Senior Cloud Security Engineer
Leads cloud and product security maturity through automated controls, container security, vulnerability management, threat modeling, and DevSecOps practices across AWS and Google Cloud. Requires 6+ years of cloud or product security experience and hands-on expertise with infrastructure as code, Kubernetes, and security automation.
About the job
Responsibilities
- Lead the maturity of cloud and enterprise security programs by identifying infrastructure gaps and developing optimized, automated solutions.
- Design, deploy, and maintain immutable cloud security controls across AWS and Google Cloud environments using Infrastructure as Code tools such as Terraform.
- Define, implement, and monitor security baselines for containerized workloads and orchestration platforms, with a focus on Docker and Kubernetes runtime security.
- Integrate automated security testing, including SAST, DAST, dependency scanning, and secret scanning, into CI/CD deployment pipelines.
- Oversee cloud vulnerability scanning, prioritize vulnerabilities based on runtime risk, and coordinate remediation across engineering teams.
- Lead security architecture reviews and threat-modeling sessions for cloud-native applications, providing actionable recommendations to Product and Engineering stakeholders.
- Author and contribute to cloud security policies, procedures, and standards, mapping technical controls to SOC 2 and ISO 27001.
- Support security incident response efforts and promote DevSecOps and security awareness across the organization.
Requirements
- 6+ years of relevant experience in Cloud Security Engineering or Product Security.
- Deep technical knowledge and hands-on experience managing security controls in AWS and/or Google Cloud environments.
- Experience using Terraform, CloudFormation, or Pulumi to deploy and manage secure infrastructure.
- Practical experience securing Kubernetes environments, managing network policies, and scanning container images.
- Proficiency in security automation using Python, Go, PowerShell, or Bash.
- Familiarity with security frameworks and standards such as NIST, ISO 27001, and CIS benchmarks.
- Strong communication skills and experience collaborating with Engineering, IT, and Product stakeholders.
Nice to Have
- Understanding of centralized logging architectures, SIEM platforms, and data analysis for anomaly detection.
- Practical knowledge of cloud digital forensics and incident response methodologies.
- Advanced application of the MITRE ATT&CK framework to detect and remediate modern threats.
- CCSP, AWS Certified Security – Specialty, Google Professional Cloud Security Engineer, or equivalent certification.
Skills
AWS, GCP, Terraform, CloudFormation, Pulumi, Kubernetes, Docker, Python, Go, PowerShell, Bash, SAST, DAST, SIEM, Mitre Att&Ck
Similar jobs
Security Engineering jobsSenior product security engineer responsible for embedding security across the SDLC, building security automation, conducting reviews and penetration testing, and leading vulnerability response. Requires 5+ years of security experience, strong web and mobile security expertise, and hands-on AWS, CI/CD, and security tooling knowledge.
Leads application and AI security assessments across web, API, cloud-native, and LLM-based systems. Requires 8+ years of cybersecurity experience, hands-on penetration testing and secure SDLC expertise, and experience adversarially testing AI applications.
The Senior Security Engineer will build and operate detection and incident-response capabilities across cloud production and corporate environments. The role requires 7+ years of security engineering experience, AWS expertise, threat hunting, investigations, automation, and SIEM/SOAR proficiency.
Own and scale security governance, risk, compliance, and customer assurance programs, including audits, controls monitoring, third-party risk, policies, and security questionnaires. The role requires 3–5 years of security GRC experience and hands-on understanding of IAM, endpoint, and cloud controls.
Own detection engineering and lead incident response across corporate and production environments, building cloud, endpoint, runtime, and Kubernetes coverage. The role requires 6+ years in security, hands-on detection development, and end-to-end incident leadership.