Skip to content
OnticOntic

Senior Cloud Security Engineer

Leads the maturation of an AWS cloud security program by designing and automating controls, integrating security into CI/CD workflows, and developing continuous compliance evidence. The role requires AWS security expertise and experience with infrastructure as code, automation, regulated SaaS, and cloud compliance initiatives.

About the job

Responsibilities

  • Design and implement cloud security controls across AWS.
  • Build security automation using infrastructure as code, APIs, and scripting.
  • Lead cloud security posture management and continuous improvement.
  • Integrate security into CI/CD pipelines and engineering workflows.
  • Develop continuous evidence collection supporting FedRAMP and other continuous compliance initiatives.
  • Partner with engineering teams on secure architecture and cloud best practices.
  • Improve cloud monitoring, detection, and security metrics.
  • Support customer security requirements and compliance initiatives, including SOC 2, ISO 27001, and FedRAMP.

Success Criteria

  • Cloud security controls are automated, repeatable, and auditable.
  • Continuous evidence collection reduces manual audit effort.
  • Security is embedded into engineering workflows.
  • AWS security posture improves through measurable automation and engineering-driven controls.
  • The organization is positioned to mature toward modern FedRAMP continuous authorization practices.

Requirements and Preferred Qualifications

  • AWS cloud security expertise required.
  • Direct FedRAMP Moderate or High experience preferred.
  • Knowledge and understanding of FedRAMP CR-26 and/or 20x preferred.
  • AWS Bedrock experience preferred.
  • Infrastructure as code experience, with Terraform preferred.
  • Security automation and scripting experience.
  • CI/CD security integration experience.
  • Cloud detection and monitoring experience.
  • Experience supporting regulated SaaS environments and cloud compliance initiatives.

Compensation and Benefits

  • Competitive salary.
  • Medical, vision, and dental benefits.
  • 401(k).
  • Stock options.
  • HSA contribution.
  • Learning stipend.
  • Flexible PTO policy.
  • Quarterly mental-escape days.
  • Generous parental leave policy.
  • Home office stipend.
  • Mobile phone reimbursement.
  • Home internet reimbursement for remote employees.
  • Anniversary and milestone celebrations.

Skills

AWS, Cloud Security, Terraform, Infrastructure As Code, Security Automation, Scripting, CI/CD, FedRAMP, Aws Bedrock, Cloud Monitoring, Cloud Detection, SOC 2, ISO 27001, APIs, Continuous Compliance

Supernova Technology

Supernova Technology

Chicago, IL

Senior Information Security Engineer
$110k+/yrOn-site5+ YOESecurity Engineering

The Senior Information Security Engineer will lead threat hunting, detection engineering, incident response, vulnerability management, and security-platform ownership across cloud and enterprise environments. The role requires 5+ years of security experience, strong attacker-TTP knowledge, and hands-on expertise with enterprise security technologies and automation.

Chainguard

Chainguard

United States

Senior Security Analyst
$110k+/yrRemote5+ YOESecurity Engineering

Build and operate Chainguard’s public-sector governance and trust capabilities, translating federal security requirements into automated controls, evidence systems, and risk-based decisions. The role requires hands-on federal, defense, or intelligence experience and strong technical fluency in cloud-native environments.

Valon

Valon

United States

Senior Security Analyst
$115k+/yrRemote5+ YOESecurity Engineering

The Senior Security Analyst will manage security governance, risk, and compliance activities, including audits, risk assessments, remediation, vendor reviews, and operational security. The role requires 5+ years of relevant experience, a bachelor’s degree, cloud-security knowledge, and hands-on AI-assisted GRC automation experience.

BlackCloak

BlackCloak

United States

Senior Incident Responder
$105k+/yrRemote5+ YOESecurity Engineering

Leads end-to-end response to sophisticated compromises, account takeovers, device threats, and related financial fraud for high-profile clients. Requires 5–8+ years of incident response or DFIR experience, broad device forensics expertise, strong client communication, and fraud-remediation experience.

ConductorOne

ConductorOne

San Francisco, CA
Senior Security Engineer
$100k+/yrRemote5+ YOESecurity Engineering

Senior Security Engineer responsible for application, cloud, and platform security, with a focus on automating security workflows, threat modeling, secure development, and remediation. Requires hands-on SaaS security, cloud infrastructure, code review, and agent or automation experience.