Remotery

Staff Cloud Security Engineer

Posted 6 days ago

This is a fully remote position, open to applicants in United States.

📋 Description

• Strengthen the security framework of the AWS environment and the software development pipeline.

• Take ownership of the cloud security posture across AWS utilizing Wiz and AWS-native services, mitigating risks related to IAM, network segmentation, container security, secrets, and data exposure.

• Implement secure defaults in Infrastructure as Code through reusable modules, guardrails, and policy as code.

• Enhance CI/CD pipelines in collaboration with the DevOps team.

• Manage vulnerability assessments across cloud and application findings, including intake, prioritization, SLA tracking, and remediation.

• Develop scalable automation for ingestion, deduplication, prioritization, and workflows for developers.

• Implement telemetry, alerting, and runbooks for systems under your ownership.

• Operate and fine-tune the WAF, incorporating managed and custom rules, rate limiting, and bot mitigation strategies.

• Collaborate with DevOps, Engineering, and the Application Security Engineer on preventative measures and application security initiatives.


⛳️ Requirements

• Over 8 years of practical security engineering experience in cloud security and vulnerability management.

• Robust background in AWS security, including IAM, networking, container orchestration, and logging/audit practices.

• Direct experience in securing CI/CD pipelines and Infrastructure as Code.

• Proficiency in Terraform is required.

• Experience in managing or significantly contributing to a vulnerability management program.

• Familiarity with OWASP Top 10 and threat modeling practices.

• Experience with Wiz, Cloudflare, GitHub Advanced Security, Spacelift, or AWS-native services is a plus.

• Production experience with WAF is advantageous.

• Exposure to AI/ML security is beneficial.

• Experience with secrets management platforms is preferred.

• Background in identity security is a plus.

• Experience in PCI-regulated or financial services sectors is advantageous.

• Familiarity with Ruby on Rails, Python, or Go is beneficial.

• Ability to work autonomously and manage projects without daily supervision.


🏝️ Benefits

• Significant employer contributions towards health, dental, and vision insurance.

• Generous paid time off, paid holidays, and parental leave.

• 401(k) matching program available.

• Opportunities for merit-based advancement.

• Career development and training programs.

• Eligibility for annual bonuses.

People also viewed

OCHIN, Inc.9 hours ago

Security Application Analyst

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$85.7k – $137.1k/year
ApplyView job
Dynanet Corporation10 hours ago

AI Security Engineer

US flagMaryland OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
Solutions for Information Design, Inc.10 hours ago

Infrastructure & Security Engineer

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$110k – $130k/year
ApplyView job
Fuze Health11 hours ago

Senior Security Engineer

US flagArizona, +4 more statesFull-timeCybersecurity / Security Engineer$156.8k – $196k/year
ApplyView job
LG Energy Solution Vertech, Inc.11 hours ago

Cybersecurity Specialist III

US flagMassachusetts OnlyFull-timeCybersecurity / Security Engineer$98k – $110k/year
ApplyView job
Coupa Software17 hours ago

Senior Security Engineer – Red Team

IN flagIndia OnlyFull-timeCybersecurity / Security Engineer
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers