Senior Infrastructure Security Engineer
The Senior Infrastructure Security Engineer will secure cloud and on-premises infrastructure through posture management, IaC guardrails, identity controls, certificate lifecycles, and network security. The role requires 5–8 years of infrastructure, SRE, or security engineering experience plus strong Terraform, cloud, Kubernetes, networking, and cryptography expertise.
About the job
Responsibilities
- Drive comprehensive Infrastructure Security Posture Management (ISPM) and cloud-native visibility using tools such as Wiz to identify risks, drift, and misconfigurations across cloud and on-premises infrastructure.
- Champion Infrastructure-as-Code (IaC) standards, including Terraform, to enforce secure defaults, immutability, and drift detection.
- Lead infrastructure security access and posture management for cloud and on-premises environments.
- Build automated security guardrails directly into CI/CD and deployment pipelines.
- Operate security-as-a-service platforms, including secrets management and certificate lifecycle services.
- Design and operate X.509 and SSH certificate lifecycles for secure machine-to-machine trust.
- Contribute to identity-centric access control systems using short-lived, Just-In-Time (JIT) access, Zero Trust, and automated authorization policies.
- Secure core network foundations, including global DNS architecture, service discovery, and network authentication systems.
- Design and maintain authentication controls for network infrastructure to ensure secure, monitored access.
- Partner with infrastructure, platform, and SRE teams to identify and remediate security gaps in foundational systems.
Requirements
- 5–8 years of hands-on experience in infrastructure engineering, SRE, or security engineering.
- Deep understanding of security principles across Linux, container runtimes, and cloud control planes.
- Proven experience using Terraform to manage complex, multi-environment infrastructure at scale.
- Strong knowledge of cryptography, secrets management, PKI, and modern authentication standards.
- Experience securing public cloud environments such as AWS or Google Cloud and/or bare-metal environments.
- Strong networking fundamentals, including routing, segmentation, firewalls, and Zero Trust architectures.
- Hands-on experience with Kubernetes and container security, including secure secrets injection into microservices.
- Fluency in at least one programming language; Go or Python preferred.
Nice-to-haves
- Experience securing high-scale cloud or AI infrastructure.
- Experience implementing Zero Trust identity architectures end to end.
- Familiarity with bare-metal provisioning and data center security considerations.
- Experience building or operating internal security platforms, such as Vault-as-a-Service.
- Deep experience with Wiz or similar CSPM platforms for enterprise-scale risk management.
Compensation and Benefits
- Compensation is paid as salary or hourly and is determined based on education, experience, knowledge, skills, abilities, internal equity, and market data.
- Pension contributions.
- Private health and dental insurance.
- Income protection.
- Life assurance.
Skills
Wiz, Terraform, Infrastructure-As-Code, CI/CD, Secrets Management, X.509, Ssh, Pki, Zero Trust, DNS, Kubernetes, AWS, GCP, Python
Similar jobs
Security Engineering jobsOwn and scale security governance, risk, compliance, and customer assurance programs, including audits, controls monitoring, third-party risk, policies, and security questionnaires. The role requires 3–5 years of security GRC experience and hands-on understanding of IAM, endpoint, and cloud controls.
Security Engineer responsible for threat modeling, security reviews, vulnerability management, cloud and Kubernetes security, and detection and response across products and production infrastructure. Requires 7+ years of cloud security experience and hands-on expertise with IAM, infrastructure as code, automation, and security tooling.
Leads interpretation and productization of federal compliance controls for Vanta’s public-sector platform, translating FedRAMP and related frameworks into technically testable guidance, automated detectors, mappings, and machine-readable authorization workflows. Requires 8–10+ years of hands-on federal compliance experience, especially FedRAMP program and SSP work.
Leads product security strategy and assessments for MongoDB’s server products, partnering with engineers on threat modeling, secure architecture, vulnerability research, and remediation. The role requires 7+ years of security experience and strong C++ expertise with low-level codebases.
Leads live fraud and abuse incident response, investigates high-risk accounts, and helps merchants remediate security threats. Requires 10+ years of security or fraud incident-response experience, expert Python and SQL skills, and expertise in forensics, threat intelligence, and network security.