Senior Security Engineer - Cloud Security
Senior individual contributor responsible for improving multi-cloud security posture, leading vulnerability management, hardening infrastructure, and embedding DevSecOps controls. Requires 6–9 years of security experience, deep AWS expertise, and experience with cloud-native environments and vulnerability programs.
About the job
Responsibilities
Cloud Security Engineering and Posture Management
- Improve cloud security posture across AWS, Azure, and Google Cloud, including workload security, IAM hardening, network segmentation, encryption, and least-privilege enforcement.
- Lead cloud security assessments and configuration reviews using Wiz and cloud-native tools.
- Drive zero-trust initiatives and cloud-native security controls across multi-cloud infrastructure.
- Translate security architecture standards into operational controls and provide implementation feedback.
- Evaluate and implement security controls for containers, Kubernetes workloads, CI/CD pipelines, and Infrastructure as Code.
- Contribute to cloud security architecture and design reviews, implementation guidance, operational security expertise, and risk assessments.
Vulnerability Management
- Lead execution and continuous improvement of the vulnerability management program across AWS, Azure, and Google Cloud.
- Define and enforce vulnerability SLAs and risk-based prioritization frameworks.
- Analyze vulnerability data, synthesize trends, and produce executive-ready reporting on exposure, remediation velocity, and risk posture.
- Drive systemic remediation with DevOps, SRE, IT/infrastructure, and engineering teams.
- Tune scanning coverage, detection fidelity, and vulnerability-management platform configuration.
- Identify program gaps, define improvement roadmaps, and present recommendations to security leadership.
DevSecOps and Infrastructure Hardening
- Embed security controls into CI/CD pipelines, Infrastructure as Code templates, and cloud provisioning workflows.
- Drive policy-as-code, automated misconfiguration detection, and runtime security controls.
- Define and enforce secure configuration baselines across cloud workloads, operating systems, and network infrastructure.
- Harden container and Kubernetes environments and support secrets management and workload identity practices.
Incident Response
- Support complex and high-severity incident responses involving cloud and infrastructure security.
- Improve incident response playbooks and runbooks for cloud and infrastructure-related security events.
- Conduct cloud threat hunting and contribute to detection engineering.
- Participate in post-incident reviews and systemic improvements.
Compliance and Governance
- Align vulnerability-management and cloud-security controls with compliance requirements.
- Prepare technical evidence and control documentation for audits and compliance activities.
- Advise engineering and business teams on security considerations for technologies, integrations, and infrastructure decisions.
Mentorship and Team Contribution
- Mentor colleagues and peers and guide technical decisions.
- Lead security tooling evaluations and contribute to platform investment decisions.
- Design and scale AI-assisted security workflows for vulnerability analysis, cloud security assessments, remediation prioritization, and operational efficiency, with strong validation and risk-management practices.
Requirements
Experience
- 6–9 years of experience in security engineering, cloud security, or a closely related discipline.
- Ownership of complex cloud security workstreams in a multi-cloud or cloud-native environment.
- Experience leading or significantly contributing to a vulnerability management program, including tool operation, process design, and stakeholder engagement.
- Experience securing cloud-native SaaS products or working in complex cloud-first technology environments.
- Experience designing or operationalizing repeatable AI-assisted workflows for security engineering, vulnerability management, security analysis, automation, or operational efficiency.
Cloud Security
- Deep hands-on AWS security expertise, including IAM, VPC/networking, GuardDuty, Security Hub, CloudTrail, KMS, and AWS-native hardening practices.
- Additional Azure and Google Cloud experience is a plus.
- Strong working knowledge of CSPM tools; direct Wiz experience is highly advantageous.
- Experience with container security, Kubernetes security, and Infrastructure as Code security tooling such as Terraform or CloudFormation.
- Familiarity with CI/CD security integration and DevSecOps practices.
Technical Foundations
- Strong understanding of network security, protocols, and infrastructure security fundamentals, including TCP/IP, DNS, TLS, VPN, and firewall design.
- Working knowledge of IAM, Zero Trust principles, secrets management, OAuth 2.0, OIDC, and SAML.
- Scripting or automation experience with Python, Bash, or equivalent.
- Ability to validate AI-generated outputs using security expertise, testing, data analysis, or structured review before production use.
Frameworks and Compliance
- Familiarity with NIST CSF, CIS Benchmarks, and OWASP frameworks.
- Strong command of CVSS, EPSS, and risk-based prioritization methodologies.
- Experience conducting technical risk assessments and security design reviews.
Communication and Influence
- Ability to explain complex security risks and trade-offs clearly to engineering and business stakeholders.
Skills
AWS, Azure, GCP, Aws Iam, Amazon Vpc, Guardduty, Aws Security Hub, Cloudtrail, Aws Kms, Wiz, Kubernetes, Terraform, CloudFormation, Python
Similar jobs
Security Engineering jobsOwn and scale security governance, risk, compliance, and customer assurance programs, including audits, controls monitoring, third-party risk, policies, and security questionnaires. The role requires 3–5 years of security GRC experience and hands-on understanding of IAM, endpoint, and cloud controls.
Leads interpretation and productization of federal compliance controls for Vanta’s public-sector platform, translating FedRAMP and related frameworks into technically testable guidance, automated detectors, mappings, and machine-readable authorization workflows. Requires 8–10+ years of hands-on federal compliance experience, especially FedRAMP program and SSP work.
Secures Supabase’s cloud platform, Kubernetes environments, containers, and infrastructure by conducting risk assessments, strengthening controls, and building scalable security guardrails. Requires senior-level platform or cloud security experience with deep AWS, Kubernetes, container, and Linux expertise.
Build and automate technical security controls, compliance workflows, and audit evidence for enterprise readiness. The role requires strong scripting or programming skills, security fundamentals, and the ability to collaborate across engineering, security, legal, and customer-facing teams.
Leads a global Security Operations team, setting detection, response, and security strategy while driving incident response and risk remediation. The role requires strong SaaS and cloud security experience, leadership ability, familiarity with major security standards, and responsible use of AI.