Cloud Security Engineer

Tiger Security
Philadelphia, PA, United States
2 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Compensation
$90,000.0 - $130,000.0
Working hours
Shift work
Job source

Tech stack

Amazon Web Services Software System Penetration Testing Microsoft Azure Bash Shell Cloud Computing Cloud Computing Security Cloud Engineering Cyber Security Computer Networks Continuous Integration DevOps Identity and Access Management
+20 more
Python (Programming Language) Peering Windows PowerShell Zero Trust Network Access Security Information and Event Management Google Cloud Cloud Platform System Microsoft Power Automate Multi-Cloud Amazon Virtual Private Cloud (VPC) Cloudformation Infrastructure Automation Frameworks Information Technology Bicep Patch Management Opsworks CIS Benchmarks Purple Team (Cyber Security) Terraform Devsecops

Job description

Security Risk Advisors Intl., LLC (SRA) is offering a Cloud Security Engineer position. This role is responsible for designing, implementing, and maintaining security controls across SRA’s multi-cloud environment, spanning Microsoft Azure/Entra ID, Google Cloud Platform (GCP), and Amazon Web Services (AWS). The Cloud Security Engineer will work closely with internal IT, security operations, and engineering teams to ensure cloud infrastructure is deployed and maintained in a secure, compliant, and resilient manner., * Design, implement, and maintain cloud security architectures across Azure/Entra ID, GCP, and AWS environments.

  • Administer and continuously improve cloud identity and access management (IAM) policies, roles, and privilege models across all three platforms.
  • Monitor cloud environments for misconfigurations, threats, and vulnerabilities using cloud-native and third-party security tooling (e.g., Defender for Cloud, Security Command Center, AWS Security Hub).
  • Operationalize cloud vulnerability and patch management processes, ensuring timely remediation of identified risks.
  • Implement and maintain Cloud Security Posture Management (CSPM) solutions to enforce security baselines and compliance standards.
  • Develop and enforce cloud security policies, standards, and guardrails (e.g., Azure Policy, GCP Organization Policies, AWS SCPs).
  • Collaborate with engineering and DevOps teams to embed security into CI/CD pipelines and infrastructure-as-code (IaC) workflows.
  • Conduct cloud security assessments and architecture reviews for new and existing environments.
  • Support incident response activities related to cloud infrastructure, including investigation, containment, and remediation.
  • Create and maintain technical documentation for cloud security architectures, configurations, and operational procedures.
  • Research and evaluate emerging cloud security technologies and provide recommendations for adoption.
  • Develop detection content and security analytics in SRA’s internal SOC applicable to cloud environments.

Requirements

Do you have a valid AWS Certified Security - Specialty certification?, Do you have experience in Zero Trust security?, Do you have a Bachelor’s degree?, In-depth understanding of:

  • Microsoft Azure and Entra ID, including conditional access, PIM, and Defender for Cloud
  • Google Cloud Platform (GCP) security services, including Security Command Center, IAM, and VPC Service Controls
  • Amazon Web Services (AWS) security services, including IAM, GuardDuty, Security Hub, and AWS Config
  • Cloud identity and access management principles and zero trust architecture

Working knowledge of:

  • Cloud Security Posture Management (CSPM) and Cloud Workload Protection Platforms (CWPP)
  • Infrastructure-as-Code (IaC) tools such as Terraform, Bicep, or CloudFormation
  • Networking concepts as applied to cloud environments (VPCs, peering, private endpoints, firewalls)
  • SIEM and EDR technologies in cloud-integrated environments

Experience with:

  • CI/CD pipeline security and DevSecOps practices
  • Organizing or supporting penetration testing, purple team exercises, or cloud-focused security assessments
  • Compliance frameworks relevant to cloud environments (e.g., CIS Benchmarks, NIST CSF, SOC 2)

Moderate experience with:

  • Scripting and automation using Python, PowerShell, or Bash
  • Automation via tools such as Power Automate, Logic Apps, or cloud-native orchestration services, * Punctuality and timely attendance to external client and internal stakeholder needs.
  • A bachelor’s degree in Information Technology, Computer Science, or a similar field of study, or equivalent experience.
  • 3+ years of hands-on experience in cloud security engineering or a related role, with demonstrable experience across at least two of the three major cloud platforms (Azure, GCP, AWS).
  • Relevant cloud security certifications preferred (e.g., AZ-500, SC-100, Google PCSE, AWS Security Specialty).
  • A passion for learning about cloud security, emerging technologies, and threat landscapes.
  • Excellent verbal and written communication skills.
  • Strong time management and organizational skills., These Essential Functions, Requirements, and Skills are guidelines. If you are a candidate who does not meet this exact job description but can demonstrate excellent organization, attention to detail, professionalism, flexibility, and self-direction in your professional background, we hope you apply. SRA values a diverse workplace and strongly encourages women, people of color, LGBTQ+ individuals, people with disabilities, members of ethnic minorities, and veterans to apply.

Benefits & conditions

Pulled from the full job description

  • Paid training
  • Pet insurance
  • Parental leave
  • 401(k)
  • Health insurance
  • Vision insurance
  • Dental insurance, Work with Experts: Robust internal training program, plus Company-paid external training. SRA recognizes the value of professional development for employees. Therefore, we encourage our employees to pursue continuing education and role-specific training. Every SRA employee is eligible to attend one training per year paid for by SRA.

Mental Health Services: SRA has partnered with BetterHelp to provide SRA employees with free mental health support. BetterHelp connects individuals with licensed therapists for chat, video, and phone sessions.

Medical / Dental / Other (regular full-time employees only)

  • Generous medical, dental, and vision benefits at different price points.
  • Company-paid disability and life insurance.
  • Company 401(k) plan including annual 3% safe harbor contribution.
  • Free patient advocacy service that helps find care providers and resolve insurance queries.
  • Free financial advising.
  • Generous parental leave, sick leave, and vacation policies.
  • Possibility to work remotely or with a flexible schedule when needed and approved.
  • Company-paid cell phone with discounted accessories.
  • 1-2-3 Give Program: 1. SRA will give $1,000 to a charity of your choice. 2. If you give an additional amount (up to $1,000), then 3. SRA will match that amount up to $1,000.
  • Other discounted, employee-paid benefits including pet insurance, legal support, and voluntary life insurance.

About the company

SRA’s mission is to level up every day to protect our clients and their customers. This begins with our team members and their experience. SRA prides itself on maintaining a culture where team members have a shared sense of support and belonging, consistent with our It’s Personal company value. At SRA, we prioritize transparent career pathing, varied DEI programming and community groups, competitive benefits including mental health support, and an emphasis on a sustainable, healthy, and engaging work culture. SRA has twice been named a Best Place to Work by the Philadelphia Business Journal.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

5:28 min

Bitcoin scaling and the transition to peer-to-peer transactions

Jad Wahab · LIVE

2:17 min

Mapping the maturity roadmap for scaled devops adoption

Dominik Krichbaum Dominik Krichbaum · WWC Europe 2026

2:56 min

Provisioning a secure container infrastructure with Bicep

Matthias Falkenberg +1 · WWC 2022

1:35 min

Powping protocol for direct peer-to-peer interactions

Glenn Wolfe · LIVE

3:18 min

Scaling global network engineering through DevOps culture

Stuart Clark · LIVE

Videos

See all

Related articles

See all