Senior Cloud Security Engineer

Posted 4 days ago

This is a fully remote position, open to applicants in United States.

📋 Description

• Take ownership of cloud security posture management, ensuring proper configurations, workload management, and entitlement controls across AWS and Azure.

• Design and implement identity and access management (IAM), enforce least privilege principles, establish federation, single sign-on (SSO), manage secrets, oversee privileged access, implement identity controls, ensure network segmentation, enhance container security, facilitate encryption, manage keys, and create policy-as-code guardrails.

• Integrate application security earlier in CI/CD processes through static and dynamic analysis, dependency checks, software supply chain scanning, threat modeling, secrets management, and secure-by-design evaluations.

• Architect segmentation strategies, zero-trust access frameworks, firewalls, web application firewalls (WAFs), and traffic inspection mechanisms for both cloud and hybrid networks.

• Lead initiatives for data classification, encryption, tokenization, key management, data loss prevention (DLP), and privacy-by-design standards for protected health information (PHI) and electronic protected health information (ePHI).

• Develop guardrails, data protection methodologies, abuse controls, misuse controls, and monitoring systems for artificial intelligence, machine learning, and generative AI applications.

• Optimize security information and event management (SIEM) systems, enhance cloud-native detection capabilities, facilitate event correlation and incident response, conduct vulnerability assessments, and coordinate penetration testing efforts.

• Transform security findings into actionable remediation with established timelines.

• Uphold security baselines, ensure configuration compliance, maintain controls, and document logging and audit evidence.

• Mentor engineers across various teams to embed secure practices as the default approach.

• Undertake additional responsibilities as needed.


⛳️ Requirements

• Bachelor’s degree in Computer Science or a related discipline.

• 6 to 9 years of experience in security engineering with hands-on cloud expertise, regarded as a guideline rather than an absolute requirement.

• Proficient with agentic AI tools as a primary focus for security engineering, analysis, detection, and automation tasks.

• Demonstrated senior-level knowledge across network security, application security, cloud security, information security, and AI security, with substantial depth in multiple areas.

• Practical experience in developing and managing controls as code, including policy as code, infrastructure as code, automation, and detection mechanisms.

• Experience managing on-call responsibilities and incident management.

• Extensive cloud security knowledge in AWS and Azure, encompassing IAM, least privilege access, identity federation, SSO, secrets management, privileged access, workload and non-human identity security, network security, container security, image scanning, runtime protection, key management, encryption, CSPM, CWPP, and CIEM.

• Background in data protection and privacy engineering, including data classification, encryption, tokenization, key management, DLP, and privacy by design for regulated health data, along with awareness of data residency requirements.

• Experience in application and product security, including secure software development lifecycle (SDLC), threat modeling, static analysis, dynamic analysis, software composition analysis, secrets management, software supply chain security, and API security.

• Background in detection, response, and vulnerability management, including SIEM, cloud-native detection, log and event correlation, vulnerability scanning and management, penetration testing coordination, and remediation processes.

• Awareness of AI security issues such as prompt injection, data and model poisoning, and data leakage.

• Familiarity with OWASP Top 10 for LLM Applications and MITRE ATLAS is advantageous.

• Experience with frameworks such as HIPAA, HITRUST, SOC 2, NIST, ISO 27001, ISO 42001, and GDPR.

• Ability to manage multiple tasks and work independently.

• Strong organizational and project management capabilities.

• Outstanding interpersonal and communication skills.


🏝️ Benefits

• Paid Time Off (PTO)

• Medical insurance

• Dental insurance

• Vision insurance

• 401(k) with matching contributions

• Comprehensive Employee Assistance Program (EAP)

• Wellness program

People also viewed

Primer22 hours ago

Senior Security Engineer

GB flagUnited Kingdom, +6 more countriesFull-timeCybersecurity / Security Engineer
ApplyView job
Akamai Technologies23 hours ago

Security Architect

IN flagIndia OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
Mashreq23 hours ago

Vice President – Information Security

IN flagIndia OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
Alice1 day ago

GenAI CBRNE Cyber Security Expert

US flagIllinois, +1 more stateFull-timeCybersecurity / Security Engineer$150k – $178k/year
ApplyView job
Flodesk1 day ago

Founding Information Security Lead

US flagUnited States, +3 more locationsFull-timeCybersecurity / Security Engineer$120k – $220k/year
ApplyView job
GitLab2 days ago

Staff Security Researcher

US flagUnited States, +2 more countriesFull-timeCybersecurity / Security Engineer$168k – $238k/year
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers