
Cloud Security Engineer
Posted Sep 18

Posted Sep 18
This is a fully remote position, open to applicants in Ohio.
• Design and uphold security standards and reference architectures for cloud environments.
• Engage in architectural reviews for new cloud services, platforms, and significant infrastructure modifications.
• Analyze proposed architectures for security vulnerabilities and suggest suitable controls.
• Create secure patterns for cloud networking, identity management, encryption, logging, storage, computing, and managed services.
• Assess security boundaries between AWS-managed infrastructure and externally managed platforms such as Heroku and Snowflake.
• Detect insecure cloud configurations and excessive permissions.
• Evaluate cloud environments against established security standards and benchmarks.
• Prioritize and manage the remediation of cloud security issues.
• Establish least-privilege access models and controls for administrative and privileged cloud access.
• Develop security controls and configuration baselines for computing, storage, databases, networking, serverless services, VPNs, data warehouses, APIs, and secrets management.
• Collaborate with engineering teams to implement cloud security guardrails.
• Ensure cloud logging and security telemetry facilitate effective monitoring.
• Create or assist with detections for suspicious activities in the cloud.
• Partner with Security Operations to investigate cloud security incidents.
• Integrate security requirements into Infrastructure-as-Code practices.
• Develop automated checks, preventative controls, reusable secure modules, and templates.
• Automate security processes utilizing APIs, scripts, and cloud-native services.
• Support vulnerability management across cloud infrastructure and workloads.
• Coordinate the remediation of vulnerabilities with infrastructure and engineering teams.
• Formulate cloud security standards and technical specifications.
• Align cloud controls with security and compliance requirements.
• Provide technical documentation for audits and assessments.
• Assess AI-enabled cloud services such as Amazon Q for security and data-handling considerations.
• Collaborate frequently with Infrastructure, Platform Engineering, DevOps, Software Engineering, IAM, and Security teams.
• Report directly to the Director of Security.
• A minimum of 3 years of experience in cloud engineering, cloud security, infrastructure engineering, DevOps, security engineering, or a related discipline.
• Practical experience securing environments on at least one major public cloud platform.
• Comprehensive understanding of cloud IAM, networking, encryption, secrets management, logging and monitoring, computing and storage security, vulnerability management, and cloud-native security services.
• Capability to secure workloads across a hybrid environment that includes AWS and externally managed platforms like Heroku and Snowflake.
• Experience with scripting or automating infrastructure and security-related activities.
• Knowledge of least privilege and cloud-native identity models.
• Ability to assess cloud architectures and clearly communicate security requirements to technical teams.
• Must be capable of working on a computer for prolonged periods.
• Must demonstrate effective communication skills, both verbally and in writing.
• Must be able to manage and access sensitive cloud infrastructure and security data while adhering to organizational policies.
• Must be prepared to respond to critical cloud security incidents outside of standard working hours when necessary.
• Relevant certifications in AWS, cloud security, Kubernetes, or related security fields are advantageous but not mandatory.
• Preferred: extensive AWS security experience, particularly with multi-account cloud environments.
• Preferred: familiarity with Kubernetes, containers, or serverless technologies.
• Preferred: experience with CSPM or CNAPP platforms and knowledge of CIS cloud benchmarks, NIST guidance, or other cloud security frameworks.
• Preferred: understanding of Site-to-Site and client VPN architectures.
• Preferred: experience with column-level masking, row-level security, or PHI field-level governance in Snowflake or BigQuery.
• Preferred: proficiency with Terraform or CloudFormation and preventative cloud guardrails.
• Preferred: experience in regulated environments.
• Full-time employment.
• Standard business hours.
• Flexibility for responding to cloud security incidents or urgent remediation of high-risk issues.
• Equal Opportunity Employer dedicated to fostering an inclusive environment.
Sony Interactive Entertainment
Squads
Neo4j
PingWind Inc. (SDVOSB)
Get handpicked remote jobs straight to your inbox weekly.