Cloud Security Engineer
Secures multi-cloud infrastructure (AWS, Azure, GCP, OCI) with emphasis on Kubernetes hardening, IAM enforcement, CSPM using Wiz, and IaC security. Requires 5+ years experience, deep AWS and Kubernetes security expertise.
About the job
Responsibilities
- Securely deploy and maintain infrastructure across multi-cloud environments (AWS, Azure, GCP, OCI), establishing cloud-specific guardrails to prevent insecure deployments and configurations.
- Implement and enforce security best practices for Cloud native Kubernetes clusters, including granular RBAC, network policies, and admission controllers.
- Develop, implement, and enforce IAM policies and procedures across all systems, managing user identities and enforcing least privilege.
- Ensure security of container images, registries, and runtime environments using Docker, Podman, and container scanning solutions.
- Manage infrastructure and security policies through IaC tools such as Terraform, CloudFormation, or AWS CDK.
- Maintain CSPM tools such as Wiz to detect and remediate misconfigurations and compliance drifts.
- Automate compliance checks and generate audit evidence across multi-cloud environments.
- Monitor and protect running applications and containers from runtime threats.
Requirements
- 5+ years of industry experience in software engineering or security engineering, focusing on secure, production-grade cloud systems.
- Extensive experience with Kubernetes security (securing workloads, RBAC, cloud-native secret management).
- Deep operational security experience with AWS (mandatory), preferred experience with Azure, GCP, or OCI.
- Proficiency in IaC tools: Terraform, CloudFormation, or AWS CDK.
- Hands-on expertise with CSPM platforms like Wiz.
- Strong background in IAM and least-privilege architectures across multi-cloud and on-premises environments.
- Experience with container security, image scanning, and runtime protection tools.
Nice to Haves
- Certifications: AWS Certified Security – Specialty, CKS, CKA.
- Proficiency in Go/Golang, Python, or C++ for security automation.
- Experience automating compliance frameworks and audit evidence generation.
- Experience in air-gapped or constrained on-premises environments.
Compensation
Base salary range: $125,000 - $160,000 USD annually, plus equity and benefits.
Skills
Kubernetes, AWS, Terraform, Wiz, IAM, RBAC, Docker, CloudFormation, Aws Cdk, Azure, GCP, Oci, Podman
Similar jobs
Security Engineering jobsDevelops machine-level safety cases, hazard analyses, and safety requirements for autonomous mining and industrial equipment. The role requires hands-on system safety experience, knowledge of ISO 26262, and collaboration across hardware, software, controls, and validation teams.
The Security GRC Analyst will manage security risks, policies, audits, control testing, and compliance reporting while partnering with technical and business stakeholders. The role requires 4+ years of GRC or security assurance experience and familiarity with major security frameworks.
Investigates and assesses physical security threats involving personnel, executives, events, travel, and operations. The role requires at least five years of relevant intelligence or threat-assessment experience, strong analytical communication, and familiarity with OSINT, behavioral threat methodologies, and technology-enabled investigations.
Owns application security by embedding review workflows in SDLC, building SAST/DAST pipelines in CI/CD, managing vulnerability remediation, and operating bug bounty programs. Requires 5+ years experience finding/fixing vulnerabilities, strong skills in Python/TypeScript/Go, and SAST/DAST tooling.
The Security Engineer will secure AWS and Google Cloud environments, monitor infrastructure, and assess AI/LLM deployments, MCP integrations, and agentic workflows. The role requires 5+ years of security engineering experience, including 2+ years in AI/ML security, plus cloud security and compliance expertise.