
Cloud Security Engineer
Posted 2 days ago

Posted 2 days ago
This is a fully remote position, open to applicants in Pennsylvania.
• Oversee and protect Azure-centric cloud infrastructure and cloud-based applications.
• Safeguard containerized workloads and Kubernetes environments, focusing on network policy, workload identity, runtime protection, and container image assessments.
• Take ownership of and enhance Cloud Security Posture Management (CSPM) by pinpointing and correcting cloud misconfigurations.
• Secure Infrastructure-as-Code (IaC) pipelines using Terraform/OpenTofu through access control, secrets management, and deployment approval processes.
• Manage Microsoft Entra ID, utilizing Conditional Access, Entitlement Management, and Just-In-Time (JIT) privileged access models.
• Evaluate network diagrams and changes in connectivity; provide guidance on segmentation and sensitive data flows alongside IT and SRE teams.
• Administer Zero Trust network access and edge security solutions.
• Oversee Security Information and Event Management (SIEM), Data Loss Prevention (DLP), Extended Detection and Response (E/XDR), and vulnerability management systems.
• Monitor alerts, respond to incidents, escalate issues as necessary, and engage in the incident response on-call rotation.
• Perform threat analyses, vulnerability assessments, and risk evaluations; document findings, manage mitigations, and report updates to leadership.
• Create queries, scripts, integrations, and automated workflows to enhance cloud security operations.
• Collaborate with development teams to embed security within the Software Development Life Cycle (SDLC) and Continuous Integration/Continuous Deployment (CI/CD) pipeline.
• Conduct regular cloud configuration and access reviews to ensure compliance.
• Contribute to audits and assessments that bolster Governance, Risk, and Compliance (GRC) initiatives.
• Bachelor's degree in information security, computer science, or a related discipline is preferred; equivalent experience will be considered.
• 5+ years of experience in cloud security engineering or a similar role.
• Extensive hands-on experience in securing cloud infrastructure and cloud-based applications; Azure experience is preferred, AWS experience is an advantage.
• Practical network security experience with a robust understanding of network architecture, connectivity, segmentation, and firewall controls.
• Proven experience securing containerized workloads and Kubernetes environments, including network policy, workload identity, and runtime protection.
• Familiarity with cloud security posture management (CSPM) and addressing misconfigurations across cloud environments.
• Experience in securing Infrastructure-as-Code (IaC) orchestration platforms, including access control, secrets management, and deployment approval workflows, specifically with Terraform or OpenTofu.
• Proficient with Microsoft Entra ID, including Conditional Access, Entitlement Management, and Just-In-Time (JIT) privileged access models.
• Experience with Zero Trust / SASE tools, such as Cloudflare Zero Trust, WAF, and Gateway.
• Knowledge of NIST, ISO 27001, CIS, HITRUST, and PCI DSS frameworks.
• Demonstrated ability to conduct security assessments, manage vulnerabilities, and respond to incidents.
• Strong understanding of Windows, Linux, and endpoint security.
• Industry certifications such as CISSP, SSCP, Security+, or Azure/AWS cloud security certifications are preferred.
• Familiarity with GitOps tools like Argo and Flux for secure Kubernetes deployments.
• Knowledge of programming or scripting languages is a plus.
• Employer-sponsored health, dental, vision, life, and disability insurance.
• Retirement plan with company contributions.
• Annual profit-sharing program.
• Personal development and training budget.
• Open and collaborative work environment.
• Comprehensive 2-week onboarding process.
• Robust mentorship program.
OpenLoop
Funcional Health Tech
Salesforce
CNO Financial Group
Get handpicked remote jobs straight to your inbox weekly.