
Cloud Security Engineer
Posted 3 hours ago

Posted 3 hours ago
This is a fully remote position, open to applicants in New York.
• Take ownership and enhance Polymarket's AWS security posture across various accounts, regions, and services — which includes IAM policies, SCPs, VPC segmentation, and account-level security baselines.
• Evaluate and contribute to Infrastructure as Code (IaC) modules that implement security defaults; incorporate automated security checks into the deployment pipeline, including policy-as-code validation and misconfiguration scanning.
• Manage cloud-side security telemetry, including CloudTrail, GuardDuty, Security Hub, Config Rules, VPC Flow Logs, and S3 access logging.
• Create and refine detection logic for cloud-specific threats; collaborate with the SOC team on alert fidelity, incident response runbooks, and AWS-level investigations.
• Oversee secrets management utilizing AWS Secrets Manager and SSM Parameter Store; manage KMS key policies, rotation, and envelope encryption techniques.
• Facilitate the remediation of findings from AWS Inspector, Security Hub, and third-party CSPM tools; uphold benchmarks aligned with CIS AWS Foundations.
• Assist with audit and compliance efforts (SOC 2, PCI-DSS, or similar) and perform regular access reviews to identify and address privilege creep.
• Over 4 years of experience in cloud security, cloud engineering, or a security-oriented infrastructure position.
• Extensive hands-on experience with AWS security services: IAM, SCP, GuardDuty, Security Hub, CloudTrail, Config, KMS, WAF, Inspector, and VPC.
• Practical experience in writing Infrastructure as Code (Pulumi, Terraform, CDK, or similar) with a security-centric approach.
• Solid understanding of AWS networking and how misconfigurations can lead to real attack surfaces.
• Proficient in at least one scripting or programming language (Python, TypeScript, or Go) for automation and tooling purposes.
• Capacity to assess architectural decisions for security risks and clearly communicate findings to engineering colleagues.
• (Plus) Familiarity with Pulumi, particularly TypeScript-based stacks.
• (Plus) Understanding of Web3, blockchain infrastructure, or crypto-sector threat models.
• (Plus) Experience in securing containerized workloads on ECS or EKS, including image scanning and runtime security measures.
• (Plus) AWS certifications: Security Specialty, Solutions Architect — Professional, or equivalent.
• (Plus) Knowledge of SOC 2 Type II or PCI-DSS cloud control requirements.
• Competitive salary & equity.
• Unlimited PTO.
• Comprehensive Health, Vision, & Dental coverage.
• 401k match.
• Hardware setup: new MacBook Pro, large display, & accessories.
Xometry
Carrier
Cloud at Work
PROSTAFF Schweiz
Get handpicked remote jobs straight to your inbox weekly.