Skip to content
HexHex

Cloud Security Engineer

Cloud Security Engineer secures AWS and Kubernetes infrastructure using Terraform IaC, conducts threat modeling and audits, embeds security in CI/CD pipelines, and ensures compliance with standards like SOC 2 and HIPAA. Requires 5+ years experience with AWS and Kubernetes security expertise.

About the job

Responsibilities

  • Design, implement, and manage security solutions and controls for AWS environments and Kubernetes clusters, including appropriate isolation/sandboxing methods for Hex’s RCE-as-a-Service platform.
  • Build, deploy, and maintain infrastructure-as-code using Terraform, ensuring robust security standards are enforced.
  • Conduct security assessments, threat modeling, and audits on AWS cloud infrastructure and Kubernetes deployments.
  • Collaborate with development and operations teams to embed security best practices into CI/CD pipelines.
  • Monitor and respond to cloud security incidents, identifying root causes and recommending remediation actions.
  • Provide expertise in compliance requirements related to cloud security (e.g., SOC 2, ISO 27001, GDPR, HIPAA, PCI DSS).
  • Mentor engineers and advocate for cloud security across the organization.

Requirements

  • 5+ years of experience in cloud security engineering, with extensive expertise in AWS.
  • Demonstrated proficiency with Kubernetes security including cluster hardening, RBAC, network policies, and container vulnerability management.
  • Expert-level knowledge and hands-on experience with Terraform.
  • Familiarity with AWS security services (e.g., IAM, GuardDuty, Security Hub, CloudTrail, WAF).
  • Familiarity with CNAPP solutions such as Wiz.
  • Familiarity with SIEM solutions such as Panther.
  • Solid understanding of secure software development lifecycle practices, CI/CD security, and DevSecOps methodologies.

Nice-to-haves

  • Relevant certifications such as AWS Certified Security – Specialty, Certified Kubernetes Security Specialist (CKS), and Terraform Associate certification.
  • Bonus points for security certifications from SANS or OffSec.

Skills

AWS, Kubernetes, Terraform, IAM, Guardduty, Security Hub, Cloudtrail, Waf, Wiz, Panther, CI/CD, DevSecOps, RBAC

OpenAI

OpenAI

San Francisco, CA
Red Team Specialist - Cyber
$198k+/yrHybridSecurity Engineering

The Red Team Specialist evaluates AI models for cyber capabilities, safeguard failures, and agentic-system abuse risks. The role combines hands-on security testing, automated evaluation infrastructure, risk assessment, and cross-functional communication.

Vercel

Vercel

San Francisco, CA
Software Engineer, Trust & Safety
$196k+/yrHybrid5+ YOESecurity Engineering

Build and operate trust and safety systems that detect and mitigate abuse at internet scale. The role combines security engineering, large-scale data analysis, and applied LLM techniques, requiring 5+ years of relevant experience and strong Python and JavaScript/TypeScript skills.

1Password

1Password

United States
Manager, Security Incident Response
$192k+/yrRemote5+ YOESecurity Engineering

Leads and develops a security incident response team while driving automation, AI-assisted workflows, operational maturity, and response strategy. The role requires 5+ years of incident response experience, people leadership, technical depth, and calm management of high-severity incidents.

Decagon

Decagon

San Francisco, CA

Governance, Risk, and Compliance Manager - Privacy
$190k+/yrOn-site5+ YOESecurity Engineering

Own and operate Decagon’s privacy and GRC programs, including regulatory compliance, data governance, customer security engagements, audits, and cross-functional privacy initiatives. The role requires 5+ years of GRC experience, strong communication and project management skills, and familiarity with enterprise security controls.

Anthropic

Anthropic

San Francisco, CA
Safeguards Policy Analyst, Cyber Harms
$190k+/yrHybridSecurity Engineering

The analyst develops and evaluates cyber product policies, enforcement guidance, controlled-access frameworks, and launch-review inputs for AI systems. The role requires strong policy writing, cybersecurity or platform-enforcement familiarity, technical security literacy, and cross-functional communication.