Skip to content
MercuryMercury

Senior Cloud Security Engineer - InfoSec

The Senior Cloud Security Engineer will design secure, resilient AWS infrastructure, automate security controls, and partner with engineering teams on cloud risk, compliance, and remote-access challenges. Candidates should have at least five years of relevant experience and familiarity with IaC, security frameworks, and privacy regulations.

About the job

Responsibilities

  • Build and define cloud security posture, enable cyber resilience, and support zero-trust initiatives.
  • Apply Governance, Risk, and Compliance principles to cloud engineering.
  • Partner with infrastructure and engineering teams to improve cloud infrastructure reliability and security.
  • Automate cloud security controls to minimize threats, vulnerabilities, and risk.
  • Shape AWS cloud architecture around resilience, least privilege, and long-term maintainability.
  • Address remote-access challenges in a remote-first environment.
  • Collaborate with teams and stakeholders across the company to resolve cloud security concerns.

Requirements

  • 5+ years of relevant experience in cloud security, networking, information security, or related fields.
  • Strong desire and demonstrated ability to learn and grow.
  • Familiarity with security frameworks and privacy regulations, including NIST CSF, FFIEC, SOX, SOC 2, GLBA, ISO 27018, and PCI DSS.
  • Strong problem-solving and analytical skills, with the ability to remain calm and competent in high-pressure situations.
  • Understanding of accepted security practices, troubleshooting, attack vectors, and customer support.
  • Familiarity with infrastructure-as-code tooling.

Nice to Have

  • AWS certifications.

Compensation and Benefits

  • US base salary: $166,600–$208,300.
  • Canadian base salary: CAD 157,400–196,800.
  • Total rewards include base salary, equity (stock options/RSUs), and benefits.

Skills

AWS, Cloud Security, Cloud Architecture, Zero Trust, Cyber Resilience, Infrastructure As Code, Nist Csf, SOC 2, Pci Dss, Security Automation, Networking, Governance Risk Compliance

Upstart

Upstart

United States

Senior Application Security Engineer
$167k+/yrRemote5+ YOESecurity Engineering

Leads application security initiatives across products, APIs, distributed systems, and AI-enabled applications. The role requires at least five years of security or software engineering experience, strong threat-modeling and architecture skills, and the ability to build security automation and drive remediation.

GitLab

GitLab

United States
Senior Manager, Product Security Engineering
$168k+/yrRemote5+ YOESecurity Engineering

Leads the Product Security team responsible for security posture management, governed security rollouts, and software supply chain security across GitLab’s software factory. The role combines technical security leadership, organizational adoption, audit readiness, team building, and external thought leadership.

Censys

Censys

United States

Research Systems Analyst
$170k+/yrRemote6+ YOESecurity Engineering

Build and operate scalable malware-analysis, threat-enrichment, and graph-intelligence systems that power security research and detection. The role requires 6+ years of security pipeline or threat-intelligence experience, strong Python or Go skills, and expertise in cloud and distributed systems.

Flex

Flex

United States

Senior Software Engineer, Security
$170k+/yrRemote5+ YOESecurity Engineering

Build and lead product and infrastructure security for systems that move money, creating secure defaults, automation, access controls, and vulnerability management processes. The role requires strong software engineering, cloud infrastructure expertise, risk-based judgment, and the ability to operate independently as the senior security engineer.

Wiz

Wiz

United States

Compliance Engineer - Public Sector
$174k+/yrRemote6+ YOESecurity Engineering

Leads engineering for Wiz’s FedRAMP CR26 initiative, translating federal compliance requirements into scalable compliance-as-code, automation, and evidence-generation solutions. Requires 6+ years in security, DevOps, or systems engineering and deep experience with NIST, FedRAMP, and government cloud environments.