> Markdown version of [/jobs/ext/3546740-cloud-security-automation-engineer](https://www.wearedevelopers.com/jobs/ext/3546740-cloud-security-automation-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cloud Security & Automation Engineer - **Company:** W. R. Berkley Corporation - **Location:** Wilmington, DE, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Artificial Intelligence, Amazon Web Services, Applications Architecture, JIRA, Microsoft Azure, Cloud Computing, Cloud Computing Security, Cloud Engineering, Configuration Management, Cyber Security, Continuous Integration, Data Security, DevOps, Data Flow Control, Identity and Access Management, Information Systems Security Architecture Professional, JSON, Python (Programming Language), Key Management, Network Security, Log Analysis, Enterprise Messaging Systems, Open Web Application Security, Windows PowerShell, Role-Based Access Control, Cloud Services, Runbook, Security Information and Event Management, Systems Integration, Software Vulnerability Management, Workflow Management Systems, YAML, Policy as Code, Data Logging, Mitre Att&ck, Software Troubleshooting, Multi-Cloud, Cloudformation, AI Platforms, Kubernetes, Information Technology, Bicep, Tools for Reporting, CIS Benchmarks, Restful APIs, Terraform, Prisma Cloud Platform, Software Version Control, Data Pipelines, Devsecops, Serverless Computing, Azure Resource Manager, Security Orchestration, Automation & Response, Servicenow - **Published:** September 30, 2026 - **Apply:** https://careers-berkley.icims.com/jobs/14487/cloud-security-%26-automation-engineer/job?in_iframe=1 ## About the Role * Bachelor's degree in Computer Science, Cybersecurity, Information Technology, Engineering or related discipline * 5 or more years of experience in cloud security engineering, security engineering, DevSecOps, cloud platform engineering, or a related technical security role. * Hands-on experience securing and operating production environments in Microsoft Azure and/or Amazon Web Services; multi-cloud experience is preferred. * Hands-on experience with a CNAPP, CSPM, or cloud exposure management platform such as Wiz or Prisma Cloud, including policy configuration, findings analysis, integrations, reporting, and remediation workflows. * Demonstrated comfort using AI-assisted tools in a professional context; approaches AI as a standard part of modern workflow rather than a specialized or optional capability * Demonstrated experience prioritizing cloud risk using business context, exploitability, attack paths, asset criticality, identity exposure, network exposure, and data sensitivity. * Strong scripting and automation skills using Python and/or PowerShell, REST APIs, JSON/YAML, source control, and CI/CD practices. * Experience with Infrastructure as Code and policy-as-code technologies such as Terraform, Bicep, ARM templates, CloudFormation, Open Policy Agent, or equivalent controls. * Solid understanding of cloud identity and access management, non-human identities, least privilege, network security, workload and container security, secrets management, encryption, logging, monitoring, and incident response. * Ability to troubleshoot complex technical issues, communicate risk clearly, and drive remediation across teams without relying solely on direct authority. * Ability to produce clear technical documentation, operating metrics, and leadership-ready status or risk updates. Preferred Qualifications * Experience designing or operating a formal CTEM program or exposure management operating model. * Experience integrating cloud security platforms with ServiceNow, Azure DevOps, Jira, SIEM/SOAR platforms, messaging platforms, data pipelines, or reporting tools. * Experience securing Kubernetes, containers, serverless services, CI/CD pipelines, software supply chains, and cloud-native application architectures. * Familiarity with AI/ML security, including AI service architecture, model and data access, agent or workload identities, prompt and data-flow risks, AI security posture management, and governance of AI-enabled services. * Working knowledge of cloud and security frameworks such as NIST CSF, NIST 800-53, CIS Benchmarks, CSA CCM, MITRE ATT&CK, OWASP, and relevant regulatory or audit requirements. * Relevant certifications such as CCSP, CISSP, CCSK, Microsoft Azure Security Engineer, AWS Certified Security - Specialty, or vendor platform certifications. * Ability to sit at a desk and work on a computer for extended periods of time. * Must occasionally lift and/or move up to ten pounds. * Vision abilities required by this job include close vision and the ability to adjust focus. ## Description The Cloud Security & Automation Engineer is a hands-on engineering role responsible for improving security across public cloud, hybrid, container, and cloud-native environments. The role owns the day-to-day engineering and operation of cloud exposure management capabilities, including platforms such as Wiz or Prisma Cloud, and converts prioritized risk into durable technical controls, automated workflows, and measurable remediation outcomes. The engineer will work closely with Vulnerability Management and AI Security Teams. Cloud exposure management and platform ownership Configure, administer, optimize, and troubleshoot cloud security and exposure management platforms such as Wiz or Prisma Cloud. Manage cloud account and subscription onboarding, connectors, permissions, policies, rules, integrations, dashboards, and platform health across Azure, AWS, and other in-scope cloud services. CTEM operations and risk prioritization Support the continuous threat exposure management lifecycle by identifying and validating cloud exposures, analyzing attack paths and toxic combinations, prioritizing material risk, coordinating remediation with accountable teams, validating closure, and tracking exceptions. Translate platform findings into a focused, risk-based backlog rather than a high-volume queue of uncontextualized alerts. Security automation and engineering Design and build reusable automation for cloud security operations using Python, PowerShell, REST APIs, JSON/YAML, workflow orchestration, serverless services, and Infrastructure as Code. Automate asset onboarding, policy deployment, enrichment, ticket routing, evidence collection, remediation validation, reporting, and other repeatable engineering tasks. Cloud security architecture and guardrails Define and implement cloud security requirements, reference patterns, preventive guardrails, and detective controls for identity, network, workload, container, Kubernetes, data, secrets, logging, and configuration security. Contribute security requirements to cloud landing zones and platform engineering standards. Cross-functional remediation and enablement Partner with Cloud, DevOps, Vulnerability Management, IAM, infrastructure, and application teams to assign ownership, develop practical remediation patterns, integrate controls into delivery workflows, and improve adoption of secure cloud practices. AI security partnership Provide cloud security engineering for AI platforms and services, including secure architecture reviews, identity and non-human identity controls, secrets management, data-flow protection, logging and monitoring, exposure analysis, and automation. Help translate emerging AI security requirements into repeatable cloud controls and engineering patterns. Metrics, governance, and continuous improvement Develop dashboards and operating metrics for cloud coverage, critical exposures, attack paths, remediation aging, exceptions, automation effectiveness, and control adoption. Use metrics to identify systemic issues and recommend improvements to architecture, tooling, and operating processes. Incident support and technical escalation Provide cloud security expertise during investigations and incidents, including exposure validation, cloud configuration analysis, identity and access review, log analysis, containment support, and corrective-action engineering. Participate in senior escalation or Person in Charge coverage when assigned. Standards, documentation, and knowledge sharing Create and maintain technical standards, standard operating procedures, runbooks, architecture diagrams, operational playbooks, and control documentation. Share knowledge through design reviews, demonstrations, and hands-on coaching. Technical leadership and recruiting Lead technical workstreams, mentor engineers, review designs and automation, and contribute to resume reviews, technical interviews, and practical assessments for cloud security engineering roles. ## Related Videos - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [GitOps for the people](https://www.wearedevelopers.com/videos/461-gitops-for-the-people) - [CI/CD with Github Actions](https://www.wearedevelopers.com/videos/856-ci-cd-with-github-actions) - [Tips and Tricks for Working with JSON](https://www.wearedevelopers.com/videos/1229-tips-and-tricks-for-working-with-json) - [Kubernetes Security Best Practices](https://www.wearedevelopers.com/videos/1411-kubernetes-security-best-practices) - [Improving quality with Agentic AI with Rovo Dev and Xray](https://www.wearedevelopers.com/videos/2005-improving-quality-with-agentic-ai-with-rovo-dev-and-xray) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [7 Cloud Computing Trends Coming in 2025 for Developers](https://www.wearedevelopers.com/magazine/412-7-cloud-computing-trends-coming-in-2025-for-developers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again)