Cloud Security Engineer
Own cloud security posture across AWS, Azure, and GCP by triaging CNAPP findings, enforcing Terraform policy-as-code guardrails, and hardening Kubernetes environments. The role requires 4–6 years of cloud or platform security experience, strong expertise in at least one major cloud, and hands-on remediation leadership.
About the job
Responsibilities
Cloud Posture Management
- Own the CNAPP end-to-end.
- Triage Wiz findings by exploitability and business impact.
- Drive remediation across engineering teams to SLA and prevent backlog accumulation.
Infrastructure-as-Code Security
- Design and ship policy-as-code gates in the Terraform pipeline.
- Block misconfigurations at pull-request and plan time before they reach production.
- Use OPA/Rego, Checkov, tfsec, or equivalent tools.
- Calibrate security gates to prevent bad patterns without creating excessive friction.
Multi-Cloud Security Baseline
- Define, document, and enforce a consistent security baseline across AWS, Azure, and GCP.
- Cover IAM, networking, KMS/encryption, and logging.
- Maintain documentation for enterprise customer security reviews and audit evidence requests.
Kubernetes and Container Security
- Harden clusters, images, and admission paths across EKS, AKS, and GKE.
- Set and enforce RBAC policies, admission controls, and image-scanning standards.
Remediation Leadership
- Drive fixes through engineering teams without direct management authority.
- Track SLAs, communicate risk to technical and non-technical stakeholders, and escalate when needed.
Shift-Left Guardrails
- Increase the share of cloud infrastructure managed through Terraform with active security checks.
- Trend critical misconfigurations reaching production toward zero.
Requirements
- 4–6 years of experience in cloud security or platform/infrastructure security.
- Expert depth in at least one major cloud provider: AWS, Azure, or GCP, including IAM, networking, KMS/encryption, and logging.
- Hands-on experience with a CNAPP/CSPM, preferably Wiz, including triage, prioritization, and remediation coordination with engineering teams.
- Production Terraform experience and policy-as-code experience with OPA/Rego, Checkov, tfsec, or similar tools integrated into CI/CD.
- Kubernetes security fundamentals, including RBAC, admission control, and image scanning.
- Scripting proficiency in Python or Go.
- English proficiency at B2 level or higher.
Nice to Have
- Experience working across two or more cloud providers, including AWS, Azure, and GCP.
- CCSK, CKA, CKS, AWS Security Specialty, or equivalent certifications.
- EKS, AKS, or GKE hardening and container runtime security experience.
- TypeScript or advanced Go experience beyond scripting.
- SIEM and detection experience, including RunReveal.
- SOC 2 or ISO 27001 cloud-control evidence experience.
Compensation and Benefits
- Competitive salary and equity in a high-growth startup.
- Healthcare, dental, and vision coverage.
- Ownership and autonomy over projects.
Skills
AWS, Azure, GCP, Wiz, Terraform, Opa/Rego, Checkov, Tfsec, Kubernetes, RBAC, Python, Go, EKS, Aks, GKE
Similar jobs
Security Engineering jobsSecures Supabase’s cloud platform, Kubernetes environments, containers, and infrastructure by conducting risk assessments, strengthening controls, and building scalable security guardrails. Requires senior-level platform or cloud security experience with deep AWS, Kubernetes, container, and Linux expertise.
Leads a global Security Operations team, setting detection, response, and security strategy while driving incident response and risk remediation. The role requires strong SaaS and cloud security experience, leadership ability, familiarity with major security standards, and responsible use of AI.
Senior offensive security engineer responsible for penetration testing, adversary emulation, exploit development, threat modeling, and security automation across cloud, container, SaaS, and AI/ML systems. Requires at least 3 years of security engineering experience, strong development skills, and hands-on offensive security expertise.
Own and scale security governance, risk, compliance, and customer assurance programs, including audits, controls monitoring, third-party risk, policies, and security questionnaires. The role requires 3–5 years of security GRC experience and hands-on understanding of IAM, endpoint, and cloud controls.
Security Engineer responsible for threat modeling, security reviews, vulnerability management, cloud and Kubernetes security, and detection and response across products and production infrastructure. Requires 7+ years of cloud security experience and hands-on expertise with IAM, infrastructure as code, automation, and security tooling.