
Senior Cloud Security Engineer
Posted Aug 4

Posted Aug 4
This is a fully remote position, open to applicants in United States, +1 more state.
• Conduct reviews of AWS, Kubernetes, CI/CD, and SaaS environments to pinpoint security vulnerabilities, misconfigurations, and architectural flaws.
• Execute threat modeling, security architecture evaluations, and cloud security assessments.
• Evaluate infrastructure against security benchmarks and facilitate remediation or the formal acceptance of risks.
• Confirm the effectiveness of security controls across cloud, identity, network, and platform layers.
• Develop and refine security hardening standards for cloud and platform environments.
• Create reference architectures, Architectural Decision Records (ADRs), and security design recommendations.
• Establish and uphold secure patterns, guardrails, and baseline configurations.
• Define and implement least-privilege access models within AWS and Kubernetes.
• Analyze IAM policies, Role-Based Access Control (RBAC) models, identity federation, service identities, and cross-account trust boundaries.
• Review and enhance CI/CD security measures, secrets management, deployment safeguards, and pipeline trust boundaries.
• Analyze Infrastructure-as-Code patterns and suggest secure-by-default methodologies.
• Validate network security measures, segmentation, ingress controls, and cloud networking designs.
• Evaluate Kubernetes security controls and workload isolation practices.
• Maintain visibility of platform security posture through metrics, reporting, and tracking mechanisms.
• Monitor remediation progress and convey risk in terms of business impact, exposure reduction, and blast radius.
• Collaborate with DevOps, Site Reliability Engineering (SRE), and Engineering teams as a trusted advisor.
• Shape technical decisions through expertise, collaboration, and practical recommendations.
• Over 7 years of experience in Cloud Security, Infrastructure Security, Platform Security, Security Architecture, DevSecOps, or related fields.
• Background in assessing cloud environments and identifying security vulnerabilities, misconfigurations, or architectural risks.
• Extensive hands-on expertise with AWS, including IAM, VPC, EKS, KMS, Secrets Manager, CloudTrail, S3, logging, networking, and access controls.
• Demonstrated experience with Kubernetes security encompassing RBAC, service accounts, workload identities, network policies, and workload isolation.
• Experience in securing CI/CD pipelines and cloud-native delivery workflows.
• Solid grasp of threat modeling and risk-based security assessments.
• Proficient in writing or maintaining security standards, hardening baselines, reference architectures, or security design guidelines.
• Strong proficiency in Infrastructure-as-Code, particularly with Terraform.
• Capability to read and review Helm charts.
• Experience collaborating with DevOps, SRE, Platform Engineering, or Infrastructure teams.
• Ability to work independently and influence results without formal authority.
• Legal authorization to work in the United States.
• Preferred: experience in large SaaS, technology, fintech, cloud-native, or highly regulated organizations.
• Preferred: familiarity with GitHub Actions, OIDC federation, secrets management, and deployment protection mechanisms.
• Preferred: experience with CNAPP, CSPM, or cloud security posture management tools.
• Preferred: ability to produce ADRs, security design documents, or architecture standards.
• Preferred: knowledge of AI platform security, agentic workloads, and AI-enabled development practices.
• Preferred: relevant certifications such as AWS Security Specialty, CCSP, CISSP, CKS, or equivalent.
• Competitive salary.
• Annual performance bonus.
• Stock options or eligibility for stock options.
• Comprehensive medical, dental, and vision insurance.
• 401(k) retirement plan with company contributions or employer match.
• Generous paid time off and company holidays.
• Flexible vacation policy.
• Paid sick leave.
• Extended leave for significant life events.
• Dedicated learning time with access to LinkedIn Learning.
• Wellbeing initiatives.
• Employee assistance program.
• Employer-covered short- and long-term disability, life, and AD&D insurance.
• Career development programs.
• Employee-led resource groups.
• RTD Eco Pass for local employees in Colorado.
• Internal development hub.
• Access to Learning & Development trainers, AI-powered tools, mentors, and opportunities for cross-continent collaboration.
KirkpatrickPrice
Euna Solutions
Gartner
Credence
Get handpicked remote jobs straight to your inbox weekly.