> Markdown version of [/jobs/ext/36730-cloud-security-engineer](https://www.wearedevelopers.com/jobs/ext/36730-cloud-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cloud Security Engineer - **Company:** YipitData - **Location:** New York, NY, United States (Remote available) - **Experience:** Experienced - **Salary:** $185,000.0 - $215,000.0 - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Software System Penetration Testing, Bash Shell, Software as a Service, Cloud Computing, Cloud Computing Security, Cloud Engineering, Cyber Security, Identity and Access Management, Intrusion Detection and Prevention, Python (Programming Language), Zero Trust Network Access, Runbook, Security Information and Event Management, Datadog, Policy as Code, Scripting, Cloud Platform System, Software Security, Amazon Virtual Private Cloud (VPC), Cloudformation, CIS Benchmarks, Terraform, Virtual Private Clouds, Serverless Computing, Vulnerability Analysis - **Published:** May 15, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=0e99eefd06c861b6 ## About the Role Do you have experience in Virtual Private Clouds?, * 5+ years of experience in information security, cloud security, or security engineering roles * 3+ years of hands-on experience with AWS security services and architecture (IAM, VPC security, CloudTrail, GuardDuty, etc.) * Strong understanding of cloud-native security principles including least privilege, defense in depth, zero trust, and shared responsibility models * Hands-on experience with Datadog Security or similar cloud-native SIEM/observability platforms (Cloud SIEM, security signal management, log pipeline configuration, custom detection rules) * Proficiency with Infrastructure-as-Code (Terraform, CloudFormation, or CDK) and policy-as-code frameworks * Working knowledge of container and serverless security * Solid scripting/automation skills in Python, Bash, or similar languages * Familiarity with common security frameworks and standards (NIST CSF, CIS Benchmarks, SOC 2, ISO 27001), * CISSP, CCSP, and / or AWS Certified Security - Specialty ## Description We are seeking an experienced Cloud Security Engineer to join our security team and play a critical role in protecting our cloud-native infrastructure, data, and SaaS ecosystem. As a mid-market, cloud-first company, our technology stack is built primarily on AWS with extensive use of SaaS applications across the enterprise. You will be responsible for designing, implementing, and maintaining security controls that protect our cloud environments, ensure compliance, and enable the business to move fast and securely. This is a hands-on, technically deep role that blends cloud infrastructure security, identity and access management, detection engineering, and SaaS security governance. This role will serve as a key technical resource for security across the organization. This is a remote-friendly opportunity that can sit in NYC (where our headquarter is located), one of our office hubs in Austin, Miami, Los Angeles (CA), and Cupertino (CA), or anywhere else in the US. However, depending upon where the remote work is performed, income could be subject to New York State tax withholding. We expect U.S. based working hours with the majority of the team working East and Central Time Zones., + Design, implement, and maintain security controls across our AWS environment + Manage and tune AWS-native security tooling (GuardDuty, Security Hub, CloudTrail, Inspector, etc) + Develop and enforce infrastructure-as-code (IaC) security policies using tools such as Terraform + Conduct periodic reviews of AWS account architecture, SCPs, and organizational unit (OU) structures to ensure least-privilege and segmentation best practices + Collaborate with Platform Engineering teams to shift left our security posture by embedding security into CI/CD pipelines + Monitor, investigate, and respond to cloud security alerts and incidents within AWS environments * Detection, Monitoring & Incident Response * + Build and maintain cloud-focused detection rules, alerts, and dashboards within Datadog Security (Cloud SIEM, Cloud Security Management, Application Security) + Develop and operationalize Datadog detection rules, log pipelines, and security signals in collaboration with the SOC team to provide real-time visibility across AWS infrastructure, application logs, and cloud workloads + Correlate findings from Datadog Security with alerts from Obsidian Security and AWS-native tooling to provide a unified view of risk across cloud and SaaS environments + Develop automated response playbooks for common cloud and SaaS security events + Participate in incident response activities, including investigation, containment, and post-incident review for cloud and SaaS-related security events + Conduct threat modeling exercises for cloud architectures and SaaS integrations * Compliance & Governance * + Support compliance initiatives (e.g., SOC 2, or other frameworks as applicable) by implementing and evidencing technical controls in AWS and SaaS environments + Maintain security documentation including architecture diagrams, runbooks, and policy documents + Contribute to internal security audits and third-party assessment processes + Track and remediate findings from vulnerability scans, penetration tests, and cloud security assessments ## Related Videos - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [The OpenTelemetry mistakes I keep seeing (and how to stop making them)](https://www.wearedevelopers.com/videos/100158-the-opentelemetry-mistakes-i-keep-seeing-and-how-to-stop-making-them) - [Technical Documentation - How Can I Write Them Better and Why Should I Care?](https://www.wearedevelopers.com/videos/681-technical-documentation-how-can-i-write-them-better-and-why-should-i-care) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Intermediate Bitcoin Script](https://www.wearedevelopers.com/videos/25-intermediate-bitcoin-script) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [7 Cloud Computing Trends Coming in 2025 for Developers](https://www.wearedevelopers.com/magazine/412-7-cloud-computing-trends-coming-in-2025-for-developers) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)