Lead Engineer, Cloud Security
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+13 more
Job description
- Manage and optimize cloud security posture management (CSPM) and cloud workload protection (CWPP) tooling
- Conduct cloud security assessments, identify misconfigurations, and drive remediation with engineering teams.
- Design and implement guardrails for Infrastructure-as-Code (IaC) pipelines (Terraform, CloudFormation, Bicep) to prevent insecure deployments
- Monitor and respond to cloud-specific threats, integrating cloud telemetry into SIEM and detection workflows
- Evaluate and harden container and serverless architectures (EKS, ECS, Lambda, AKS, Azure Functions).
- Develop and maintain cloud security standards, reference architectures, and runbooks.
- Support incident response activities for cloud-based security events.
- Partner with Engineering, and Application Development teams to embed security into CI/CD pipelines.
- Provide technical input on cloud security tooling decisions, vendor evaluations, and proof-of-concept testing.
Requirements
- Bachelors degree in computer science, Information Security, Information Technology, or a related field.
- 7+ years of progressive experience in information security, with at least 4 years focused on cloud security engineering.
- Experience with container security (Docker, Kubernetes) and serverless security patterns. Capable of persuading non-security leaders (e.g., IT Ops, Engineering, Product) by linking security initiatives to operational continuity, consumer trust, and compliance posture.
Education/Certifications:
- AWS Security Specialty, Azure Security Engineer Associate (AZ-500), CCSP, CISSP, or equivalent
Experience:
- Experience with cloud detection and response (CDR) tooling and cloud-native threat detection
Knowledge and Skills:
- Deep hands-on experience with both AWS and Microsoft Azure security services, including: AWS: IAM, GuardDuty, Security Hub, CloudTrail, Config, KMS, VPC security, WAF, Organizations/SCPs. Azure: Entra ID, Defender for Cloud, Azure Policy, Key Vault, NSGs, Azure Monitor, Sentinel.
- Strong experience with cloud security posture management (CSPM) platforms (e.g., Wiz, Orca, Rapid7 InsightCloudSec, CrowdStrike Falcon Cloud Security, or equivalent).
- Working knowledge of Infrastructure-as-Code (Terraform, CloudFormation, or ARM/Bicep templates) and securing IaC pipelines.
- Solid understanding of network security principles applied to cloud environments (VPCs, transit gateways, private endpoints, zero trust network architecture).
- Familiarity with CI/CD security integration and DevSecOps practices.
- Ability to communicate complex technical concepts to both engineering peers and non-technical stakeholders.
- Collaborative approach to working across engineering, IT, and product teams.
About the company
V-Soft Consulting is currently hiring for a Lead Engineer, Cloud Security for our premier client in Oak Brook, Illinois., V-Soft Consulting Group is recognized among the top 100 fastest growing staffing companies in North America, V-Soft Consulting Group is headquartered in Louisville, KY with strategic locations in India, Canada and the U.S. V-Soft is known as an agile, innovative technology services company holding several awards and distinctions and has a wide variety of partnerships across diverse technology stacks.
As a valued V-Soft Consultant, youre eligible for full benefits (Medical, Dental, Vision), a 401(k) plan, competitive compensation and more. V-Soft is partnered with numerous Fortune 500 companies, exceptionally positioned to advance your career growth.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on dice.comGood distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
Walking Into The Era of Supply Chain Risks
Learning Kubernetes made easy with KubeCampus
Understanding and Mitigating Common Web Vulnerabilities