# Cloud Security Engineer

**Company:** [Polymarket](https://hotfix.jobs/companies/polymarket)
**Location:** Remote
**Role:** Security Engineering
**Salary:** $180k – $250k/yr
**Experience:** 4+ years
**Skills:** AWS, IAM, scp, guardduty, security hub, cloudtrail, config, kms, waf, inspector, vpc, Terraform, Pulumi, cdk, Python
**Posted:** 2026-07-16

> Own and improve Polymarket's AWS security posture by designing and enforcing security controls in infrastructure code, managing cloud telemetry and detection, and driving compliance. Requires 4+ years cloud security experience, deep AWS expertise, and IaC skills.

## Job Description

## Responsibilities
- Own and continuously improve Polymarket's AWS security posture across accounts, regions, and services — including IAM policies, SCPs, VPC segmentation, and account-level security baselines.
- Review and contribute to IaC modules that encode security defaults; integrate automated security checks into the deployment pipeline including policy-as-code validation and misconfiguration scanning.
- Own cloud-side security telemetry: CloudTrail, GuardDuty, Security Hub, Config Rules, VPC Flow Logs, and S3 access logging.
- Develop and tune detection logic for cloud-specific threats; partner with the SOC team on alert fidelity, incident response runbooks, and AWS-level investigations.
- Govern secrets management using AWS Secrets Manager and SSM Parameter Store; manage KMS key policies, rotation, and envelope encryption patterns.
- Drive remediation of findings from AWS Inspector, Security Hub, and third-party CSPM tooling; maintain benchmarks aligned to CIS AWS Foundations.
- Support audit and compliance activities (SOC 2, PCI-DSS, or similar) and conduct regular access reviews to identify and remediate privilege creep.

## Requirements
- 4+ years of experience in cloud security, cloud engineering, or a security-focused infrastructure role.
- Deep, hands-on expertise with AWS security services: IAM, SCP, GuardDuty, Security Hub, CloudTrail, Config, KMS, WAF, Inspector, and VPC.
- Hands-on experience writing infrastructure as code (Pulumi, Terraform, CDK, or equivalent) with a security-first mindset.
- Strong understanding of AWS networking and how misconfigurations translate to real attack surface.
- Proficiency in at least one scripting or programming language (Python, TypeScript, or Go) for automation and tooling.
- Ability to evaluate architectural decisions for security risk and communicate findings clearly to engineering peers.

## Nice-to-Haves
- Familiarity with Pulumi, specifically TypeScript-based stacks.
- Familiarity with Web3, blockchain infrastructure, or crypto-sector threat models.
- Experience securing containerized workloads on ECS or EKS, including image scanning and runtime security.
- AWS certifications: Security Specialty, Solutions Architect — Professional, or equivalent.
- Exposure to SOC 2 Type II or PCI-DSS cloud control requirements.

## Compensation & Benefits
- Competitive salary & equity.
- Unlimited PTO.
- Full Health, Vision, & Dental coverage.
- 401k match.
- Hardware setup: new MacBook Pro, big display, & accessories.

## Similar roles

- [Network Security Engineer](https://hotfix.jobs/jobs/e7a9e818-ec25-409d-a1d9-0de7d952564d) - Lightning AI - San Francisco, CA - $180k – $220k/yr
- [Product Security Engineer (PSIRT - Product Security Incident Response Team)](https://hotfix.jobs/jobs/4a459143-2760-42fb-8536-f8b48519d936) - Replit - Foster City, CA - $180k – $325k/yr
- [Security Engineer - Azure Government](https://hotfix.jobs/jobs/77997ce4-7f3e-4114-90ae-2b590d6da619) - xAI - Palo Alto, CA - $180k – $440k/yr
- [Security Engineer, Infrastructure Security](https://hotfix.jobs/jobs/07228b27-48b3-41af-8e9a-208076e63fac) - OpenAI - Remote - $184k – $385k/yr
- [Software Engineer, Infrastructure Security](https://hotfix.jobs/jobs/afa352ff-09e0-4e37-8fa3-ab06fe7448dc) - OpenAI - Remote - $184k – $385k/yr

**Apply:** https://hotfix.jobs/jobs/eee034cc-a2f0-4fa9-bf73-e27f81d8ad68
**Canonical:** https://hotfix.jobs/jobs/eee034cc-a2f0-4fa9-bf73-e27f81d8ad68