# Staff Cloud Security Engineer

**Company:** [Addepar](https://hotfix.jobs/companies/addepar)
**Location:** Unspecified
**Role:** Security Engineering
**Experience:** 7+ years
**Skills:** AWS, Aws Organizations, Aws Control Tower, Terraform, Python, Boto3, Opa, Rego, GitHub Actions, Argo Cd, Kubernetes, Linux, IAM, Aws Kms, Aws Secrets Manager
**Posted:** 2026-06-30

> Secures and hardens Addepar’s multi-account AWS environments, enforcing data locality, identity, networking, and infrastructure-as-code controls. The role requires deep AWS security, Terraform, Python, networking, Kubernetes, CI/CD, and policy-as-code expertise.

## Job Description

## Responsibilities

- Maintain and iterate on Addepar’s Swiss AWS environment to enforce data locality restrictions and ensure core infrastructure is secure and operational.
- Integrate security best practices, policies, and solutions.
- Partner with the Swiss Infrastructure Operations team to maintain high security standards across the estate.
- Design and harden a multi-account AWS environment using Organizations, Control Tower, SCPs, custom tools, and guardrails.
- Design and build secure networking and private resource access patterns for human and programmatic use.
- Author and maintain Terraform code for security infrastructure and contribute to a secure Terraform module registry.
- Write and support CI checks using policy-as-code and infrastructure-as-code scanning.
- Automate vulnerability detection and remediation with native AWS technologies, event-driven architecture, and serverless workflows.
- Strengthen identity and secrets management through federation, role design, ABAC, IAM policy reviews, KMS strategy, Secrets Manager, and Parameter Store.
- Use discovery tools and cloud-native logging for investigations, resource discovery, and troubleshooting.
- Participate in infrastructure design reviews and cloud security assessments, producing clear and actionable reports.
- Partner with engineering teams to deliver secure business outcomes and measure impact through coverage, prevention, and response metrics.
- Act as an escalation point for the Security Operations Center.

## Requirements

- Extensive security experience, including several years of hands-on experience building and securing AWS production environments and multi-account architectures.
- Bachelor’s degree in computer science or engineering, or equivalent practical experience.
- Clear written and verbal communication skills, with the ability to influence across teams and mentor others.
- Expertise in AWS security best practices and deep knowledge of native AWS services.
- Advanced Terraform experience, including module creation, remote execution environments, and integrating security checks into CI.
- Extensive experience with Python and boto3.
- Deep networking knowledge.
- Strong Linux, containers, Kubernetes, secrets management, and CI/CD fundamentals.
- Experience with policy-as-code, GitOps, and Zero Trust solutions.

## Similar jobs

- [Senior Security GRC Analyst](https://hotfix.jobs/jobs/b54fb115-3bb7-4d88-8fdc-b7901d26d90d) - Monarch - Remote - $180k – $215k/yr
- [Lead Product GRC Subject Matter Expert](https://hotfix.jobs/jobs/57c937d5-05e3-4033-875a-890645c4aa6b) - Vanta - Remote - $230k – $270k/yr
- [Platform Security Engineer](https://hotfix.jobs/jobs/e556dd76-0f95-4dfa-9d3d-e476f24057c0) - Supabase - Remote
- [Compliance Engineer](https://hotfix.jobs/jobs/63197ba5-a12d-497a-a0b9-91e5e7050ac1) - Retell AI - Remote - $72k – $90k/yr
- [Manager, Security Operations](https://hotfix.jobs/jobs/0a4637da-6072-4ec3-a0a9-8b6d4a412d45) - Vanta - Remote - $178k – $209k/yr

**Apply:** https://hotfix.jobs/jobs/cd42c2e1-731c-4e5f-aa90-de1ac68ebcf3
**Canonical:** https://hotfix.jobs/jobs/cd42c2e1-731c-4e5f-aa90-de1ac68ebcf3