Senior Cloud Security Engineer
Leads the maturation of an AWS cloud security program by designing and automating controls, integrating security into CI/CD workflows, and developing continuous compliance evidence. The role requires AWS security expertise and experience with infrastructure as code, automation, regulated SaaS, and cloud compliance initiatives.
About the job
Responsibilities
- Design and implement cloud security controls across AWS.
- Build security automation using infrastructure as code, APIs, and scripting.
- Lead cloud security posture management and continuous improvement.
- Integrate security into CI/CD pipelines and engineering workflows.
- Develop continuous evidence collection supporting FedRAMP and other continuous compliance initiatives.
- Partner with engineering teams on secure architecture and cloud best practices.
- Improve cloud monitoring, detection, and security metrics.
- Support customer security requirements and compliance initiatives, including SOC 2, ISO 27001, and FedRAMP.
Success Criteria
- Cloud security controls are automated, repeatable, and auditable.
- Continuous evidence collection reduces manual audit effort.
- Security is embedded into engineering workflows.
- AWS security posture improves through measurable automation and engineering-driven controls.
- The organization is positioned to mature toward modern FedRAMP continuous authorization practices.
Requirements and Preferred Qualifications
- AWS cloud security expertise required.
- Direct FedRAMP Moderate or High experience preferred.
- Knowledge and understanding of FedRAMP CR-26 and/or 20x preferred.
- AWS Bedrock experience preferred.
- Infrastructure as code experience, with Terraform preferred.
- Security automation and scripting experience.
- CI/CD security integration experience.
- Cloud detection and monitoring experience.
- Experience supporting regulated SaaS environments and cloud compliance initiatives.
Compensation and Benefits
- Competitive salary.
- Medical, vision, and dental benefits.
- 401(k).
- Stock options.
- HSA contribution.
- Learning stipend.
- Flexible PTO policy.
- Quarterly mental-escape days.
- Generous parental leave policy.
- Home office stipend.
- Mobile phone reimbursement.
- Home internet reimbursement for remote employees.
- Anniversary and milestone celebrations.
Skills
AWS, Cloud Security, Terraform, Infrastructure As Code, Security Automation, Scripting, CI/CD, FedRAMP, Aws Bedrock, Cloud Monitoring, Cloud Detection, SOC 2, ISO 27001, APIs, Continuous Compliance
Similar jobs
Security Engineering jobsThe Senior Information Security Engineer will lead threat hunting, detection engineering, incident response, vulnerability management, and security-platform ownership across cloud and enterprise environments. The role requires 5+ years of security experience, strong attacker-TTP knowledge, and hands-on expertise with enterprise security technologies and automation.
Build and operate Chainguard’s public-sector governance and trust capabilities, translating federal security requirements into automated controls, evidence systems, and risk-based decisions. The role requires hands-on federal, defense, or intelligence experience and strong technical fluency in cloud-native environments.
The Senior Security Analyst will manage security governance, risk, and compliance activities, including audits, risk assessments, remediation, vendor reviews, and operational security. The role requires 5+ years of relevant experience, a bachelor’s degree, cloud-security knowledge, and hands-on AI-assisted GRC automation experience.
Leads end-to-end response to sophisticated compromises, account takeovers, device threats, and related financial fraud for high-profile clients. Requires 5–8+ years of incident response or DFIR experience, broad device forensics expertise, strong client communication, and fraud-remediation experience.
Senior Security Engineer responsible for application, cloud, and platform security, with a focus on automating security workflows, threat modeling, secure development, and remediation. Requires hands-on SaaS security, cloud infrastructure, code review, and agent or automation experience.