practices. * Work with technologies including: + VPC Service Controls + Network Security Groups + Cloud Storage + GKE + BigQuery + Cloud SQL + Pub/Sub + Cloud Functions + Cloud Run * Support container and workload security initiatives, including hardened container images, CVE scanning, and secure deployment practices. * Support encryption, key management, and data protection controls across cloud environments. * Contribute to security automation using Infrastructure as Code, scripting, and cloud-native tooling. * Integrate and maintain cloud-native and third-party security tools to improve visibility, posture management, and threat detection. * Support the implementation of security controls within CI/CD pipelines, including: + Vulnerability scanning + Secrets detection + Policy validation + DevSecOps controls * Assist development teams with secure cloud architecture patterns and application deployment practices. Monitoring & Incident Response * Monitor and tune cloud security alerts, vulnerabilities, and findings from cloud-native and third-party CSPM and CNAPP tools. * Investigate suspicious activity, misconfigurations, exposed secrets, and potential security incidents. * Support incident response involving cloud resources, identities, workloads, applications, and data. * Perform root cause analysis and recommend remediation actions following security events. * Validate remediation efforts and improve monitoring coverage based on lessons learned from incidents and investigations. Compliance & Risk Management * Support cloud security assessments and control reviews against established frameworks and organizational standards, including: + CIS Benchmarks + NIST 800-53 + PCI-DSS * Assist with vulnerability management activities, including identification, prioritization, remediation tracking, and validation. * Participate in cloud security posture reviews and continuous improvement initiatives using CNAPP and CSPM technologies. * Support audit requests, evidence collection, and documentation related to cloud security controls. * Execute security assessments of: + Cloud workloads + Data storage + Network segmentation + CI/CD processes, * Partner with infrastructure, platform, application development, and security teams to promote secure cloud adoption and DevSecOps best practices. * Provide guidance on secure cloud architecture, infrastructure-as-code, identity management, and cloud-native services. * Assist development teams with identifying and remediating cloud and application security issues throughout the Software Development Life Cycle. * Contribute to the development of cloud security standards, procedures, technical documentation, and operational runbooks. ## Related Videos - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Data Science in Retail](https://www.wearedevelopers.com/videos/586-data-science-in-retail) - [Shifting Stress to Progress— Understanding DevOps to do DevOps Better](https://www.wearedevelopers.com/videos/268-shifting-stress-to-progress-understanding-devops-to-do-devops-better) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Intermediate Bitcoin Script](https://www.wearedevelopers.com/videos/25-intermediate-bitcoin-script) - [Making Data Warehouses fast. A developer's story.](https://www.wearedevelopers.com/videos/302-making-data-warehouses-fast-a-developer-s-story) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [7 Cloud Computing Trends Coming in 2025 for Developers](https://www.wearedevelopers.com/magazine/412-7-cloud-computing-trends-coming-in-2025-for-developers) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Got AI ideas but no money? Here are 10 free ways to level up your AI skills with Google Cloud](https://www.wearedevelopers.com/magazine/600-got-ai-ideas-but-no-money-here-are-10-free-ways-to-level-up-your-ai-skills-with-google-cloud)