
Cloud Security Engineer – Architect
Posted Jul 29

Posted Jul 29
This is a fully remote position, open to applicants in North Carolina, +2 more states.
• Spearhead the creation of a global Zero Trust architecture, ensuring comprehensive identity governance (IAM), network micro-segmentation, and data encryption across AWS, Azure, or GCP.
• Design specialized security frameworks for AI/ML pipelines, emphasizing data privacy for training datasets, model integrity, and securing LLM-integrated applications against new attack vectors.
• Formulate and implement enterprise-wide security policies using Terraform, guaranteeing that non-compliant infrastructure is automatically remediated or halted from deployment.
• Plan and supervise the integration of CNAPP and CSPM tools to deliver real-time insights into misconfigurations, vulnerabilities, and excessive permissions.
• Perform in-depth threat modeling for intricate cloud-native systems, simulating advanced persistent threats (APTs) and "blast radius" scenarios to enhance system resilience.
• Serve as the chief security advisor for the Cloud Architecture team, bridging the chasm between DevOps agility and stringent regulatory compliance (SOC2).
• Assist in transitioning the organization to a "Zero Standing Privilege" model for all production environments.
• Aid in achieving automated audits for essential compliance frameworks (e.g., NIST, CIS Benchmarks).
• Leverage AI-driven monitoring to minimize the detection time of anomalous cloud activities.
• An advanced degree in Computer Science, Cybersecurity, or a related engineering discipline is preferred.
• A BS degree from an accredited College/University in the relevant field of services is required, or 4 additional years of pertinent experience in lieu of a college degree.
• Over 12 years of experience in Cybersecurity.
• At least 6 years of experience focused on designing secure cloud environments at scale.
• Mastery of cloud-native security suites (e.g., AWS Security Hub, Azure Defender, GCP Security Command Center).
• Expert-level knowledge of Identity-First Security, including CIEM, Just-In-Time (JIT) access, and complex OIDC/SAML flows.
• Proficiency in Python, Go, or Bash for developing custom security automations and integrating with SOAR platforms.
• Extensive expertise in embedding automated security testing (SAST/DAST/SCA) directly into CI/CD pipelines.
• Advanced understanding of secure connectivity, including SD-WAN, Cloud WAF, and Zero Trust Network Access (ZTNA).
• Strong capability to bridge the divide between "Speed of DevOps" and "Rigors of Security" while effectively communicating with executive leadership.
• Demonstrated ability to influence technical roadmaps and clearly present security risks to C-suite stakeholders.
• Must be a US Citizen or Permanent US Resident (Green Card Holder).
• Must be eligible to obtain Public Trust Clearance.
• Capable of passing a drug screening, criminal history, and credit checks.
• Must have resided in the United States for the past 5 years.
• Cannot have traveled more than 6 months outside the United States within the last five years, excluding military service. (Exceptions do not include military family members.)
• None specified
Sony Interactive Entertainment
Squads
Neo4j
PingWind Inc. (SDVOSB)
Get handpicked remote jobs straight to your inbox weekly.